If you are engaged in businesses related to hardware, software, apps or IoT products with digital functions and plan to enter the EU market, you have most likely come across concepts such as CRA, Cyber Resilience Act, and new CE marking requirements. There are different views on CRA in the market: some believe the compliance cost is extremely high, some think small and medium-sized merchants don’t need to care about it, and others feel it’s just a process of affixing a label.
In fact, CRA conformity assessment is neither an unattainable threshold nor a perfunctory process — it is essentially a cybersecurity access rule set by the EU for products with digital functions. Taking the right path can significantly reduce compliance costs, while taking the wrong path may lead to severe penalties. Judging CRA conformity assessment usually proceeds in four steps: scope screening, product classification matching, assessment process implementation, and post-market maintenance, covering core content from entry-level to semi-proficient, helping you sort out most common compliance issues independently.
1. Entry-level Cognition: First Understand What CRA Conformity Assessment Is
1.1 Plain-language Definition and Core Logic
CRA is the abbreviation of the EU’s Cyber Resilience Act. CRA conformity assessment is the “cybersecurity access verification” for products with digital functions entering the EU market. Its core is not a one-time test score, but to prove that the product meets the security requirements of the CRA throughout its entire life cycle, from design and development to post-market vulnerability handling.

After the assessment is completed, three types of core compliance certificates need to be formed: first, complete technical documentation, which records all evidence of product security design, testing, and management; second, the EU Declaration of Conformity (DoC for short), a legal guarantee signed by the manufacturer, where the signatory bears full responsibility for the authenticity of compliance; third, the CE mark, a compliance mark affixed to the product.
It should be particularly noted that CRA compliance is not a one-time task — it covers the entire life cycle of the product, and post-market vulnerability remediation, security updates, and incident response are all necessary components of compliance.
1.2 Relationship with the CE Mark (Most Easily Confused)
Many people confuse the relationship between CRA and the CE mark. The CE mark is a declaration that the product has completed all applicable EU statutory compliance procedures, and the CRA is just one of the many EU regulations covered by the CE mark. The same product may be subject to multiple EU regulations at the same time (for example, radio equipment must comply with the Radio Equipment Directive, and toys must comply with the Toy Safety Directive). Only after the compliance procedures of all applicable regulations are completed can the CE mark be affixed.
The CE mark only represents that the manufacturer has completed the compliance process in accordance with regulations; it is neither a quality certification nor a proof of absolute safety.
1.3 Actual Consequences of Non-compliance
According to the final CRA regulation, penalties for violations are set at different levels, which are specifically determined by the market regulatory authorities of EU member states in accordance with the law based on the circumstances of the violation:
- The maximum fine is 4% of the global turnover in the previous fiscal year or 20 million euros, whichever is higher, applicable to serious violations;
- Other violations may be subject to lower fine caps, and the specific standards shall be subject to the formal provisions of the CRA and the regulatory enforcement rules of member states.
In addition to fines, penalties such as product sales bans, mandatory recalls, and public disclosure of violation information may also be imposed. At the same time, liability is not limited to manufacturers: importers and distributors within the EU who violate corresponding obligations may also bear joint liability, which in turn affects supply chain cooperation.
1.4 Key Transition Period Timeline
The CRA has clarified the statutory dates for phased application, and the specific arrangements are as follows:
- From September 11, 2026, the reporting obligation for known actively exploited vulnerabilities and serious security incidents will come into effect;
- From December 11, 2027, core compliance obligations such as conformity assessment, technical documentation, DoC signing, and CE marking for most products will be officially applicable.
The specific scope of obligations shall be subject to the provisions of the CRA and subsequent implementation guidelines.
It is recommended that enterprises start compliance preparation 6-12 months in advance to avoid omissions caused by rushing to supplement materials intensively near the deadline. The above preparation cycle is a practical suggestion, not a statutory deadline.
