InsideCRA
InsideCRA › Articles › Article 32

Regulation (EU) 2024/2847 · Chapter

Article 32 — Conformity assessment procedures for products with digital elements

Conformity assessment: the module system, decoded.

LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.

1.1. The manufacturer shall perform a conformity assessment of the product with digital elements and the processes put in place by the manufacturer to determine whether the essential cybersecurity requirements set out in Annex I are met. The manufacturer shall demonstrate conformity with the essential cybersecurity requirements by using any of the following procedures:
(a) the internal control procedure (based on module A) set out in Annex VIII;
(b) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII;
(c) a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII; or
(d) where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9).

2.2. Where, in assessing the compliance of an important product with digital elements that falls under class I as set out in Annex III and the processes put in place by its manufacturer with the essential cybersecurity requirements set out in Annex I, the manufacturer has not applied or has applied only in part harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least ‘substantial’ as referred to in Article 27, or where such harmonised standards, common specifications or European cybersecurity certification schemes do not exist, the product with digital elements concerned and the processes put in place by the manufacturer shall be submitted with regard to those essential cybersecurity requirements to either of the following procedures:
(a) the EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII; or
(b) a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII.

3.3. Where the product is an important product with digital elements that falls under class II as set out in Annex III, the manufacturer shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using any of the following procedures:
(a) EU-type examination procedure (based on module B) set out in Annex VIII followed by conformity to EU-type based on internal production control (based on module C) set out in Annex VIII;
(b) a conformity assessment based on full quality assurance (based on module H) set out in Annex VIII; or
(c) where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9) of this Regulation at assurance level at least ‘substantial’ pursuant to Regulation (EU) 2019/881.

4.4. Critical products with digital elements listed in Annex IV shall demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the following procedures:
(a) a European cybersecurity certification scheme in accordance with Article 8(1); or
(b) where the conditions in Article 8(1) are not met, any of the procedures referred to in paragraph 3 of this Article.

5.5. Manufacturers of products with digital elements qualifying as free and open-source software, which fall under the categories set out in Annex III, shall be able to demonstrate conformity with the essential cybersecurity requirements set out in Annex I by using one of the procedures referred to in paragraph 1 of this Article, provided that the technical documentation referred to in Article 31 is made available to the public at the time of the placing on the market of those products.

6.6. The specific interests and needs of microenterprises and small and medium-sized enterprises, including start-ups, shall be taken into account when setting the fees for conformity assessment procedures and those fees shall be reduced proportionately to their specific interests and needs.

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847

What this article does

Article 32 assigns the assessment procedures: default products may use internal control (Module A) among other routes; Annex III class I important products may use Module A only where harmonised standards, common specifications or a European cybersecurity certification scheme at 'substantial' level are applied in full, and otherwise go through Modules B+C or H; class II products use Modules B+C, H or such a scheme; and Annex IV critical products use a European cybersecurity certification scheme where available, otherwise the class II procedures F-026 F-023 F-025.

How to use it

Classification first, route second: establish whether Annex III or Annex IV names your product type, then read this article for the route that classification permits F-026. The route is a major driver of cost and timeline.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Ready to work through your obligations? Get your CE readiness verdict on CEMarque.