Chapter III - CONFORMITY OF THE PRODUCT WITH DIGITAL ELEMENTS
32

Article 32

Conformity assessment procedures for products with digital elements

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

(1)

The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met. The manufacturer shall demonstrate conformity with the essential cybersecurity requirements by using any of the following procedures:

a)

the internal control procedure (based on module A) set out in Annex VIII;

b)

the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII;

c)

a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII; or

d)

where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9).

(2)

Where, in assessing the compliance of an important product with digital elements that falls under class I as set out in Annex III and the processes put in place by its manufacturer with the essential cybersecurity requirements set out in Annex I, the manufacturer has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least ‘substantial’ as referred to in Article 27, or where such harmonised standards, common specifications or European cybersecurity certification schemes do not exist, the product with digital elements concerned and the processes put in place by the manufacturer shall be submitted with regard to those essential cybersecurity requirements to either of the following procedures:

a)

the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or

b)

a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII.

(3)

Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures:

a)

EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII;

b)

a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII; or

c)

where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9) of this Regulation at assurance level at least ‘substantial’ pursuant to Regulation (EU) 2019/881.

(4)

Critical products with digital elements listed in Annex IV shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the following procedures:

a)

a European cybersecurity certification scheme in accordance with Article 8(1); or

b)

where the conditions in Article 8(1) are not met, any of the procedures referred to in paragraph 3 of this Article.

(5)

Manufacturers of products with digital elements qualifying as free and open-source software, which fall under the categories set out in Annex III, shall be able to demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the procedures referred to in paragraph 1 of this Article, provided that the technical documentation referred to in Article 31 is made available to the public at the time of the placing on the market of those products.

(6)

The specific interests and needs of microenterprises and small and medium-sized enterprises, including start-ups, shall be taken into account when setting the fees for conformity assessment procedures and those fees shall be reduced proportionately to their specific interests and needs.

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 2.7Products designed before the CRA applies — no forced redesign

Products designed before 11 December 2027 but placed on the market after that date do not necessarily require redesign. The manufacturer carries out a current risk assessment; where it shows that existing measures address the risks, compliance can rest on those measures. Historical design and test documentation need not be recreated.

Key takeaways

  • The conformity assessment procedure, EU declaration of conformity and CE marking remain mandatory in any case.
  • No obligation to provide test results covering the original design phase; tests can be grouped across product families (Section 7.4 of the guidance).
  • Vulnerability handling (Annex I Part II), keeping the risk assessment updated (Art. 13(3)) and user information (Art. 13(18)) apply without restriction.

Example from the guidance

A microcontroller designed before the CRA applies may continue to be placed on the market without redesign where a current risk assessment shows that existing security measures address the identified risks (Example 12).

In practice

Do not plan a redesign for legacy designs unless the risk assessment demands one: a current risk assessment plus evidence that existing measures cover the risks is sufficient. You need not recreate historical design and test documentation — but the declaration of conformity and CE marking remain mandatory.

Section in the guidance overview
Section 6.2Conformity assessment for important and critical products

Class II and critical products require third-party assessment. Important class I products may use the internal control procedure (module A) where a relevant harmonised standard is applied in full and covers at least all risks associated with the core functionality — risks beyond that scope must be addressed through additional, documented measures.

Key takeaways

  • FOSS exception: important class I/II products placed on the market as FOSS may follow the default-category procedures (Art. 32(5)).
  • Antivirus with extra features (disk cleaning, anti-tracking): self-assessment is possible where the standard covers the core functionality's risks and additional risks are addressed and documented (Example 62).
  • An integrated critical component does not force the whole product into that component's stricter regime — the product's own core functionality remains decisive (Example 63: router integrating a firewall component).
  • Non-compliance with Art. 32 can trigger administrative fines under Art. 64(3).

In practice

For class I products, first check whether a harmonised standard covers all risks of the core functionality — that determines whether you may self-assess (module A) or need a notified body. Risks from additional functions outside the standard must be closed with your own documented measures. FOSS products of classes I/II may always self-assess.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Related Recitals

(5)

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex