Cyber Resilience Act certification: the four conformity routes and what each costs

This guide walks you through different types of conformity assessments, when you need a notified body, and what drives costs.

framework_CyberResilienceAct_pillar_en

Is there a Cyber Resilience Act certification?

Many teams search for a "CRA certification." What they need is a conformity assessment, which can happen through four different routes.

For example, one route allows you to assess conformity yourself, document the evidence, and affix the CE marking. A certificate only enters the picture for higher-risk product classes, or when you choose a European cybersecurity certification scheme.

What does the CRA require instead of a certificate?

Every manufacturer, whatever the product class, produces the same four things:

  • A conformity assessment under Article 32, using one of the procedures the regulation allows for your product class
  • Technical documentation under Article 31 and Annex VII, covering design, the risk assessment, how you meet each essential requirement, and vulnerability handling
  • An EU declaration of conformity under Article 28 and Annex V, stating the product meets the Annex I requirements
  • The CE marking under Article 30, affixed to the product or its packaging

The CE mark is the visible outcome. For products not listed in Annex III or IV, there is no certificate number, registry, or annual renewal (unless you substantially change the product, which requires a new assessment). You keep the documentation available to market surveillance authorities for ten years, or for the product's support period if that's longer.

When does a European cybersecurity certificate apply?

For the highest-risk products (Annex IV, such as smartcards and smart meter gateways), the CRA expects you to get a third-party EU cybersecurity certificate, not just self-declare.

The Commission can make that certificate mandatory for specific products by passing a separate legal act (a "delegated act"), and "substantial" is the minimum level of testing the certificate must reflect.

Until that act exists, these products use the Class II routes, meaning you get the conformity assessment through a notified body.

CRA certification versus CRA training certificates

Product conformity and personal training credentials are two different things. Courses such as CybResActTPro, or CRA programs from UL, the Linux Foundation, Bureau Veritas, and similar providers, certify that a person understands the regulation. They build your team's knowledge, but they do not make a product compliant.

Does the EU Cyber Resilience Act apply to your product?


Check in a few steps whether your product is in scope and how to become compliant

Which conformity assessment route applies to your product?

Your product's class decides which routes are open to you. Check it against Annex III (important products, Class I and Class II) and Annex IV (critical products). Anything not listed is a default product.

 

The routing table

Product class Available routes Notified body needed? Typical effort

Default (not in Annex III or IV)

Module A (internal control): You check conformity yourself and sign off on it, with no outside auditor.

Optionally, module B+C: You bring in a notified body to review the product design.

 

Optionally, module H: a notified body approves your quality system instead of examining each product type

 

Optionally, get an EU cybersecurity certificate

No

Lowest: internal documentation and self-declaration

Annex III Class I, where you fully apply harmonized standards, common specifications, or a certification scheme

Module A (internal control): If you've fully applied a harmonized standard, common specification, or certification scheme, you can check conformity yourself.

Optionally, module B+C: You bring in a notified body to review the product design.

 

Optionally, module H: a notified body approves your quality system instead of examining each product type

 

Optionally, a certification scheme at assurance level at least "substantial"

No, if you use module A

Low to moderate: depends on standards being available

Annex III Class I, standards not applied, applied in part, or not available

Module B+C: a notified body examines the product design, then you make sure production matches it

 

Module H: a notified body approves your quality system instead of examining each product type

 

Alternatively, a certification scheme

Yes

Moderate to high: third-party examination or quality system audit

Annex III Class II

Module B+C: a notified body examines the product design, then you make sure production matches it

 

Module H: a notified body approves your quality system instead of examining each product type

 

Alternatively, a certification scheme at assurance level at least "substantial"

Yes

High: no self-assessment option

Annex IV critical

European cybersecurity certification scheme under Article 8(1); otherwise any Class II procedure

Yes, or a certification body

Highest: certification at assurance level at least "substantial"

Default products: self-assessment under module A

Module A is the internal control procedure in Annex VIII. You carry out the assessment yourself, with no notified body. It covers the large majority of products.

Self-assessment still obliges you to produce:

  • the cybersecurity risk assessment required by Article 13(2),
  • the full technical documentation under Annex VII, including evidence that you meet each Annex I requirement, and
  • the EU declaration of conformity under Annex V

Authorities can ask for this at any time, so build with the intention to make everything easy for them to understand.

Annex III Class I important products

Class I includes identity management systems, browsers, password managers, VPNs, operating systems, routers, and smart home security products such as door locks and cameras.

