FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Module H

Does Module H issue an EU-type examination certificate like module B+C?

No.

Unlike module B+C, Module H is not built around an EU-type examination certificate for a representative specimen. Under the CRA, Module H is built around approval of the manufacturer's quality system, later decisions on changes to that system, and ongoing surveillance. That is why the retained records under Part IV are the quality-system documentation, approved changes, and notified-body decisions and reports, rather than an EU-type certificate.

Citations
Cyber Resilience Act

Annex VIII Part IV points 3.3-4.3 and 6 describe quality-system approval, change decisions, surveillance, audit reports, and retained records, not an EU-type examination certificate.

CRA Module H

Under Module H, does the notified body perform the product risk-assessment, testing, and documentation work instead of the manufacturer?

No.

The notified body assesses and surveils the quality system, but the manufacturer still carries out the product-level compliance work within that system. The Commission FAQ says the manufacturer, based on the quality system, implements the necessary cybersecurity mitigation measures following the risk assessment, tests the product, draws up the technical documentation, and ensures that production of the different units does not alter compliance.

Citations
Cyber Resilience Act

Annex VIII Part IV points 1-3.2 leave product conformity, vulnerability-handling processes, risk-related documentation, and quality-system operation with the manufacturer.

European Commission CRA FAQs

Section 6.3 explains that the manufacturer still implements mitigations, tests products, draws up technical documentation, and controls production under the quality system.

CRA Module H

Can an approved Module H system automatically cover any new or substantially modified product without further notified-body assessment?

No.

The Commission FAQ says the manufacturer can extend the scope of the quality system to new or substantially modified products, but the quality system must be updated to document the new scope, new standards may need to be applied, and new tests may need to be performed. That extension is subject to a new assessment by the same notified body that performed the original assessment. Annex VIII Part IV point 3.5 also requires the manufacturer to keep that notified body informed of intended changes to the quality system.

Citations
Cyber Resilience Act

Annex VIII Part IV point 3.5 requires intended quality-system changes to be evaluated by the notified body that approved the system.

European Commission CRA FAQs

Section 6.3 says scope extensions to new or substantially modified products require an updated quality system and a new assessment by the same notified body.

CRA Module H

In what language can Module H technical documentation and correspondence be submitted to the notified body?

They must be in an official language of the Member State where the notified body is established, or in another language acceptable to that body.

That rule applies to technical documentation and correspondence for any CRA conformity assessment procedure, including Module H.

Citations
Cyber Resilience Act

Article 31(4) sets the language rule for technical documentation and correspondence relating to any conformity-assessment procedure.

CRA Module H

If software uses Module H, where does the notified body's identification number go?

It follows the CE marking wherever the CRA allows that CE marking to be placed for software.

For software products, Article 30(1) says the CE marking is affixed either to the EU declaration of conformity or on the website accompanying the software product. Article 30(4) then says that, where Module H is used, the CE marking is followed by the notified body's identification number. So the CRA does not create a separate location rule for software under Module H; the number follows the CE marking in the place where that marking is lawfully affixed.

Citations
Cyber Resilience Act

Article 30(1) sets CE marking locations for software; Article 30(4) requires the notified-body identification number to follow the CE marking when Module H is used.

CRA Notified Bodies

What is a notified body under the Cyber Resilience Act?

A CRA notified body is a conformity assessment body that has been assessed, designated, and notified for CRA conformity assessment tasks. It may be public or private, but it must meet the CRA requirements for legal personality, independence, competence, impartiality, confidentiality, and operational capability.

A body does not become a CRA notified body just because it performs cybersecurity audits, penetration testing, certification, or assessments under another EU law. For CRA purposes, the notification procedure must be completed and the body's public notification must cover the relevant CRA activities.

Citations
Cyber Resilience Act

Defines notified bodies and sets the Article 39 requirements for independence, competence, impartiality, confidentiality, and capability.

CRA Notified Bodies

Who designates and monitors CRA notified bodies?

Each Member State designates a notifying authority. That authority is responsible for the procedures used to assess, designate, notify, and monitor conformity assessment bodies, including their use of subsidiaries or subcontractors.

A Member State may use a national accreditation body for assessment and monitoring. If assessment, notification, or monitoring is delegated to a non-governmental body, the notifying authority remains fully responsible for the delegated tasks.

Citations
Cyber Resilience Act

Article 36 assigns Member State notifying authorities responsibility for assessment, designation, notification, monitoring, and delegated-task accountability.

CRA Notified Bodies

How does a conformity assessment body apply to become a CRA notified body?

The body applies to the notifying authority in the Member State where it is established. The application must describe the conformity assessment activities, the conformity assessment procedure or procedures, and the products with digital elements for which the body claims competence.

