
Following on from the previous article, “Is my product Class I or Class II?”, this one takes up the next question from the boss of Xiaowang Technology: we know the classification — now what?
Key points first
At the in-person seminar Applus+ Laboratories × SV Surveillance are holding in Taipei on Friday 18 September — with Jose Ruiz Gualda, Director of the Cybersecurity Business Unit at Applus+ Laboratories, travelling from Spain to present — the classification results companies bring along will be worked through one by one to discuss which conformity assessment route to take. This article lays out Xiaowang Technology’s answers first, so that you can ask sharper questions on the day.
CRA conformity assessment ultimately answers one question: “You say the product meets the Annex I requirements — who confirms that this is true?” There are only three answers:
The previous article left a thread hanging: Xiaowang’s router is Class I, so in theory it could take Module A if the conditions were met. But as of September 2026 not a single CRA harmonised standard has been formally cited in the Official Journal of the European Union, so “if the conditions were met” cannot be cashed in at this stage. In other words, all three of Xiaowang’s products now have to take the Notified Body route seriously — the difference is only one of degree.
| Product | Classification | Realistic route today | Why |
|---|---|---|---|
| Home router | Class I | Module B+C (potentially switching to Module A once the standards are published) | The condition for Class I self-declaration — applying the harmonised standards in full — cannot currently be met |
| Enterprise firewall | Class II | Module B+C or Module H (no Module A option) | The Regulation gives Class II no self-declaration route at all, published standards or not |
| Smart doorbell | Default product | Module A | Not on the Annex III or IV lists, so self-declaration was always available and is unaffected by the standards timetable |

Having read the table, the boss asked a very practical question: “The router and the firewall both need a Notified Body, so why not just put both through the same process?”
That is precisely the choice between Module B+C and Module H.
Module B+C means “examine the type once, then manage series production yourself”. What the Notified Body does is review the technical documentation, confirm that the risk analysis is robust enough, and verify that the sample submitted really was built to the documentation. If it passes, an EU-type examination certificate is issued. From then on you manufacture to that approved type, ensuring yourself that every batch conforms, without submitting every batch for testing.
But if Xiaowang’s router goes through two or three revisions a year (a new chipset, a major firmware overhaul), then in principle any substantial change to the type means running the examination again — a hidden cost that is easy to overlook on a fast-turning product line.
Module H works the other way round: what the Notified Body audits is not “the type of this one product” but whether your company’s quality management system for design and development, production and vulnerability handling is good enough in itself. Once the system passes, different models and different versions produced under that system need not, in principle, be re-examined every time. The price is continuing surveillance: the Notified Body audits your system periodically to confirm that it is being operated the way you wrote it down.

Xiaowang’s router line turns over quickly and carries many models, while the firewall is a small, relatively stable set of models — which is the original logic behind “many models, frequently revised” pointing to Module H and “few models, stable” being well served by Module B+C. But there is a detail here that often gets missed. If the router is already on Module H, the company’s whole design, development, production and vulnerability handling quality management system is inside the Notified Body’s audit scope. Whether the firewall then has to go through a separate Module B+C turns on whether the audit scope of that quality system also covers the firewall product line. If it can be covered, applying to the Notified Body to bring the firewall into the existing Module H audit scope is usually simpler than running a separate Module B+C — and saves a duplicated fee. Only where the firewall’s design, development and production processes differ too much from the router’s, so that the Notified Body considers them outside the original audit scope, does a separate Module B+C become necessary. Put differently, “one product, one module” is not the only answer: a company should also weigh whether to widen the audit scope of its quality system once and cover several product lines with a single Module H.
The actual choice still depends on the maturity of the company’s quality system, on budget, and on how the Notified Body prices the work. There is no standard answer.
Whichever route you take, the underlying deliverable is the same: the eight items of Annex VII technical documentation (worth revisiting our SBOM series). What differs is who looks at it, and how closely:
No — and this is where things are currently stuck. Although the CRA’s rules on notified bodies (Articles 35 to 51) have applied since 11 June 2026, at the time of writing not one CRA Notified Body has been formally listed in the EU’s NANDO database. The Regulation requires Member States to “ensure that a sufficient number of notified bodies is available” by 11 December 2026, but progress is visibly short of that target.

In other words, what Xiaowang can do at this stage for its firewall — and for the router that cannot yet take the self-declaration route — is not “file”, but this: get the technical documentation, the risk assessment and, if Module H is chosen, the quality system documentation into shape, while starting conversations with the conformity assessment bodies that already run RED and EN 18031 testing and are planning CRA readiness services. Securing a place in the queue matters more than waiting until everything is ready.
You are also welcome to join the in-person seminar in Taipei on Friday 18 September, where you can put questions directly to a CRA expert from Spain and learn more about planning for 2027 compliance and estimating the time and cost of implementation. Registration: Register for the seminar
Q: My product is Class I — can it really not be self-declared at all right now? Article 32(2) permits it in theory, but only where the harmonised standards or common specifications formally cited by the EU have been applied in full. As of September 2026 not one CRA harmonised standard has been cited in the Official Journal of the European Union, so that condition cannot currently be met. Once the standards are formally published, whether the self-declaration conditions are satisfied can be reassessed.
Q: Which costs more, Module B+C or Module H? There is no single answer; it depends on how the Notified Body prices the work and on the size of your product line. Broadly: Module B+C is charged per type, so the more models, the higher the total; Module H is charged as a quality system audit plus an annual surveillance fee, which can work out cheaper over time for a company with many models and a stable system. Actual quotations still have to come from a Notified Body or a consultant.
Q: No notified bodies have been listed yet — can I wait until both the standards and the bodies are ready before I start on the documentation? We would advise against it. The technical documentation, the risk assessment and (if Module H is chosen) the quality system documentation have to be prepared whichever route you eventually take, and that work is unrelated to whether any notified bodies have been listed. Waiting for designation before starting is very likely to land you in the traffic jam when everyone files at once.
Q: Does “self-declaration” under Module A mean no testing at all? No. Module A still requires the Annex VII technical documentation, a cybersecurity risk assessment and a conformity argument against each Annex I requirement in turn. The testing and documentation that need doing are unchanged; what differs is who signs and takes responsibility, and whether it goes to a third party for review — not whether the work gets done.
All legal provisions and dates cited in this article are based on the following official documents:
By the Secure Vectors Surveillance Inc. (SV Surveillance) × Applus+ Laboratories consulting team
* This article is regulatory commentary, not legal advice. “Xiaowang Technology” is a fictional case. The designation of notified bodies and the harmonised standards timetable continue to move; before taking a formal decision, rely on the final versions published in the Official Journal of the European Union and on the results of a NANDO database search.