Testing Services
Industry
EU CRAFDA & MDRPayment & FinanceNewsAbout Us
EN繁中
Contact Us
← Back to news
Knowledge

How Does CRA Conformity Assessment Work? Comparing Modules A, B+C and H

September 11, 2026
How Does CRA Conformity Assessment Work? Comparing Modules A, B+C and H

Following on from the previous article, “Is my product Class I or Class II?”, this one takes up the next question from the boss of Xiaowang Technology: we know the classification — now what?

Key points first

  • CRA conformity assessment offers three routes: Module A (self-declaration), Module B+C (EU-type examination plus conformity to type based on internal production control) and Module H (full quality assurance).
  • Class II products have no Module A option at all; a Notified Body has to be involved.
  • Class I can in theory be self-declared, but only if the harmonised standards formally cited by the EU have been applied in full — and as of September 2026 that condition cannot be met.
  • As of mid-2026, not one CRA Notified Body has been formally listed in the EU’s NANDO database. The scarce resource right now is a notified body with capacity, not a documentation template.

At the in-person seminar Applus+ Laboratories × SV Surveillance are holding in Taipei on Friday 18 September — with Jose Ruiz Gualda, Director of the Cybersecurity Business Unit at Applus+ Laboratories, travelling from Spain to present — the classification results companies bring along will be worked through one by one to discuss which conformity assessment route to take. This article lays out Xiaowang Technology’s answers first, so that you can ask sharper questions on the day.

Step one: three routes — start by asking who gets to sign

CRA conformity assessment ultimately answers one question: “You say the product meets the Annex I requirements — who confirms that this is true?” There are only three answers:

  • Module A (internal control): you confirm it and you sign it; no third party is involved.
  • Module B+C (EU-type examination plus conformity to type based on internal production control): a Notified Body examines the type once, after which series production of that same model is controlled by you.
  • Module H (full quality assurance): rather than examining one type, the Notified Body audits your entire quality management system and then keeps it under surveillance.

The previous article left a thread hanging: Xiaowang’s router is Class I, so in theory it could take Module A if the conditions were met. But as of September 2026 not a single CRA harmonised standard has been formally cited in the Official Journal of the European Union, so “if the conditions were met” cannot be cashed in at this stage. In other words, all three of Xiaowang’s products now have to take the Notified Body route seriously — the difference is only one of degree.

Step two: putting the three products into the three routes

ProductClassificationRealistic route todayWhy
Home routerClass IModule B+C (potentially switching to Module A once the standards are published)The condition for Class I self-declaration — applying the harmonised standards in full — cannot currently be met
Enterprise firewallClass IIModule B+C or Module H (no Module A option)The Regulation gives Class II no self-declaration route at all, published standards or not
Smart doorbellDefault productModule ANot on the Annex III or IV lists, so self-declaration was always available and is unaffected by the standards timetable
The three CRA conformity assessment routes side by side: Module A self-declaration, Module B+C EU-type examination plus internal production control, and Module H full quality assurance
The three conformity assessment routes at a glance

Having read the table, the boss asked a very practical question: “The router and the firewall both need a Notified Body, so why not just put both through the same process?”

That is precisely the choice between Module B+C and Module H.

Step three: Module B+C or Module H? It depends how fast your products turn over

Module B+C means “examine the type once, then manage series production yourself”. What the Notified Body does is review the technical documentation, confirm that the risk analysis is robust enough, and verify that the sample submitted really was built to the documentation. If it passes, an EU-type examination certificate is issued. From then on you manufacture to that approved type, ensuring yourself that every batch conforms, without submitting every batch for testing.

But if Xiaowang’s router goes through two or three revisions a year (a new chipset, a major firmware overhaul), then in principle any substantial change to the type means running the examination again — a hidden cost that is easy to overlook on a fast-turning product line.

Module H works the other way round: what the Notified Body audits is not “the type of this one product” but whether your company’s quality management system for design and development, production and vulnerability handling is good enough in itself. Once the system passes, different models and different versions produced under that system need not, in principle, be re-examined every time. The price is continuing surveillance: the Notified Body audits your system periodically to confirm that it is being operated the way you wrote it down.

Decision flow after classification: start from the classification result, check whether the applicable harmonised standards have been published, then look at how often the product is revised, leading to Module A, Module B+C or Module H
Choosing a module once the classification is settled

Xiaowang’s router line turns over quickly and carries many models, while the firewall is a small, relatively stable set of models — which is the original logic behind “many models, frequently revised” pointing to Module H and “few models, stable” being well served by Module B+C. But there is a detail here that often gets missed. If the router is already on Module H, the company’s whole design, development, production and vulnerability handling quality management system is inside the Notified Body’s audit scope. Whether the firewall then has to go through a separate Module B+C turns on whether the audit scope of that quality system also covers the firewall product line. If it can be covered, applying to the Notified Body to bring the firewall into the existing Module H audit scope is usually simpler than running a separate Module B+C — and saves a duplicated fee. Only where the firewall’s design, development and production processes differ too much from the router’s, so that the Notified Body considers them outside the original audit scope, does a separate Module B+C become necessary. Put differently, “one product, one module” is not the only answer: a company should also weigh whether to widen the audit scope of its quality system once and cover several product lines with a single Module H.