Where available, the application includes an accreditation certificate from a national accreditation body. Without accreditation, the body must provide documentary evidence allowing the notifying authority to verify, recognise, and regularly monitor compliance with Article 39.

Citations
Cyber Resilience Act

Article 42 specifies the notification application contents and the evidence needed with or without an accreditation certificate.

CRA Notified Bodies

When can a body start acting as a CRA notified body?

A body may perform CRA notified-body activities only after the Article 43 notification procedure is complete. If the notification relies on accreditation, the no-objection period is two weeks. If it does not rely on accreditation, the no-objection period is two months.

The notification must include full details of the conformity assessment activities, the module or modules, the products with digital elements concerned, and the relevant attestation of competence. That scope is central: a body can be notified for some CRA activities without being competent for every CRA module or product category.

Citations
Cyber Resilience Act

Article 43 sets the notification contents, objection periods, and rule that only bodies completing that procedure count as CRA notified bodies.

CRA Notified Bodies

How should manufacturers use NANDO or public notified-body listings?

The Commission assigns each CRA notified body an identification number and publishes an up-to-date list showing the bodies notified under the CRA, their numbers, and the activities for which they have been notified.

A listing should be read as a scope record, not as a blanket approval. Manufacturers should check whether the listed CRA notification covers the product with digital elements, the applicable conformity route, and the specific module needed for the assessment.

Citations
Cyber Resilience Act

Article 44 requires a public list of CRA notified bodies, their identification numbers, and their notified activities.

CRA Notified Bodies

Does a manufacturer have to choose a CRA notified body in its own Member State?

No. Where the CRA procedure requires a notified body, Annex VIII lets the manufacturer apply to a single notified body of its choice for the relevant Module B or Module H assessment.

The practical constraint is scope, not the manufacturer's location. The selected body must be notified for the CRA module and product scope that match the product and assessment route.

Citations
Cyber Resilience Act

Annex VIII permits applications to a single notified body of the manufacturer's choice, while Articles 43 and 44 tie that choice to notified scope.

CRA Notified Bodies

When does the CRA require a notified body?

A notified body is part of the route when the product must use Module B+C or Module H. Module A, internal control, does not involve a notified body.

Article 32 allows several conformity routes. For important class I products, third-party assessment is triggered where qualifying harmonised standards, common specifications, or cybersecurity certification routes are not applied or do not exist for the relevant requirements. Important class II products use Module B+C, Module H, or an applicable certification route. Critical products use the Article 8 certification route where it applies, otherwise the CRA third-party routes in Article 32 apply.

Citations
Cyber Resilience Act

Article 32 distinguishes Module A, Module B+C, Module H, and certification routes for default, important, and critical products.

European Commission CRA FAQs

Section 6 explains that no notified body participates in Module A and that Module B+C or H is mandatory for specified important and critical products.

CRA Notified Bodies

What does the notified body assess under Module B+C?

Module B is the notified-body step. The notified body examines the technical design and development of the product and the manufacturer's vulnerability-handling processes, reviews technical documentation and supporting evidence, examines specimens of critical parts, and carries out or arranges appropriate examinations and tests.

Module C follows Module B and is not a second notified-body production approval. Under Module C, the manufacturer ensures and declares that production units conform to the type described in the EU-type examination certificate and satisfy the CRA requirements.

Citations
Cyber Resilience Act

Annex VIII Part II defines the notified body's Module B examination tasks; Part III defines the manufacturer's Module C production-control responsibility.

European Commission CRA FAQs

Section 6.2 explains the practical split between notified-body design examination and manufacturer production responsibility.

CRA Notified Bodies

What certificate does a notified body issue under Module B?

If the product type and vulnerability-handling processes meet the applicable essential cybersecurity requirements, the notified body issues an EU-type examination certificate. The certificate identifies the manufacturer, states the conclusions of the examination, records any validity conditions, and includes the data needed to identify the approved type and vulnerability-handling processes.

If the type or vulnerability-handling processes do not meet the requirements, the notified body must refuse the certificate and give detailed reasons. Modifications that may affect conformity or certificate validity require additional approval as an addition to the original EU-type examination certificate.

Citations
Cyber Resilience Act

Annex VIII Part II points 6 and 7 set the EU-type examination certificate contents, refusal duty, and approval route for relevant modifications.

CRA Notified Bodies

Does Module B+C include ongoing notified-body surveillance?

Yes, but the surveillance is specific. Under Module B, the notified body must carry out periodic audits to ensure that the manufacturer's vulnerability-handling processes are implemented adequately.

That does not turn Module C into notified-body production surveillance. The production-control obligation remains with the manufacturer under Module C.

Citations
Cyber Resilience Act

Annex VIII Part II point 8 requires periodic audits of vulnerability-handling processes; Part III keeps production conformity under manufacturer control.

Page 28 of 58