Conformity assessment procedures for products with digital elements
Binds
manufacturer
Applies from
Evidence
process
Article 32(1): Conformity assessment procedures for products with digital elements
manufacturer · Article 32(1)
Conformity assessment procedures for products with digital elements 1. The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met. The manufacturer shall demonstrate conformity with the essential cybersecurity requirements by using any of the following procedures: (a) the internal control procedure (based on module A) set out in Annex VIII; (b) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; (c) a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII; or (d) where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9).
How to satisfy it: Classification drives cost. Determine whether the product is default, Annex III Class I, Annex III Class II or Annex IV before estimating the route, because a notified body changes the timeline by months.
Article 32(2): Conformity assessment for important products with digital elements, class I
manufacturer · product class important class i · Article 32(2)
2. Where, in assessing the compliance of an important product with digital elements that falls under class I as set out in Annex III and the processes put in place by its manufacturer with the essential cybersecurity requirements set out in Annex I, the manufacturer has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least ‘substantial’ as referred to in Article 27, or where such harmonised standards, common specifications or European cybersecurity certification schemes do not exist, the product with digital elements concerned and the processes put in place by the manufacturer shall be submitted with regard to those essential cybersecurity requirements to either of the following procedures: (a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or (b) a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII.
How to satisfy it: Class I is the only route that depends on what you did about standards. Apply harmonised standards in full and self-assessment under Article 32(1) remains available; apply them partly or not at all, or find none exist, and a notified body becomes mandatory. As of 13 Aug 2026 no CRA harmonised standard is cited in the Official Journal, so in practice this paragraph currently routes every class I product to module B+C or module H.
Article 32(3): Conformity assessment for important products with digital elements, class II
manufacturer · product class important class ii · Article 32(3)
3. Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures: (a) EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; (b) a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII; or (c) where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9) of this Regulation at assurance level at least ‘substantial’ pursuant to Regulation (EU) 2019/881.
How to satisfy it: Class II always requires a third party. There is no self-assessment route, whatever the state of the standards. No notified body had been designated under the CRA in NANDO as of mid-2026 and designation typically takes 12 to 18 months, so capacity, not readiness, is the likely constraint on this route.
Article 32(4): Conformity assessment for critical products with digital elements
manufacturer · product class critical · Article 32(4)
4. Critical products with digital elements listed in Annex IV shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the following procedures: (a) a European cybersecurity certification scheme in accordance with Article 8(1); or (b) where the conditions in Article 8(1) are not met, any of the procedures referred to in paragraph 3 of this Article.
How to satisfy it: Annex IV products go to a European cybersecurity certification scheme under Article 8(1) where one applies, and otherwise fall back to the class II procedures in paragraph 3.
Article 32(5): Conformity assessment for free and open-source software under Annex III
manufacturer · Article 32(5)
5. Manufacturers of products with digital elements qualifying as free and open-source software, which fall under the categories set out in Annex III, shall be able to demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the procedures referred to in paragraph 1 of this Article, provided that the technical documentation referred to in Article 31 is made available to the public at the time of the placing on the market of those products.
How to satisfy it: The relief that matters for open-source manufacturers: a product in an Annex III category may use the ordinary Article 32(1) procedures, including self-assessment, provided the Article 31 technical documentation is public at the time of placing on the market. Publishing the technical file is the price of avoiding a notified body.
Every quoted requirement on this page is verbatim Official Journal text. The surrounding guidance is Legalithm’s commentary and is not regulation. This page states the obligation and its legal basis; it is not legal advice, and the corpus has not been reviewed by counsel.