1.5 4 Most Common Initial Misconceptions for Beginners
Beginners who have just come into contact with CRA usually have four most basic cognitive misconceptions, which are quickly clarified here at once:
- It is not only hardware that needs to comply; pure software, apps, and embedded firmware are all within the scope of application as long as they have digital functions;
- It is not that small sellers or individual developers do not need to comply; all entities that place products on the EU market must perform their obligations, and only eligible micro and small enterprises can enjoy simplified policies;
- Conducting a penetration test does not equal compliance; the CRA requires life-cycle security management, and a single test cannot replace full-process compliance;
- The CE mark is not issued by a third-party institution; for ordinary products, it is affixed by the manufacturer itself, and randomly affixing the mark without completing the assessment constitutes fraud.
2. First Step Judgment: Whether the Product Needs Assessment and Which Category It Belongs To
After understanding the basic concepts, the first step is not to find an institution, but to conduct eligibility screening first: determine whether the product needs CRA assessment, which category it belongs to, and what corresponding responsibilities it has. This step is the starting point of the entire process; a wrong judgment will render all subsequent work invalid.
2.1 Three Elements for Quick Judgment of Whether Assessment Is Needed
To determine whether a product needs to undergo CRA conformity assessment, the following three conditions must be met simultaneously, none of which is dispensable:
First, whether the product has digital elements. Digital elements include embedded software/firmware, networking functions, remote data processing capabilities, updatable digital components, etc. Products that do not have any digital elements at all do not need to apply the CRA. It should be noted that remote services and supporting software provided in conjunction with hardware products will also be included in the scope of the product’s digital elements if they are a necessary part of the product’s functions.
Second, whether the product falls within the statutory exclusion scope of the CRA. If it belongs to a clearly excluded product category, the CRA does not need to be applied.
Third, whether the product is placed on the EU market or provided to EU users. The judgment basis includes whether it is sold for the EU region, provides EU official language versions, supports delivery or download within the EU, has customer service within the EU, etc., and has nothing to do with whether the enterprise is registered in the EU. It should be noted that if SaaS or remote data processing functions are a necessary part of the product’s digital functions, they need to be included in the product scope judgment; whether independent online services are applicable needs to be checked separately against the CRA’s definitions of “products with digital elements” and remote data processing solutions, and cannot be directly equated.
2.2 Scope of Application and Exclusion Boundaries
The scope of application of the CRA covers all products with digital elements provided to EU users, including smart home appliances, consumer electronics, IoT devices, pure software, apps, industrial control equipment, etc. The following are common categories of statutory exclusions or partial exemptions, and the specifics shall be subject to the formal provisions of the CRA:
- Military and national defense-related products are usually covered by special EU regulations in the defense field, and products that meet the statutory exclusion conditions of the CRA are not subject to the CRA; if they are for dual civilian and commercial use, or the relevant digital functions are not covered by special regulations, the scope of application still needs to be checked separately;
- Aerospace-related products are usually covered by special regulations of the European Union Aviation Safety Agency (EASA), and products that meet the statutory exclusion conditions of the CRA are not subject to the CRA; if they are for dual civilian and commercial use, or the relevant digital functions are not covered by special regulations, the scope of application still needs to be checked separately;
- Medical devices and in vitro diagnostic medical devices are subject to the Medical Devices Regulation (MDR) and In Vitro Diagnostic Medical Devices Regulation (IVDR). If their cybersecurity requirements have covered the corresponding content of the CRA, the CRA does not need to be applied repeatedly within the covered scope;
- Motor vehicles, trailers and related components are subject to vehicle cybersecurity regulations such as R155 of the United Nations Economic Commission for Europe (UNECE), and the CRA does not need to be applied repeatedly within the corresponding scope.
Regarding the application boundary of open source software, non-commercial open source software itself is usually exempt. If open source components are integrated into commercial products and placed on the EU market, the manufacturer is responsible for the security of the entire product (including the integrated open source components), and needs to retain relevant evidence such as component source, version, and vulnerability tracking. The Software Bill of Materials (SBOM for short) is an important form of evidence for recording component information.
In addition, pure offline services themselves are usually not directly subject to the CRA, but if the service is a necessary functional component bound to a digital product, the corresponding digital functions need to be included in the compliance scope of the product.
2.3 Division of Responsibilities for Different Market Roles
The CRA has a clear division of obligations for different roles in the supply chain, with the core responsibility borne by the manufacturer:
- Manufacturer: Is the first responsible party for compliance, responsible for conducting conformity assessment, preparing technical documentation, signing the DoC, affixing the CE mark, and fulfilling post-market security maintenance obligations.
