CRA
Cybersecurity of networked devices
The Cyber Resilience Act (CRA) adopted by the Council of EU Home Affairs Ministers in 2024 will impose new minimum requirements on manufacturers of networked devices in terms of cybersecurity.
Submit a request now
The CRA sets out binding cybersecurity requirements for connected devices placed on the market within the EU. Its aim is to establish a uniform security standard for digital hardware and software products on the European market.
The Cyber Resilience Act imposes new, binding requirements on manufacturers regarding the cybersecurity of their products – throughout their entire life cycle. From risk assessment and secure development processes through to conformity assessment and market surveillance: CRA compliance requires structure, expertise and clear lines of responsibility.
TÜVIT supports manufacturers through all the relevant steps on the path to compliance – in a practical, independent and standards-compliant manner.
Our free guidance document outlines what matters, which specific obligations apply and how TÜVIT can provide you with targeted support to meet the CRA requirements efficiently and sustainably.
Download the document in English for free now and plan your path to CRA compliance in a structured way.
The CRA sets out fundamental cybersecurity requirements that apply to all products with a digital element placed on the market in the EU following the expiry of a transition period. By contrast, the type of conformity assessment procedure permitted depends on how critical or sensitive individual products are classified from a cybersecurity perspective. In this regard, the CRA distinguishes between the product categories described below.
Standard products (default products) are products containing digital elements that are classified neither as essential Class I or II products nor as critical products, and which are subject to the basic cybersecurity requirements
Class I products are products containing digital elements whose core function supports safety-critical IT or network functions and which are therefore subject to enhanced cybersecurity compliance requirements.
Class II essential products are products containing digital elements with particularly critical safety functions or significant cyber risk potential, which are subject to stricter conformity requirements and more comprehensive testing obligations.
Critical products are products containing digital elements whose core function performs particularly sensitive security or cryptographic tasks, and whose compromise could have a significant impact on cyber security and critical infrastructure.

The path to achieving CRA compliance is rarely a sprint. Under the umbrella of the TÜV NORD GROUP, there are a host of helping hands to support manufacturers of products with digital elements on their journey towards successfully demonstrating compliance – and beyond.
Get started now and prepare thoroughly for the new requirements of the Cyber Resilience Act. This will ensure that your products are fully compliant when the EU regulation comes into force. With our service modules designed to help you achieve CRA readiness, we support developers in understanding the wide-ranging requirements of the EU regulation, meeting them in good time and ensuring that your products comply with the necessary cybersecurity standards.
Get in touch nowThe criteria listed below may support a case for demonstrating conformity on the basis of Module H:
Note: Whilst Class I often covers security components for end users (e.g. password managers), Class II focuses more on infrastructure-critical components. The requirements for Class II products are therefore more stringent, as their compromise could have significant negative consequences for a large number of other products, users or critical infrastructure. Consequently, these products must undergo a conformity assessment by an authorised conformity assessment body (Notified Body), such as TÜV NORD.
The CRA calls for the implementation of a comprehensive quality assurance system.
If Module H is chosen to demonstrate compliance with the CRA requirements, the following must be taken into account:
DE
Other EU countries: The conformity assessment procedure may vary in some respects depending on the EU country. Please contact us; we will look into this for you.
The criteria listed below may support a case for demonstrating conformity on the basis of Module B/C:
The CRA requires the implementation of a comprehensive quality assurance system.
Module B – Type examination
As part of Module B, manufacturers submit an application for EU type examination to TÜV NORD as a notified body. The manufacturer’s obligations include:
The technical documentation must contain all the information necessary to assess the product’s conformity.
We therefore check:
Upon successful assessment, TÜV NORD issues an EU type-examination certificate.
Module C – Internal production control
Module C is mandatory in addition to Module B and relates to series production. The following principles apply:
Module C is based entirely on the EU type-examination certificate previously issued under Module B.
Other EU countries: The conformity procedure may vary in some respects depending on the EU country. Please contact us; we will look into this for you.
Key products with digital elements – Class I
Default products with digital elements
Note: Under the manufacturer’s declaration of conformity in Module A, the involvement of a notified body is not required.
The CRA sets out new minimum safety requirements for connected devices. In future, all connected products placed on the market within the EU must bear the CE marking. This visibly demonstrates to the public that the marked product meets the requirements of the CRA.
The CRA was adopted by the Council of EU Ministers of the Interior on 10 October 2024 and published in the Official Journal of the European Union on 20 November 2024 as Regulation (EU) 2024/2847.