Cyber Resilience Act certification: the four conformity routes and what each costs
This guide walks you through different types of conformity assessments, when you need a notified body, and what drives costs.

This guide walks you through different types of conformity assessments, when you need a notified body, and what drives costs.

Many teams search for a "CRA certification." What they need is a conformity assessment, which can happen through four different routes.
For example, one route allows you to assess conformity yourself, document the evidence, and affix the CE marking. A certificate only enters the picture for higher-risk product classes, or when you choose a European cybersecurity certification scheme.
Every manufacturer, whatever the product class, produces the same four things:
The CE mark is the visible outcome. For products not listed in Annex III or IV, there is no certificate number, registry, or annual renewal (unless you substantially change the product, which requires a new assessment). You keep the documentation available to market surveillance authorities for ten years, or for the product's support period if that's longer.
For the highest-risk products (Annex IV, such as smartcards and smart meter gateways), the CRA expects you to get a third-party EU cybersecurity certificate, not just self-declare.
The Commission can make that certificate mandatory for specific products by passing a separate legal act (a "delegated act"), and "substantial" is the minimum level of testing the certificate must reflect.
Until that act exists, these products use the Class II routes, meaning you get the conformity assessment through a notified body.
Product conformity and personal training credentials are two different things. Courses such as CybResActTPro, or CRA programs from UL, the Linux Foundation, Bureau Veritas, and similar providers, certify that a person understands the regulation. They build your team's knowledge, but they do not make a product compliant.
Your product's class decides which routes are open to you. Check it against Annex III (important products, Class I and Class II) and Annex IV (critical products). Anything not listed is a default product.
| Product class | Available routes | Notified body needed? | Typical effort |
|
Default (not in Annex III or IV) |
Module A (internal control): You check conformity yourself and sign off on it, with no outside auditor.
Optionally, module H: a notified body approves your quality system instead of examining each product type
Optionally, get an EU cybersecurity certificate |
No |
Lowest: internal documentation and self-declaration |
|
Annex III Class I, where you fully apply harmonized standards, common specifications, or a certification scheme |
Module A (internal control): If you've fully applied a harmonized standard, common specification, or certification scheme, you can check conformity yourself.
Optionally, module H: a notified body approves your quality system instead of examining each product type
Optionally, a certification scheme at assurance level at least "substantial" |
No, if you use module A |
Low to moderate: depends on standards being available |
|
Annex III Class I, standards not applied, applied in part, or not available |
Module B+C: a notified body examines the product design, then you make sure production matches it
Module H: a notified body approves your quality system instead of examining each product type
Alternatively, a certification scheme |
Yes |
Moderate to high: third-party examination or quality system audit |
|
Annex III Class II |
Module B+C: a notified body examines the product design, then you make sure production matches it
Module H: a notified body approves your quality system instead of examining each product type
Alternatively, a certification scheme at assurance level at least "substantial" |
Yes |
High: no self-assessment option |
|
Annex IV critical |
European cybersecurity certification scheme under Article 8(1); otherwise any Class II procedure |
Yes, or a certification body |
Highest: certification at assurance level at least "substantial" |
Module A is the internal control procedure in Annex VIII. You carry out the assessment yourself, with no notified body. It covers the large majority of products.
Self-assessment still obliges you to produce:
Authorities can ask for this at any time, so build with the intention to make everything easy for them to understand.
Class I includes identity management systems, browsers, password managers, VPNs, operating systems, routers, and smart home security products such as door locks and cameras.
If you fully apply harmonized standards, common specifications, or a certification scheme at assurance level that reaches at least "substantial," self-assessment under module A remains available.
If you have not fully applied harmonized standards, common specifications, or a certification scheme at assurance level at least "substantial," or none exist for your product, Article 32(2) requires module B plus C or module H, both involving a notified body.
Class II covers hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers.
Under Article 32(3), your assessment options are module B plus C, module H, or a European cybersecurity certification scheme under Article 27(9) at assurance level at least "substantial." There is no self-assessment option for Class II.
Annex IV is the shortest list in the regulation:
Article 32(4) requires a European cybersecurity certification scheme under Article 8(1). Where the Article 8(1) conditions are not met—for example, because no delegated act covers your product yet—you may use any Class II procedure.
Under Article 32(5), manufacturers of free and open-source software in an Annex III category may use any Article 32(1) procedure, including self-assessment, provided they make the Article 31 technical documentation public when placing the product on the market. Transparency replaces the third-party check.
Module H usually pays off when you have multiple product variants or frequent releases, because one approved quality system covers them all.
Chapter IV of the CRA, which governs notified bodies, has applied since June 11, 2026. Notification has only recently opened, and few bodies are notified under the CRA so far.
Every Class II manufacturer, many Class I manufacturers, and critical-product manufacturers not using the certification route now need the same limited pool of notified bodies before December 11, 2027. That makes booking lead time a scheduling problem, rather than a compliance concern. The earlier you book, the more choice you have.
Use the European Commission's NANDO database (New Approach Notified and Designated Organisations). Confirm the body is notified specifically under Regulation (EU) 2024/2847. Many labs are notified under other legislation, such as the Radio Equipment Directive, which does not cover CRA assessments.
