Skip to content

CRA

Cyber Resilience Act

Cybersecurity of networked devices

The Cyber Resilience Act (CRA) adopted by the Council of EU Home Affairs Ministers in 2024 will impose new minimum requirements on manufacturers of networked devices in terms of cybersecurity.

Submit a request now
PCB-Board

What is the Cyber Resilience Act?

The CRA sets out binding cybersecurity requirements for connected devices placed on the market within the EU. Its aim is to establish a uniform security standard for digital hardware and software products on the European market.

Find out more about the requirements and deadlines
Ensuring the effective implementation of the CRA

Your Guide to CRA Compliance for Products with Digital Elements

The Cyber Resilience Act imposes new, binding requirements on manufacturers regarding the cybersecurity of their products – throughout their entire life cycle. From risk assessment and secure development processes through to conformity assessment and market surveillance: CRA compliance requires structure, expertise and clear lines of responsibility.

TÜVIT supports manufacturers through all the relevant steps on the path to compliance – in a practical, independent and standards-compliant manner.
Our free guidance document outlines what matters, which specific obligations apply and how TÜVIT can provide you with targeted support to meet the CRA requirements efficiently and sustainably.

Download the document in English for free now and plan your path to CRA compliance in a structured way.

Download the whitepaper now
Standard, important or critical?

The CRA Defines these Product Categories

The CRA sets out fundamental cybersecurity requirements that apply to all products with a digital element placed on the market in the EU following the expiry of a transition period. By contrast, the type of conformity assessment procedure permitted depends on how critical or sensitive individual products are classified from a cybersecurity perspective. In this regard, the CRA distinguishes between the product categories described below.

The key Factor is the Cyber Risk Rating

Standard products (default products) are products containing digital elements that are classified neither as essential Class I or II products nor as critical products, and which are subject to the basic cybersecurity requirements

  • Examples include: consumer products such as games, software and image-processing devices.
  • Reference: No separate article in the CRA; these arise indirectly from Articles 7 and 8 and are not listed in Annex III or IV

Class I products are products containing digital elements whose core function supports safety-critical IT or network functions and which are therefore subject to enhanced cybersecurity compliance requirements.

  • Examples include: identity management systems, browsers, password managers, security software, network products, network management systems, operating systems, hardware components, smart home devices, virtual assistants, health wearables, …
  • Reference: CRA, Article 7 and Annex III, Class 1

Class II essential products are products containing digital elements with particularly critical safety functions or significant cyber risk potential, which are subject to stricter conformity requirements and more comprehensive testing obligations.

  • Examples include: operating systems, virtualisation software, network security, hardware security components, security software, …
  • Reference: in accordance with the CRA, Article 7 and Annex III, Class II

Critical products are products containing digital elements whose core function performs particularly sensitive security or cryptographic tasks, and whose compromise could have a significant impact on cyber security and critical infrastructure.

  • Examples include: hardware with security boxes, smart meter gateways, other devices for advanced security purposes, smart cards or similar devices, including security elements, …
  • Reference: in accordance with the CRA, Article 8 and Annex IV)

Your Path to CRA Compliance

The path to achieving CRA compliance is rarely a sprint. Under the umbrella of the TÜV NORD GROUP, there are a host of helping hands to support manufacturers of products with digital elements on their journey towards successfully demonstrating compliance – and beyond. 

  • Compliance Readiness
    Through introductory seminars, bespoke strategy workshops or product checks carried out throughout the development process, we support manufacturers step by step on their journey to meeting CRA requirements.
    Get started
     now
  • Proof of Compliance
    As an approved testing laboratory (ITSEF) or an accredited conformity assessment body (CAB), we test or assess the conformity of important or critical products using appropriate conformity assessment procedures.
    Towards proof
     of compliance
  • Post-market obligations
    Throughout the required support period, we assist manufacturers with vulnerability management and in fulfilling their monitoring and response obligations under the CRA.
    This is how our experts support
Start preparing now

#1 CRA Compliance Readiness

Get started now and prepare thoroughly for the new requirements of the Cyber Resilience Act. This will ensure that your products are fully compliant when the EU regulation comes into force. With our service modules designed to help you achieve CRA readiness, we support developers in understanding the wide-ranging requirements of the EU regulation, meeting them in good time and ensuring that your products comply with the necessary cybersecurity standards.

Get in touch now

Ready to Go

  • How to: Get started efficiently and without unnecessary detours when implementing the CRA requirements.
  • Gain an overview: Identify vulnerabilities and security gaps in your products at an early stage.
  • Well prepared: Set the course today for a successful go-to-market launch of your products from 11 December 2027
Harmonised European Standards (hEN)

Standards for a Uniform Level of Safety

The CRA’s requirements are currently being set out in harmonised standards (hENs) by CEN, CENELEC and ETSI. These are intended to facilitate the implementation of the requirements and promote a uniform level of safety within the EU single market. Many hENs are still under development, but are based on existing standards.