- EU Importer: Before placing a product on the EU market, it is necessary to verify whether the manufacturer has completed the compliance procedures, whether there is a valid DoC and necessary technical documentation, and non-compliant products shall not be placed on the market; it is necessary to mark its own name and contact information on the product, and cooperate with the investigation of regulatory authorities.
- Distributor: It is necessary to ensure that the product is affixed with the CE mark and accompanied by the required compliance documents, and shall not sell obviously non-compliant products; it must be able to trace the upstream suppliers and downstream purchasers of the product, and cooperate with random inspections by regulatory authorities.
- Authorized Representative: Non-EU manufacturers may entrust an authorized representative within the EU in writing to handle matters such as regulatory communication and information provision on their behalf, but the core compliance responsibility still rests with the manufacturer.
2.4 Product Classification: Matching the Corresponding Assessment Path
The CRA divides products with digital elements into four categories, and different categories correspond to different assessment paths. The specific classification must be based on the lists of Annex III (important products) and Annex IV (critical products) officially released by the EU CRA, and shall not be judged solely by industry name. To facilitate entry-level understanding, the core differences of the four types of products are summarized below:
| Product Category | Definition Basis | Typical Examples (for reference only, not equal to final classification; need to check against the product definitions, functions, uses and scenarios of Annex III/IV item by item) | Assessment Path Description |
|---|---|---|---|
| Ordinary products | Not listed in Annex III or Annex IV | Smart desk lamps, ordinary fitness apps, small household smart devices | Self-assessment conducted by the manufacturer, no participation of a third-party notified body required |
| Important Products Class I | Part 1 of Annex III | Network management/cybersecurity-related equipment (such as specific router categories), browsers, identity management software, etc. that meet the definitions in Part 1 of Annex III | If applicable harmonized standards/common specifications are fully adopted, self-assessment is possible; if not fully adopted, a notified body is required to participate |
| Important Products Class II | Part 2 of Annex III | Only products that meet the functions, uses and risk scenarios defined in Part 2 of Annex III (such as smart door locks, payment terminals, industrial control software in specific scenarios) fall into this category | Usually requires an EU notified body to participate in the conformity assessment |
| Critical Products | Annex IV | Only products such as industrial control systems for critical infrastructure and core identity authentication systems explicitly listed in Annex IV, and must meet the deployment scenarios and permission requirements specified in the list | Must be implemented strictly in accordance with the assessment modules required by the corresponding annex, and must involve a notified body |
Note: The above examples are only used to help understand the classification logic, and the final classification must be based on the latest list officially released by the EU.
If an enterprise meets the definition criteria of an EU Small and Medium-sized Enterprise (SME), it can apply for some simplified policies, such as appropriate relaxation of some technical requirements and fee reductions, but core compliance obligations (such as technical documentation retention, DoC signing, and post-market maintenance) cannot be exempted.
3. General Pre-assessment Preparation: 3 Things to Do for All Paths
Whether taking the self-assessment path or the assessment path with the participation of a notified body, there are three preparatory tasks that must be completed in advance. Doing these tasks well in advance can greatly improve the efficiency of subsequent assessments and reduce rework.
3.1 Align with the Core Security Requirements of the CRA, Rectify First Then Assess
The core security requirements of the CRA can be summarized in plain language as four points: security functions are enabled by default, able to defend against common cyber attacks, support pushing security patches, and clearly inform users of security risks. It should be noted that this is only an entry-level summary, not a complete compliance checklist, and the specific requirements shall be subject to the formal provisions of the CRA and supporting standards.
Enterprises do not need to interpret the regulations item by item by themselves, and can refer to the CRA harmonized standards published in the Official Journal of the European Union (OJEU). Harmonized standards are equivalent to officially recognized “compliance reference solutions”, but the presumption of conformity requires three prerequisites: first, the standard has been officially published in the Official Journal of the European Union; second, the standard applies to your product category; third, the product fully complies with all requirements of the standard. Only when these three conditions are met at the same time can it be directly presumed that the product meets the basic CRA requirements covered by the standard; if the standard has not been published, only partially covers the requirements, or the product does not fully comply with the standard, it is still necessary to prove compliance through risk assessment, special testing, etc.