No official per-company figure is published, and any single number would mislead you. Your cost depends on five drivers you can estimate and plan for.
| One-off costs | Ongoing costs |
| Gap analysis against Annex I | Security updates across the support period |
| Product classification and route decision | Vulnerability monitoring and SBOM maintenance |
| Cybersecurity risk assessment | Reporting readiness for actively exploited vulnerabilities and severe incidents |
| Building the technical documentation | Notified body surveillance audits, where applicable |
| First conformity assessment | Re-assessment after a substantial modification |
The CRA builds in relief for smaller companies. Article 32(6) requires that conformity assessment fees take account of the specific interests and needs of microenterprises, SMEs, and start-ups, and that fees are reduced in proportion to those needs.
Under Article 33, Member States support testing and conformity assessment activities for smaller companies, and may set up cyber resilience regulatory sandboxes for testing products in a controlled environment.
Existing certifications give you a head start but they don't replace the CRA assessment. That's because the CRA assesses the product and the manufacturer's processes rather than the broader management system.
What they rarely cover: the SBOM, the support period, coordinated vulnerability disclosure, and CRA reporting to your national CSIRT and ENISA through the single reporting platform.
When proposing the CRA, the European Commission pointed to a global annual cost of cybercrime estimated to reach EUR 5.5 trillion in 2021, annual data breach costs of at least EUR 10 billion, and annual costs of malicious attempts to disrupt internet traffic of at least EUR 65 billion. These figures describe the problem the regulation addresses. They do not estimate your own cost of non-compliance.
More recent figures point the same way. IBM's Cost of a Data Breach Report 2026 puts the global average cost of a breach at USD 4.99 million, up 12% on the previous year. In the EU, the ENISA Threat Landscape 2025 analyzed 4,875 incidents between July 2024 and June 2025 and found that attackers exploited a vulnerability to get in in 21.3% of cases. That is exactly the risk the CRA's vulnerability handling requirements target.
Work backwards from December 11, 2027. If you need a notified body, contact one now—booking is the long-lead item, so do it before your documentation is finished. In parallel, start classification and gap analysis this quarter, and check that your reporting process is live.
DataGuard helps you turn CRA complexity into a clear, actionable plan. Our platform helps you structure your CRA project and prepare your team for vulnerability handling and reporting.
For most products, no. Default products are self-assessed and end with a declaration of conformity and CE marking. A notified body issues a certificate after an EU-type examination (module B) or an approval decision for your quality system (module H). You can also get a certificate under a European cybersecurity certification scheme such as EUCC.
You need one for Class II important products, for critical products, and for Class I important products when you have not fully applied harmonized standards, common specifications, or a certification scheme. Default products do not need a notified body.
Yes, for default products and for Class I products where you fully apply harmonized standards or an equivalent. Open-source software in Annex III categories can too, if its documentation is public. Class II and critical products cannot.
There is no official per-company figure. Your cost depends on your product class and route, notified body fees, Annex I engineering effort, SBOM and vulnerability handling, and updates across a support period of at least five years.
Yes. Article 32(6) requires conformity assessment fees to take account of the needs of microenterprises, SMEs, and start-ups and to be reduced proportionately. Article 33 adds Member State support for testing and conformity assessment.
CE marking is your declaration, as the manufacturer, that the product meets EU requirements. Certification is a third-party attestation. Every in-scope product needs a CE marking; only some need a certificate on the way there.
Yes, as a foundation. It gives you reusable risk and incident processes, but it does not assess a product, so it does not replace the CRA conformity assessment or the Annex I requirements.
Pick one that matches your role: engineers benefit from secure development and Annex I, compliance teams from classification, conformity routes, and reporting. A personal certificate does not make your product compliant—only the conformity assessment does.
TISAX® is a registered trademark of the ENX Association. DataGuard is not affiliated with the ENX Association. We provide Software-as-a-Service and support for the assessment on TISAX® only. The ENX Association does not take any responsibility for any content shown on DataGuard's website.
All data provided is for information only, based on internal estimates. This information is not indicative of KPIs, and is not given with any warranties or guarantees, expressly stated or implied in relation to accuracy and reliability.
{
"@context": "https://schema.org",
"@graph": [
{
"@type": "Organization",
"@id": "www.dataguard.com#organization",
"name": "DataGuard",
"legalName": "DataCo GmbH",
"description": "DataGuard, the European leader in security and compliance software, is trusted by more than 4,000 organizations across 50+ countries. We help you identify and manage your security and compliance risks and fast-track your certifications and compliance by combining expert consultancy with AI-powered automation. Our purpose-built, all-in-one platform is developed with the experience of over 1.5 million total hours by a team of certified security and compliance experts.",
"foundingDate": "2018",
"taxID": "DE315880213",
"logo": "https://7759810.fs1.hubspotusercontent-na1.net/hubfs/7759810/DataGuardLogo.svg",
"url": "www.dataguard.com",
"email": "info@dataguard.de",
"telephone": "+49 89 452459 900",
"address": {
"@type": "PostalAddress",
"streetAddress": "Sandstrasse 33",
"addressLocality": "Munich",
"addressRegion": "Bavaria",
"postalCode": "80335",
"addressCountry": "Germany"
},
"sameAs": [
"https://www.linkedin.com/company/dataguard1/",
"https://www.youtube.com/channel/UCEQzPZ6sCBCj9cAoBvaLL6w",
"https://x.com/i/flow/login?redirect_after_login=%2FDataGuard_dg"
]
}
]
}✅ Organization schema markup for "DataGuard" has been injected into the document head.