If you fully apply harmonized standards, common specifications, or a certification scheme at assurance level that reaches at least "substantial," self-assessment under module A remains available.

If you have not fully applied harmonized standards, common specifications, or a certification scheme at assurance level at least "substantial," or none exist for your product, Article 32(2) requires module B plus C or module H, both involving a notified body.

Annex III Class II important products

Class II covers hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers.

Under Article 32(3), your assessment options are module B plus C, module H, or a European cybersecurity certification scheme under Article 27(9) at assurance level at least "substantial." There is no self-assessment option for Class II.

Annex IV critical products

Annex IV is the shortest list in the regulation:

  • hardware devices with security boxes,
  • smart meter gateways within smart metering systems, and other devices for advanced security purposes, including secure cryptoprocessing, and
  • smartcards or similar devices, including secure elements

Article 32(4) requires a European cybersecurity certification scheme under Article 8(1). Where the Article 8(1) conditions are not met—for example, because no delegated act covers your product yet—you may use any Class II procedure.

Open-source software placed on the market

Under Article 32(5), manufacturers of free and open-source software in an Annex III category may use any Article 32(1) procedure, including self-assessment, provided they make the Article 31 technical documentation public when placing the product on the market. Transparency replaces the third-party check.

What does each module involve?

  • Module A: internal control. You assess the product against Annex I, build the documentation, and sign the declaration. No third party is necessary
  • Module B: EU-type examination. A notified body examines the technical design and your vulnerability handling process, then issues an EU-type examination certificate.
  • It is followed by module C: conformity to type based on internal production control, where you ensure every shipped product matches the approved type
  • Module H: full quality assurance. The notified body audits your quality system rather than each product type

Module H usually pays off when you have multiple product variants or frequent releases, because one approved quality system covers them all.

Do you need a notified body under the CRA?

The decision depends on these three questions

  1. What class is your product? Default product: no notified body. Class II or critical: yes. Class I: go to question 2.
  2. Have you applied harmonized standards, common specifications, or an equivalent in full? If yes, a Class I product can stay in self-assessment. If no, you need a notified body.
  3. Does a European cybersecurity certification scheme cover your product? If yes, certification is an option for any product class, and the primary route for critical products.

Why is notified body capacity the real constraint?

Chapter IV of the CRA, which governs notified bodies, has applied since June 11, 2026. Notification has only recently opened, and few bodies are notified under the CRA so far.

Every Class II manufacturer, many Class I manufacturers, and critical-product manufacturers not using the certification route now need the same limited pool of notified bodies before December 11, 2027. That makes booking lead time a scheduling problem, rather than a compliance concern. The earlier you book, the more choice you have.

How to check whether a body is notified

Use the European Commission's NANDO database (New Approach Notified and Designated Organisations). Confirm the body is notified specifically under Regulation (EU) 2024/2847. Many labs are notified under other legislation, such as the Radio Equipment Directive, which does not cover CRA assessments.

Strengthen Quality Management at scale


Move beyond fragmented tools and manual processes while retaining full control over your QMS and continuous improvement program.

How much does Cyber Resilience Act compliance cost?

No official per-company figure is published, and any single number would mislead you. Your cost depends on five drivers you can estimate and plan for.

The five things that drive your CRA cost

  1. Product class and therefore route. This is the single biggest factor. A self-assessed default product and a Class II product with a notified body sit in different cost brackets
  2. Notified body fees for type examination, quality system audits, and surveillance
  3. Internal engineering effort to meet the 13 requirements in Annex I, Part I, from secure-by-default configuration to secure updates
  4. Building and maintaining the software bill of materials (SBOM) and the vulnerability handling process in Annex I, Part II
  5. The support period commitment. Under Article 13(8), it must be at least five years unless the expected use time is shorter. Updates across that period are an ongoing cost most teams never budget

One-off costs versus ongoing costs

One-off costs Ongoing costs
Gap analysis against Annex I Security updates across the support period
Product classification and route decision Vulnerability monitoring and SBOM maintenance
Cybersecurity risk assessment Reporting readiness for actively exploited vulnerabilities and severe incidents
Building the technical documentation Notified body surveillance audits, where applicable
First conformity assessment Re-assessment after a substantial modification

 

Reduced fees for SMEs and start-ups

The CRA builds in relief for smaller companies. Article 32(6) requires that conformity assessment fees take account of the specific interests and needs of microenterprises, SMEs, and start-ups, and that fees are reduced in proportion to those needs.

Under Article 33, Member States support testing and conformity assessment activities for smaller companies, and may set up cyber resilience regulatory sandboxes for testing products in a controlled environment.