In specific operations, you can first list all digital functions of the product, check them one by one against applicable harmonized standards or regulatory requirements, complete rectification if any gaps are found, and then enter the formal assessment phase.
3.2 Prepare Core Technical Documentation (Core Compliance Evidence)
Technical documentation is the core evidence to prove that the product meets the CRA requirements, and is also the focus of regulatory random inspections. The necessary content usually includes: product description and version boundaries, risk assessment report and mitigation measures, security design and development records, security test report, Software Bill of Materials (SBOM), user security guidelines, security update support plan, etc.
Regarding the obligation to retain technical documentation, the following points need to be clarified:
- The subject of the retention obligation is the manufacturer;
- The retention period is calculated from the date when the product is last placed on the EU market, and shall be retained for at least 10 years;
- The retention form can be paper or electronic, and must be authentic, complete and traceable.
Many people confuse the technical documentation retention period with the security update support period. Here is a clear distinction: the 10-year retention of technical documentation is a requirement for regulatory verification, and only refers to the data retention period; while the security update support period refers to the period during which the manufacturer promises to provide security patches for the product, which needs to be determined in combination with the expected service life of the product, risk level and statutory requirements of the CRA. The two are not the same concept and cannot be equated. The manufacturer must clearly inform users of the support period for security updates in the product description.
3.3 Build a Post-market Security Maintenance Framework
The CRA requires life-cycle compliance, so before the product is launched on the market, it is necessary to build a post-market security maintenance framework and clarify three core mechanisms:
First, vulnerability receiving channels, which need to be publicly accessible, such as a dedicated vulnerability feedback email address and official website submission page, to facilitate researchers or users to report vulnerabilities;
Second, the security update management mechanism, which clarifies the remediation time limit for vulnerabilities of different risk levels and the update push process, to ensure that security updates during the support period can be delivered to users in a timely manner. For entry-level learners, you can first use “at least 5 years for ordinary products, longer for high-risk/critical products” as a preliminary judgment benchmark; if the expected service life of the product is shorter than 5 years or official detailed rules provide otherwise, adjust it in combination with the risk assessment conclusion, and the relevant basis shall be retained in the product description, risk assessment report and technical documentation. When formally determining the support period, a comprehensive judgment shall be made in combination with the expected service life of the product, risk level and the statutory minimum requirements of the CRA, and the final period shall be clearly informed in the user documentation.
Third, the security incident reporting mechanism, which clarifies incident judgment standards, internal handling processes, responsible persons and reporting channels, to ensure timely response when serious incidents occur.
4. Ordinary Products: Full Process of Self-assessment
If your product is an ordinary product not listed in Annex III or Annex IV, you can take the manufacturer’s self-assessment path, without paying fees to a third-party notified body, as long as you conduct the assessment in accordance with the process and retain complete evidence.
4.1 Self-check Item by Item According to Harmonized Standards
The core of self-assessment is to verify the compliance of the product item by item against applicable harmonized standards or regulatory requirements. The basis for self-check is the latest list of CRA harmonized standards published in the Official Journal of the European Union, and the inspection scope covers all applicable requirements such as product security functions, vulnerability management mechanisms, update mechanisms, and user notification.
Complete records must be kept during the self-check process, and the compliance status, verification methods, and test results of each requirement must be clearly recorded to ensure traceability. If non-conformities are found, rectification must be completed first, and then the corresponding items must be re-inspected, and no fluke mentality is allowed.
4.2 Sign the EU Declaration of Conformity (DoC)
After all self-checks are passed, the manufacturer needs to sign the EU Declaration of Conformity (DoC). The DoC is a legally binding guarantee, and the signatory must bear full legal responsibility for the authenticity of the product’s compliance, and shall not sign it arbitrarily.
A qualified DoC usually contains the following information: product model, version and coverage, manufacturer’s name and contact information, specific CRA clauses complied with, harmonized standards or other specifications used, if a notified body is involved, the name and number of the body must be indicated, and the signature and date of the responsible person.