#3 Post-Market & Reporting

Compliance based on comprehensive quality assurance

The criteria listed below may support a case for demonstrating conformity on the basis of Module H:

  • The focus is on recurring product development, extensive product portfolios, product families or long-term market availability (including software)
  • An established information security management system (ISMS), e.g. in accordance with ISO/IEC 27001, is already in place or planned
  • A desire for regulatory efficiency through compliance evidence covering an entire system

  • Key Class I products (in accordance with the CRA, Article 7 and Annex III)
    Products that pose an increased cybersecurity risk but are not classified as ‘critical’.
    Examples include: identity management systems, browsers, password managers, security software, network products, network management systems, operating systems, hardware components, smart home devices, virtual assistants, health wearables, …
     
  • Important Class II products (in accordance with the CRA, Article 7 and Annex III)
    Products that present a higher cybersecurity risk than Class I products and often perform essential security functions within IT infrastructures. These products require a more rigorous conformity assessment.
    Examples include: operating systems, virtualisation software, network security, hardware security components, security software, …
     
  • Critical products (in accordance with the CRA, Article 8 or Annex IV)
    Evidence of Module H is permissible if no scheme or procedure under CRA Article 8(1) can be identified, assigned or applied.
    Examples include: hardware with security boxes, smart meter gateways, other devices for advanced security purposes, smart cards or similar devices, including security elements, …

Note: Whilst Class I often covers security components for end users (e.g. password managers), Class II focuses more on infrastructure-critical components. The requirements for Class II products are therefore more stringent, as their compromise could have significant negative consequences for a large number of other products, users or critical infrastructure. Consequently, these products must undergo a conformity assessment by an authorised conformity assessment body (Notified Body), such as TÜV NORD.

The CRA calls for the implementation of a comprehensive quality assurance system. 

  • DE: The Federal Office for Information Security (BSI) sets out, in Technical Guideline TR-03183-H, a practical approach to demonstrating this quality assurance on the basis of an effective information security management system (ISMS) in accordance with ISO/IEC 27001 – supplemented by the CRA-specific requirements of TR-03183-H.
     
  • Other EU countries: The requirements for providing evidence may vary in some respects depending on the EU country. Please contact us; we will look into this for you.

If Module H is chosen to demonstrate compliance with the CRA requirements, the following must be taken into account:

DE

  • Evidence of comprehensive quality assurance throughout the entire product lifecycle must be provided; from development, through manufacture, implementation and operation, to the decommissioning of the products.
  • The BSI in Germany favours the introduction and operation of an Information Security Management System (ISMS) in accordance with ISO/IEC 27001, extended to include the specific requirements of the BSI Technical Guideline TR-03183-H.
  • The scope of the ISMS covers not only the placing on the market of products with digital elements (PwDE), but also the provision of associated Remote Data Processing Solutions (RDPS) – i.e. cloud back-ends or server services, without which the product would be unable to perform one of its functions. In each case, both the development and production processes as well as the vulnerability handling processes must be covered.
  • Conformity assessment is carried out by a notified conformity assessment body (Notified Body) designated in accordance with the CRA notification procedure for Module H. TÜV NORD will apply to the BSI for this designation. In doing so, it can draw on its existing accreditations from the German Accreditation Body (DAkkS), such as for ISO/IEC 27001.
  • The conformity assessment body audits and verifies the conformity and effectiveness of the ISMS (ISO/IEC 27001 plus BSI TR-03183-H) and draws up a report on this, as well as a corresponding certificate which can be used as evidence for third parties.

Other EU countries: The conformity assessment procedure may vary in some respects depending on the EU country. Please contact us; we will look into this for you.

Type examination and declaration of conformity for series production as a package

The criteria listed below may support a case for demonstrating conformity on the basis of Module B/C:

  • The focus is on individual products, possibly in small quantities, or project-specific developments
  • There is no established quality management system in place, e.g. in accordance with ISO/IEC 27001 or similar standards
  • An external technical audit is desired or required due to the critical nature of the project

  • Key Class I products (in accordance with the CRA, Article 7 and Annex III)
    Products that pose an increased cybersecurity risk but are not classified as ‘critical’.
    Examples include: identity management systems, browsers, password managers, security software, network products, network management systems, operating systems, hardware components, smart home devices, virtual assistants, health wearables, …
     
  • Important Class II products (in accordance with the CRA, Article 7 and Annex III)
    Products that present a higher cybersecurity risk than Class I products and often perform essential security functions within IT infrastructures. These products require a more rigorous conformity assessment.
    Examples include: operating systems, virtualisation software, network security, hardware security components, security software, …
     
  • Critical products (in accordance with the CRA, Article 8 or Annex IV)
    Evidence of Module H is permissible if no scheme or procedure under CRA Article 8(1) can be identified, assigned or applied.
    Examples include: hardware with security boxes, smart meter gateways, other devices for advanced security purposes, smart cards or similar devices, including security elements, …

The CRA requires the implementation of a comprehensive quality assurance system. 