The actual choice still depends on the maturity of the company’s quality system, on budget, and on how the Notified Body prices the work. There is no standard answer.

Step four: what each of the three routes requires you to prepare

Whichever route you take, the underlying deliverable is the same: the eight items of Annex VII technical documentation (worth revisiting our SBOM series). What differs is who looks at it, and how closely:

  • Module A: the documentation stays in your hands and is produced only on request from market surveillance authorities. Nothing is submitted for review.
  • Module B+C: in addition to the technical documentation you need supporting evidence — above all, where the harmonised standards have not been applied in full, how you demonstrate that the requirement has nonetheless been met, together with the corresponding test reports. The Notified Body will select a type sample and test it.
  • Module H: in addition to the same technical documentation (for at least one representative model), you need a further set of quality system documentation — design and development processes, production quality control processes and vulnerability handling processes written up as formal policies, procedures and work instructions, robust enough to withstand an on-site audit.

The boss’s last question: can we file now?

No — and this is where things are currently stuck. Although the CRA’s rules on notified bodies (Articles 35 to 51) have applied since 11 June 2026, at the time of writing not one CRA Notified Body has been formally listed in the EU’s NANDO database. The Regulation requires Member States to “ensure that a sufficient number of notified bodies is available” by 11 December 2026, but progress is visibly short of that target.

CRA timeline pressure: 11 June 2026 the notified body rules apply, September 2026 today, 11 December 2026 Member States must ensure sufficient notified bodies, 11 December 2027 the CRA applies in full
The Notified Body timeline, and the squeeze it creates

In other words, what Xiaowang can do at this stage for its firewall — and for the router that cannot yet take the self-declaration route — is not “file”, but this: get the technical documentation, the risk assessment and, if Module H is chosen, the quality system documentation into shape, while starting conversations with the conformity assessment bodies that already run RED and EN 18031 testing and are planning CRA readiness services. Securing a place in the queue matters more than waiting until everything is ready.

In short

  • The three routes differ in who signs: under Module A you sign yourself; Module B+C is one type examination plus your own control of series production; under Module H your whole quality system is kept under continuing surveillance.
  • Class II has no Module A option: a Notified Body is required whether or not the standards have appeared.
  • Class I can in theory be self-declared, but the condition — published harmonised standards — cannot be met at this stage.
  • Fast-turning lines with many models can consider Module H; a few stable models suit Module B+C.
  • The scarce resource right now is not a documentation template but a notified body with capacity — which is why the queueing should start now.

You are also welcome to join the in-person seminar in Taipei on Friday 18 September, where you can put questions directly to a CRA expert from Spain and learn more about planning for 2027 compliance and estimating the time and cost of implementation. Registration: Register for the seminar

Frequently asked questions

Q: My product is Class I — can it really not be self-declared at all right now? Article 32(2) permits it in theory, but only where the harmonised standards or common specifications formally cited by the EU have been applied in full. As of September 2026 not one CRA harmonised standard has been cited in the Official Journal of the European Union, so that condition cannot currently be met. Once the standards are formally published, whether the self-declaration conditions are satisfied can be reassessed.

Q: Which costs more, Module B+C or Module H? There is no single answer; it depends on how the Notified Body prices the work and on the size of your product line. Broadly: Module B+C is charged per type, so the more models, the higher the total; Module H is charged as a quality system audit plus an annual surveillance fee, which can work out cheaper over time for a company with many models and a stable system. Actual quotations still have to come from a Notified Body or a consultant.

Q: No notified bodies have been listed yet — can I wait until both the standards and the bodies are ready before I start on the documentation? We would advise against it. The technical documentation, the risk assessment and (if Module H is chosen) the quality system documentation have to be prepared whichever route you eventually take, and that work is unrelated to whether any notified bodies have been listed. Waiting for designation before starting is very likely to land you in the traffic jam when everyone files at once.

Q: Does “self-declaration” under Module A mean no testing at all? No. Module A still requires the Annex VII technical documentation, a cybersecurity risk assessment and a conformity argument against each Annex I requirement in turn. The testing and documentation that need doing are unchanged; what differs is who signs and takes responsibility, and whether it goes to a third party for review — not whether the work gets done.

Glossary

  • Notified Body (NB) | A conformity assessment and certification body designated by an EU Member State and qualified to carry out third-party conformity assessment.
  • NANDO | The EU’s official database of notified bodies, showing which bodies have been formally designated and which product assessments they may carry out.
  • EU-type examination | A one-off technical review carried out by a Notified Body on a given “type” (a representative sample of the design); a certificate is issued once it passes.
  • Quality system | The documented management system a company establishes to ensure that design and development, production and vulnerability handling all meet the requirements. It is needed only on the Module H route.

References

All legal provisions and dates cited in this article are based on the following official documents:

By the Secure Vectors Surveillance Inc. (SV Surveillance) × Applus+ Laboratories consulting team

* This article is regulatory commentary, not legal advice. “Xiaowang Technology” is a fictional case. The designation of notified bodies and the harmonised standards timetable continue to move; before taking a formal decision, rely on the final versions published in the Official Journal of the European Union and on the results of a NANDO database search.

Keep Reading

More from the lab