The DoC must be publicly accessible, and the manufacturer should provide the DoC on the official website or in the accompanying documents of the product to facilitate inspection by regulatory authorities and users. If multiple models share one DoC, all covered models, versions and difference boundaries must be clearly marked, and it shall not be used beyond the scope.
4.3 Affix the CE Mark in a Standardized Manner
After signing the DoC and completing all compliance procedures, the CE mark can be affixed; affixing it in advance is an illegal act. The affixing of the CE mark must follow the EU general rules:
- In principle, it should be affixed to the product body or permanent data nameplate, clearly visible and not easy to wipe off;
- If it cannot be affixed to the body due to the product’s size, material, nature, etc., it can be affixed to the outer packaging or accompanying documents;
- The height of the mark is in principle no less than 5mm. For miniature or special-shaped products, it can be appropriately reduced according to general rules, but must be clearly distinguishable.
The CE mark is affixed by the manufacturer itself, not a certificate issued by a third-party institution. Affixing the CE mark only means that the product has completed the applicable compliance procedures, and does not exempt the manufacturer from subsequent compliance responsibilities.
4.4 Retain a Full Set of Materials for Inspection
After the self-assessment is completed, a full set of compliance materials must be sorted out and retained, including self-check records, technical documentation, DoC, update plans, etc. The obligations of different entities for data retention and provision are different:
- The manufacturer must keep a full set of compliance materials and provide them within the time limit required by the regulatory authority in accordance with the law;
- EU importers do not necessarily keep the complete technical files of the manufacturer by themselves, but before placing the product on the EU market, they must verify whether the DoC, CE mark, manufacturer information and necessary safety instructions are complete, and ensure that when required by the regulatory authority, they can obtain or assist in providing relevant compliance materials within the specified time limit;
- Distributors must be able to trace the upstream source of the product and cooperate with the investigation and random inspection of regulatory authorities.
5. Conformity Assessment Process Requiring Participation of a Notified Body
If the product belongs to Important Products Class II, Critical Products, or if Important Products Class I do not fully adopt applicable harmonized standards/common specifications, an EU Notified Body (NB for short) is required to participate in the conformity assessment. This part has stricter requirements and is more prone to pitfalls, so special attention is needed.
5.1 Screen Qualified Notified Bodies
A notified body is a third-party institution designated by the competent authority of an EU member state and qualified for compliance assessment of specific product categories, and the assessment documents issued by it have legal effect. It should be noted that there is no unified concept of “CRA certificate”. The names and formats of documents issued by different institutions and different assessment modules may be different, and ordinary third-party test reports cannot replace the compliance assessment of an NB.
To query NBs with CRA assessment qualifications, you can search through the EU’s official NANDO database (Notified Bodies database). Currently, CRA-related NB qualifications are being gradually updated, and the actual query results in the database shall prevail. When selecting an NB, you must confirm that it has the assessment authorization for the corresponding product category. Not all NBs can conduct CRA assessment for your product, and documents issued by institutions without corresponding qualifications are invalid.
5.2 Submit Assessment Application and Materials
After selecting a qualified NB, you can submit a formal assessment application and related materials. The materials that usually need to be submitted include: product samples, complete technical documentation, manufacturer’s self-test report, assessment application letter, etc.
After receiving the materials, the NB will first conduct a preliminary review to check whether the materials are complete and meet the basic requirements. If the materials are incomplete, the manufacturer must supplement them within the time limit specified by the NB, and the formal assessment phase will not start until the supplementation is completed.
5.3 NB Testing and Compliance Audit
The assessment of an NB usually covers three aspects: first, technical documentation review, to verify whether the technical documentation submitted by the manufacturer meets the CRA requirements; second, product security performance testing, to verify whether the product’s security functions meet the standards through actual testing; third, post-market maintenance plan review, to confirm that the manufacturer has the ability to fulfill post-market obligations.
If the assessment fails, the NB will issue rectification opinions, and the manufacturer can apply for retesting after completing the rectification. It should be noted that if the rectification involves major changes to the product’s core architecture, main security functions or threat model, a full assessment must be re-conducted, and it is not allowed to pass directly after testing only the rectified parts.