  • DE: The notified body draws up a product-specific conformity assessment plan in accordance with the requirements of Module B. Comprehensive technical documentation is an essential prerequisite for this. When preparing for the type examination, relevant standards (e.g. CEN, CENELEC, ETSI), agreed interpretations and other regulatory frameworks are taken into account. As these requirements are subject to ongoing development, both currently and in the future, their validity must be reviewed regularly.
     
  • Other EU countries: The documentation requirements may vary in some respects depending on the EU country. Please contact us; we will look into this for you.

Module B – Type examination

As part of Module B, manufacturers submit an application for EU type examination to TÜV NORD as a notified body. The manufacturer’s obligations include:

  • Preparing the technical documentation in accordance with the CRA requirements
  • Carrying out a risk analysis and risk assessment
  • Demonstrating that the measures selected are suitable for meeting the safety requirements (even if no harmonised standard (hEN) is applied)

The technical documentation must contain all the information necessary to assess the product’s conformity.

We therefore check:

  • the complete technical documentation
  • the product type
  • compliance with harmonised standards, where applicable
  • the suitability of the safety measures, where no hENs have been used

Upon successful assessment, TÜV NORD issues an EU type-examination certificate.

Module C – Internal production control

Module C is mandatory in addition to Module B and relates to series production. The following principles apply:

  • It is not necessary to involve a notified body again.
  • The manufacturer ensures that all products manufactured conform to the type tested in accordance with Module B.
  • The manufacturer affixes the CE marking and draws up the EU Declaration of Conformity.

Module C is based entirely on the EU type-examination certificate previously issued under Module B.

Other EU countries: The conformity procedure may vary in some respects depending on the EU country. Please contact us; we will look into this for you.

Module A

Conformity based on the manufacturer’s declaration of conformity

  • Default products with digital elements:
    products that are not assigned to any other class.
     
  • Key products with digital elements – Class I (in accordance with the CRA, Article 7 or Annex III)
    Examples include: password managers, public-key infrastructures and software for issuing digital certificates, routers, modems for internet connectivity and switches, network management systems

Key products with digital elements – Class I

  • Harmonised European Standard (hEN): Technical standards developed and adopted by one of the European standardisation organisations (CEN, CENELEC, ETSI) under a mandate from the European Commission, and published in the Official Journal of the European Union following review and authorisation by the European Commission.
  • Schemes in accordance with CSA
  • Technical specifications

Default products with digital elements

  • Manufacturer-specific procedures may also be applied

  • Default products with digital elements
    : Manufacturer’s declaration based on internal manufacturing records 
     
  • Essential products with digital elements – Class I
    : Manufacturer’s declaration of conformity based on harmonised European standards (hEN)

Note: Under the manufacturer’s declaration of conformity in Module A, the involvement of a notified body is not required.

Requirements and Updates

What Does the CRA Entail?

The CRA sets out new minimum safety requirements for connected devices. In future, all connected products placed on the market within the EU must bear the CE marking. This visibly demonstrates to the public that the marked product meets the requirements of the CRA.
 

Requirements for Manufacturers Include, Among Others:

  • Integration and implementation of cyber security throughout the entire product life cycle (planning, development, production, operation)
  • Documentation of all cybersecurity risks
  • Reporting of cybersecurity incidents to both ENISA and affected users
  • Ensuring that potential vulnerabilities are effectively addressed throughout the expected product lifecycle (maximum 5 years)
  • Provision of security updates for at least 5 years
  • Clear and comprehensible user manuals for products with digital elements

What is the Current Status?

The CRA was adopted by the Council of EU Ministers of the Interior on 10 October 2024 and published in the Official Journal of the European Union on 20 November 2024 as Regulation (EU) 2024/2847.

Implementation Deadlines:

  • 10 December 2024: Entry into force of the CRA
  • 11 June 2026: Chapter IV (Notification of conformity assessment bodies) enters into force.
  • 11 September 2026: Manufacturers are obliged to inform national authorities and ENISA of actively exploited security vulnerabilities in their products (reporting obligations).  
  • 11 December 2027: From this date, all requirements of the CRA will apply. This means that all connected products placed on the market within the EU must bear the CE marking. 

Press Releases

17 April 2026

From safety assessment to certificate


TÜVIT carries out the independent security assessment, whilst TÜV NORD CERT makes the certification decision. This provides manufacturers with a continuous pathway to EUCC certification as evidence of compliance with the requirements of the Cyber Security Act (CSA) and the Cyber Resilience Act (CRA).
8 May 2025

Authority as an ITSEF


TÜV Informationstechnik GmbH (TÜV NORD GROUP), based in Essen, announces that it is now officially authorised to act as an Information Technology Security Evaluation Facility (ITSEF) for the European Union Cybersecurity Certification (EUCC).

Questions, Comments, and More About the CRA

Ihr Ansprechpartner
Eric Behrendt, TÜV Informationstechnik

Eric Behrendt