What do existing certifications save you?

Existing certifications give you a head start but they don't replace the CRA assessment. That's because the CRA assesses the product and the manufacturer's processes rather than the broader management system.

  • ISO 27001 gives you risk and incident processes to reuse for the risk assessment and vulnerability handling. It does not assess a specific product
  • IEC 62443, especially parts 4-1 and 4-2, maps closely to secure development and product security requirements
  • An existing EUCC certificate gives you a strong evidence base and, where recognized under the CRA, a presumption of conformity for what it covers

What they rarely cover: the SBOM, the support period, coordinated vulnerability disclosure, and CRA reporting to your national CSIRT and ENISA through the single reporting platform.

What the Commission says the alternative costs

When proposing the CRA, the European Commission pointed to a global annual cost of cybercrime estimated to reach EUR 5.5 trillion in 2021, annual data breach costs of at least EUR 10 billion, and annual costs of malicious attempts to disrupt internet traffic of at least EUR 65 billion. These figures describe the problem the regulation addresses. They do not estimate your own cost of non-compliance.

More recent figures point the same way. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a breach at USD 4.99 million, up 12% on the previous year. In the EU, the ENISA Threat Landscape 2025 analyzed 4,875 incidents between July 2024 and June 2025 and found that attackers exploited a vulnerability to get in in 21.3% of cases. That is exactly the risk the CRA's vulnerability handling requirements target.

How to get your product CRA compliant, step by step

The seven steps

  1. Confirm the product is a product with digital elements in scope. Check for sector exclusions, such as medical devices or vehicles
  2. Classify it against Annex III and Annex IV. This decides your conformity assessment route
  3. Run the Article 13(2) cybersecurity risk assessment
  4. Meet the Annex I requirements and document the evidence
  5. Choose and complete the conformity assessment route. Book a notified body early if you need one
  6. Draw up the EU declaration of conformity under Annex V
  7. Affix the CE marking under Article 30

What to do first if you are starting now

Work backwards from December 11, 2027. If you need a notified body, contact one now—booking is the long-lead item, so do it before your documentation is finished. In parallel, start classification and gap analysis this quarter, and check that your reporting process is live.

How can DataGuard help your team become CRA compliant?

DataGuard helps you turn CRA complexity into a clear, actionable plan. Our platform helps you structure your CRA project and prepare your team for vulnerability handling and reporting.

  • Two to four weeks to meet the requirements that already apply
  • Less effort by reusing ISO 9001, ISO 27001, or NIS2 processes and evidence
  • Clear roles and workflows for vulnerability handling, disclosure, and reporting
  • Quality, product, engineering, and security working from shared requirements, tasks, and evidence

Frequently asked questions

Is there a Cyber Resilience Act certificate?

Do I need a notified body under the CRA?

Can I self-assess my product?

How much does CRA compliance cost?

Are there reduced conformity assessment fees for SMEs?

What is the difference between CE marking and certification?

Does ISO 27001 help with CRA compliance?

Which CRA training certification should I take?

🏢 Organization Schema Preview (Development Only)
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "www.dataguard.com#organization",
      "name": "DataGuard",
      "legalName": "DataCo GmbH",
      "description": "DataGuard, the European leader in security and compliance software, is trusted by more than 4,000 organizations across 50+ countries. We help you identify and manage your security and compliance risks and fast-track your certifications and compliance by combining expert consultancy with AI-powered automation. Our purpose-built, all-in-one platform is developed with the experience of over 1.5 million total hours by a team of certified security and compliance experts.",
      "foundingDate": "2018",
      "taxID": "DE315880213",
      "logo": "https://7759810.fs1.hubspotusercontent-na1.net/hubfs/7759810/DataGuardLogo.svg",
      "url": "www.dataguard.com",
      "email": "info@dataguard.de",
      "telephone": "+49 89 452459 900",
      "address": {
        "@type": "PostalAddress",
        "streetAddress": "Sandstrasse 33",
        "addressLocality": "Munich",
        "addressRegion": "Bavaria",
        "postalCode": "80335",
        "addressCountry": "Germany"
      },
      "sameAs": [
        "https://www.linkedin.com/company/dataguard1/",
        "https://www.youtube.com/channel/UCEQzPZ6sCBCj9cAoBvaLL6w",
        "https://x.com/i/flow/login?redirect_after_login=%2FDataGuard_dg"
      ]
    }
  ]
}

✅ Organization schema markup for "DataGuard" has been injected into the document head.