5.4 Ongoing Obligations After Assessment
After passing the NB assessment, it is still necessary to continue to fulfill compliance obligations. There is no unified validity period or supervision frequency for assessment documents. The specific validity period, annual supervision or regular review requirements shall be subject to the rules of the corresponding assessment module and the official documents issued by the NB, and relevant requirements must be included in the post-market compliance plan in advance.
After obtaining the assessment documents, it is recommended to establish a special compliance ledger to record core information such as document name, number, covered product model/version range, validity period or review arrangement, and change notification trigger conditions; before each adjustment of major product functions, security architecture, or networking capabilities, first check against the ledger whether it is necessary to notify the NB or re-assess, and shall not continue to sell after making changes without authorization.
If there are major changes to the product’s core functions, security architecture, or networking capabilities that may affect the results of the conformity assessment, it is necessary to promptly notify the NB and apply for re-assessment or update of the assessment documents, and shall not continue to sell after making changes without authorization.

6. Post-market Maintenance: Assessment Is Not a Once-and-for-all Matter
Many people think that everything is fine after completing the assessment and affixing the CE mark. In fact, the core requirement of the CRA is life-cycle compliance, and post-market maintenance of products is the focus of regulatory random inspections, and also the most easily overlooked part.
6.1 Vulnerability Management and Security Update Obligations
Manufacturers need to establish a continuous vulnerability monitoring and handling mechanism, remediate discovered vulnerabilities in a timely manner according to risk levels, and push security updates to users. For serious vulnerabilities, it is also necessary to promptly inform users of temporary protective measures.
Within the promised security update support period that meets regulatory requirements, all security updates shall not be forcibly charged to users, and users shall not be required to pay for version upgrades to obtain security vulnerability remediation. The specific time limit for vulnerability remediation shall be determined in combination with the vulnerability risk level and the statutory requirements of the CRA.
6.2 Vulnerability and Security Incident Reporting Obligations
The CRA stipulates two types of situations that require reporting, namely known actively exploited vulnerabilities and serious security incidents. Reporting is usually divided into stages such as early warning, initial report, progress report, and final report. All reports are submitted through the EU single reporting platform, and the information will be circulated to ENISA, relevant CSIRTs and competent market regulatory authorities in accordance with the CRA and ENISA operating rules; whether the manufacturer needs to directly notify specific member state institutions separately shall be subject to official guidelines and case-specific requirements. The specific time limit requirements for the two types of situations are different:
- Known actively exploited vulnerabilities: If the manufacturer confirms that the vulnerability in the product has been actively exploited by hackers, it must submit an early warning within 24 hours after confirmation, and then supplement complete vulnerability details, impact scope, mitigation measures and other content as required.
- Serious security incidents: If a serious security incident occurs such as causing large-scale data leakage, affecting public safety, or a large number of products being attacked, an early warning must be submitted within 24 hours after the incident is discovered, and a complete initial report must be submitted within 72 hours. Subsequently, progress reports and final summary reports must also be submitted as required by the regulator.
The specific reporting scope, platform, materials and time limits shall be subject to the formal provisions of the CRA and the operational guidelines issued by ENISA.
6.3 Compliance Judgment of Product Changes
Products are not prohibited from being changed after being launched on the market, but any change must first be judged for its impact on compliance, and shall not be sold arbitrarily after changes.
If it is a minor vulnerability fix or small function optimization that does not change the product’s core security architecture, threat model and basic functions, it is only necessary to update the risk assessment records, version information and technical documentation;
If it involves major changes, such as adding new networking functions, modifying the core identity authentication mechanism, adjusting the security architecture, etc., which may affect the compliance with the basic requirements of the CRA, a conformity assessment must be re-conducted; for products involving NB assessment, it is also necessary to apply to the NB for change confirmation or re-assessment.
For OTA (Over-the-Air) remote upgrades, in addition to following the above change judgment rules, it is also necessary to ensure that the upgrade channel has security mechanisms such as integrity check, signature verification, version traceability, and failure rollback, to prevent the upgrade process from being tampered with or introducing new security risks. The upgraded product still needs to meet all applicable requirements of the CRA.
