FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Module H

Does compliance with a quality-management standard automatically satisfy Module H?

No.

The CRA allows the notified body to presume conformity for elements of the quality system that comply with the corresponding specifications of the national standard implementing the relevant harmonised standard or technical specification. But the notified body still has to assess and approve the system under Module H.

The Commission FAQ also says that accreditation against the ISO 9000 series does not by itself entitle a manufacturer to use Module H without CRA notified-body involvement.

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.3 allows a presumption of conformity for quality-system elements matching the corresponding national standard implementing the relevant harmonised standard or technical specification.

European Commission CRA FAQs

Section 6.3 states that ISO 9000 accreditation does not remove the need for CRA notified-body involvement under Module H.

CRA Module H

What happens if the CRA Module H quality system is approved?

The manufacturer must undertake to fulfil the obligations arising from the approved quality system and maintain it so that it remains adequate and efficient.

The notified body's notification to the manufacturer must contain the conclusions of the audit and the reasoned assessment decision.

Citations
Cyber Resilience Act

Annex VIII Part IV points 3.3-3.4 require a reasoned assessment decision and continuing operation of the approved quality system.

CRA Module H

What if the manufacturer wants to change the quality system?

The manufacturer must keep the notified body informed of any intended change to the quality system.

The notified body then evaluates the proposed changes and decides whether the modified system still satisfies the requirements or whether reassessment is necessary.

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.5 requires the manufacturer to notify intended quality-system changes and the notified body to decide whether reassessment is needed.

CRA Module H

Does Module H help when a manufacturer has many product types or frequent updates?

Often yes, but only within an approved quality-system framework.

The Commission FAQ says Module H may be particularly considered by manufacturers that place numerous product types on the market or products subject to frequent updates, because it provides a more versatile framework than module B+C. That does not remove the need for notified-body assessment of the system and later changes to it.

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.5 explains how proposed quality-system changes are evaluated after approval.

CRA Module H

What surveillance happens after Module H approval?

The notified body must carry out surveillance to make sure the manufacturer fulfils the obligations arising from the approved quality system.

For that purpose, the manufacturer must allow access to the relevant design, development, production, inspection, testing, and storage sites and provide the quality-system documentation plus design and manufacturing quality records needed for assessment.

Citations
Cyber Resilience Act

Annex VIII Part IV points 4.1-4.2 define the purpose of surveillance and the sites, documentation, and quality records the manufacturer must make available.

CRA Module H

Are periodic audits part of Module H surveillance?

Yes.

The notified body must carry out periodic audits to make sure the manufacturer maintains and applies the quality system, and it must provide the manufacturer with an audit report.

Citations
CRA Module H

Does Module H replace the manufacturer's own responsibility for conformity?

No.

Even under Module H, the manufacturer ensures and declares on its sole responsibility that the covered products or product categories satisfy the applicable CRA requirements and that its vulnerability-handling processes meet Annex I Part II. The notified body assesses and surveils the quality system, but it does not take over the manufacturer's legal responsibility.

Citations
Cyber Resilience Act

Annex VIII Part IV point 1 states that the manufacturer ensures and declares conformity on its sole responsibility under Module H.

CRA Module H

How is CE marking handled under Module H?

Under Module H, the manufacturer affixes the CE marking to each individual compliant product with digital elements, and the notified body's identification number must follow the CE marking.

The identification number is affixed by the notified body itself or, under its instructions, by the manufacturer or the manufacturer's authorised representative. For software, the CE marking location follows Article 30(1), so the number follows the CE marking on the declaration of conformity or accompanying website.

Citations
Cyber Resilience Act

Article 30(4) and Annex VIII Part IV point 5.1 require the notified body's identification number to follow the CE marking when Module H is used.

CRA Module H

Under Module H, is the declaration of conformity tied to each product or to the product model?

It is tied to each product model for the Module H record duty.

Annex VIII Part IV point 5.2 requires a written declaration of conformity for each product model and requires the declaration to identify the product model for which it has been drawn up. Article 28 also says that, by drawing up the EU declaration of conformity, the manufacturer assumes responsibility for product compliance.

Citations
Cyber Resilience Act

Annex VIII Part IV point 5.2 requires a declaration for each product model; Article 28(4) links the declaration to manufacturer responsibility.

CRA Module H

What records must the manufacturer keep under Module H, and for how long?

The manufacturer must keep Module H records at the disposal of national authorities for at least 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer.

The retained file should include:

- the technical documentation

- the quality-system documentation

- approved changes to the quality system

- the notified body's decisions and reports

- the declaration of conformity for each product model

Citations
Cyber Resilience Act

Annex VIII Part IV points 5.2 and 6 set the retention period for declarations and the Module H technical, quality-system, change, decision, and report records.

CRA Module H

Who gets informed about quality-system approvals under Module H?

The notified body must inform its notifying authorities about quality-system approvals issued or withdrawn, and it must also inform other notified bodies about approvals it has refused, suspended, or withdrawn and, on request, about approvals it has issued.

Citations
Cyber Resilience Act

Annex VIII Part IV point 7 sets notified-body information duties to notifying authorities and other notified bodies.

CRA Module H

Can an authorised representative handle some Module H obligations?

Yes, but only where the mandate expressly covers them.

Under Annex VIII Part IV point 8, the authorised representative may fulfil the manufacturer's obligations relating to the application, quality-system changes, declaration, and record-retention steps on the manufacturer's behalf and under the manufacturer's responsibility.

Citations
Cyber Resilience Act

Annex VIII Part IV point 8 identifies which Module H obligations an authorised representative may fulfil when the mandate specifies them.

CRA Module H

Can important free-and-open-source software use Module H?

Yes.

Article 32(5) allows manufacturers of Annex III products qualifying as free and open-source software to use one of the procedures in Article 32(1), provided that the technical documentation is made public at the time of placing on the market. That means Module H remains available for those products.

Citations
Cyber Resilience Act

Article 32(5) preserves Article 32(1) route availability for qualifying Annex III free-and-open-source software where the technical documentation is public at placing on the market.

CRA Module H

Are CRA fee reductions for SMEs relevant to Module H?

Yes.

Article 32(6) requires the specific interests and needs of microenterprises and small and medium-sized enterprises, including start-ups, to be taken into account when setting conformity-assessment fees, and those fees must be reduced proportionately.

Citations
Cyber Resilience Act

Article 32(6) requires conformity-assessment fees to reflect the needs of microenterprises and SMEs, including start-ups, and to be reduced proportionately.

CRA Module H

What usually makes a CRA Module H system workable in practice?

A workable Module H system lets the notified body see, in a consistent and documented way, how the manufacturer controls the approved product scope from design and development through production, testing, vulnerability handling, CE marking, declarations, records, and later quality-system changes.

In practical terms, the quality-system documentation should show management responsibilities, standards and specifications used, how gaps from harmonised standards or technical specifications are covered, design and development verification, production and quality-assurance controls, examinations and tests with their frequency, quality records, and monitoring of quality-system effectiveness.

Citations
Cyber Resilience Act

Annex VIII Part IV points 3.2-4.3 define what the documented quality system must contain and how the notified body surveils it.

Page 27 of 58