6.4 Cooperate with Regulatory Random Inspections
Market regulatory authorities of EU member states will conduct random inspections on products on the market. The focus of random inspections includes the basis for product classification, the authenticity of technical documentation, the consistency between the CE mark and the DoC, vulnerability handling records, incident reporting records, etc.
The cooperation obligations of different entities are different: manufacturers must provide a full set of compliance materials as required; importers and distributors must provide compliance information they hold or should obtain in accordance with the law within the time limit required by the regulatory authority, and cooperate in tracing the source and flow of products.
7. Special Scenarios and Pitfall Avoidance Guide
In actual operation, you will encounter many scenarios with blurred boundaries, and there are also many common cognitive misconceptions. Here we sort them out uniformly to help you avoid detours.
7.1 Judgment Logic for Four Types of Boundary Scenarios
Compliance Responsibility for Open Source Components
Non-commercial open source software maintenance itself does not need to bear CRA responsibility, but for open source components integrated into commercial products, the security responsibility is borne by the manufacturer. In practice, it is necessary to establish a full-process management mechanism for open source components: including component access review, version locking, continuous monitoring of public vulnerabilities (CVE), patch verification, regular SBOM update records, etc., to ensure that the source of open source components is traceable and vulnerabilities can be handled in a timely manner.
Handling of Concurrent Multiple Regulations
If the product is subject to both the CRA and other EU special regulations (such as the RED Radio Equipment Directive, MDR Medical Devices Regulation, motor vehicle cybersecurity regulations, etc.), it must be handled according to the following logic:
First, check the statutory exclusion clauses of the CRA. If the product belongs to a clearly excluded category, the CRA does not need to be applied;
If it is not within the exclusion scope, compare the cybersecurity requirements of other regulations and the CRA: for parts already covered by other regulations, compliance evidence can be reused; for CRA requirements not covered, supplementary assessment is required.
The CRA cannot be directly exempted just because the product is subject to other regulations; the coverage of requirements must be checked item by item.
Compliance Judgment for Second-hand/Refurbished Equipment
Whether second-hand or refurbished equipment needs to undergo CRA assessment again depends on three core conditions:
First, whether it constitutes “re-placing on the EU market”. Non-commercial second-hand resale between individuals is usually not regarded as re-placing on the market, and no re-compliance is required;
Second, whether the product has undergone substantial changes. If it is only appearance refurbishment or replacement of non-digital components, without changing digital functions and security architecture, it is considered that no substantial change has occurred; if the core firmware is replaced or new digital functions are added, it is considered a substantial change;
Third, whether the original compliance documents still cover the current product version.
If a merchant re-places second-hand/refurbished products on the EU market for commercial purposes, and the product has not undergone substantial changes and the original compliance documents are still valid, it is necessary to verify the integrity of the original compliance materials; if the product has undergone substantial changes, a conformity assessment must be re-conducted.
Compliance Responsibility for Parallel Imports
Parallel import refers to the import of genuine products that have been legally marketed outside the EU into the EU market for sale without the authorization of the brand owner. In this case, the parallel importer must bear the compliance responsibility of an EU importer, and must verify whether the product meets the CRA requirements and whether it has complete compliance documents and CE marks. Non-compliant products shall not be placed on the market. Parallel imports do not exempt the original manufacturer from core compliance responsibilities.
7.2 6 Most Common Compliance Pitfalls
There are six common cognitive misconceptions in practice, each of which may lead to compliance risks. Among them, basic cognitive misconceptions have been clarified in the entry-level part. Here we focus on supplementing actionable verification actions and uncovered special situations:
- Misconception: Only hardware products need to comply with CRA, pure software, apps, and embedded firmware do not
Verification action: List all digital elements of the product (including embedded firmware, supporting software, bound remote services) and distribution channels, and judge one by one against the scope of application of the CRA. It is not allowed to exclude application just because the product form is software. - Misconception: Small sellers and individual developers do not need to comply with CRA
Verification action: First confirm whether you meet the EU SME (Small and Medium-sized Enterprise) definition, then understand the applicable simplified clauses accordingly. You shall not be exempted from all compliance obligations directly on the grounds of “small scale”. - Misconception: Having ISO27001 certification or a single penetration test equals CRA compliance
Correct explanation: ISO27001 is a certification for the enterprise’s internal information security management system, which regulates internal processes of the enterprise rather than the security of specific products; a single penetration test can only reflect the security status at the time of testing, and neither can replace the product life-cycle security management and conformity assessment required by the CRA.
Verification action: Distinguish between system certification and product compliance requirements, sort out the full life-cycle security evidence chain of the product from design, development to post-market maintenance, and confirm whether all applicable clauses of the CRA are covered. - Misconception: The CE mark is issued by a third-party institution, and affixing it equals absolute safety
Verification action: Check whether the assessment of all applicable regulations has been completed, the DoC has been signed, and a complete evidence chain has been retained before affixing the CE mark. The CE mark shall not be regarded as a security endorsement by a third-party institution. - Misconception: Only those with physical stores in the EU need to comply, online sales/downloads do not
Verification action: Sort out all sales and distribution channels of the product (including cross-border e-commerce, official website downloads, provision of remote functions bound to products, etc.), and confirm whether there are situations of provision to EU users; if independent SaaS or online services are involved, the scope of application needs to be checked separately against the CRA’s definitions of “products with digital elements” and remote data processing solutions, and shall not be directly excluded or included just because there are no offline stores. - Misconception: Class I important products definitely do not need assessment by a third-party notified body
Correct explanation: If Class I important products fully adopt applicable harmonized standards or common specifications, they can take the self-assessment path; if not fully adopted, a notified body is required to participate in the assessment.
Verification action: Check against the officially published list of harmonized standards, confirm item by item whether the product fully meets the requirements of all applicable standards, and shall not directly judge that no NB participation is required solely based on the product category.
7.3 Practical Tips to Reduce Compliance Costs
CRA compliance costs vary greatly depending on factors such as product category, complexity, rectification scale, and whether the participation of a notified body is required. The following four practical tips can help enterprises reasonably control costs:
First, front-load security requirements in the design stage. Integrating CRA security requirements in the early stage of product design, such as default security configuration, security update channels, vulnerability response mechanisms, SBOM management framework, etc., is usually less costly than centralized rectification before launch. In particular, the front-loaded design of underlying capabilities such as authentication mechanisms and log auditing can avoid the investment in later architecture reconstruction and repeated testing; the specific savings ratio depends on product complexity, number of defects, and whether NB retesting is required.
Second, prioritize the use of official harmonized standards. Developing products in accordance with the CRA harmonized standards published in the Official Journal of the European Union can not only directly obtain the presumption of conformity for corresponding requirements, but also reduce the workload of self-checks and additional testing.
Third, accurately match the assessment path. First confirm the product classification through the official list. Ordinary products take the self-assessment path, no need to pay third-party institution fees; if a notified body is required to participate, screen institutions with corresponding qualifications in advance to avoid invalid investment.
Fourth, prepare compliance evidence in advance. Sort out materials such as technical documentation, SBOM, test records, and vulnerability management processes simultaneously during the development process to avoid the additional cost of intensively making up materials near the deadline; enterprises that meet the SME standards can proactively apply for simplified policies to reduce the compliance burden.
Core Judgment Abilities You Can Master After Learning
After reading the full text, you will have the following core judgment abilities for CRA conformity assessment:
- Able to quickly judge whether a product needs to undergo CRA conformity assessment through the three elements of digital functions, exclusion scope, and market orientation;
- Able to accurately match product classification against the EU official annex list, and select the corresponding self-assessment or third-party notified body assessment path;
- Able to sort out the core steps of assessment, and clarify the preparation requirements for the three core compliance certificates: technical documentation, EU Declaration of Conformity (DoC), and CE mark;
- Able to clearly grasp the three core post-market compliance obligations: vulnerability management and security updates, security incident reporting, and compliance judgment of product changes;
- Able to make basic judgments based on core boundaries for special scenarios such as OTA upgrades, open source components, concurrent multiple regulations, second-hand/refurbished equipment, and parallel imports;
- Able to identify 6 types of the most common CRA compliance misconceptions and avoid regulatory risks caused by cognitive deviations.