Article 32 decides which conformity assessment procedure applies to a product with digital elements. Default products may use internal control (Module A). Annex III Class I products may use it only where the relevant harmonised standards, common specifications or a qualifying European cybersecurity certification scheme are fully applied; otherwise a third-party route applies. Class II products always require a third party, and Annex IV critical products follow a certification scheme where the Commission has required one. The procedures themselves are set out in Annex VIII.
The Product Tiers Article 32 Works From
Article 32 assigns routes by product tier, and the tiers come from Articles 7 and 8:
Default: any product with digital elements listed in neither Annex III nor Annex IV. This is the largest category by far.
Important, Annex III Class I: nineteen categories, among them identity and privileged access management, browsers, password managers, anti-malware software, VPNs, network management systems, SIEM, boot managers, PKI and certificate issuance software, network interfaces, operating systems, routers, modems and switches, microprocessors and microcontrollers with security-related functionality, smart home assistants, smart home products with security functions such as locks and cameras, connected toys with social or location features, and personal wearables with a health monitoring purpose.
Important, Annex III Class II: four higher-risk categories - hypervisors and container runtimes, firewalls and intrusion detection or prevention systems, tamper-resistant microprocessors, and tamper-resistant microcontrollers.
Critical, Annex IV: hardware devices with security boxes, smart meter gateways and other devices for advanced security purposes including secure cryptoprocessing, and smartcards or similar devices including secure elements.
Classification follows what a product does rather than what it is called, and it is the manufacturer's own determination, evidenced in the technical documentation.
Module A: Internal Control
Internal control is the self-assessment route in Annex VIII. Under Module A the manufacturer carries out the cybersecurity risk assessment, designs and produces the product to meet Annex I, compiles the Annex VII technical documentation, keeps series production in conformity, draws up the EU Declaration of Conformity under Article 28, and affixes the CE marking under Article 30. No notified body is involved, so no identification number follows the marking.
Article 32(1) makes Module A available to default products, which may also choose Module B plus Module C, or Module H, voluntarily - buyers in regulated sectors often ask for one.
For an Annex III Class I product the position is conditional. Article 32(2) opens Module A only where the manufacturer fully applies the relevant harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least substantial. Partial application does not satisfy the condition. Presumption of conformity itself comes from Article 27, and it only reaches the requirements the applied standard actually covers.
Annex III Class I: When a Third Party Becomes Necessary
Where the Article 32(2) condition is not met - because no harmonised standard is yet cited for the product category, or because the manufacturer applies one only in part - a Class I product takes a third-party route:
EU type-examination (Module B) plus conformity to type (Module C): a notified body examines the design and issues a type-examination certificate; the manufacturer then declares that production units conform to the approved type and keeps production controlled. Modifications to the approved type that may affect conformity require further approval from the body.
Full quality assurance (Module H): a notified body approves and then surveils a quality system covering design, development, production and final inspection. This suits portfolios with many variants or frequent releases, where anchoring on a single approved type is impractical.
There is no lighter 'documentation review' route in the CRA. Either the Article 32(2) condition is satisfied and internal control is available, or one of the two third-party procedures applies.
Annex III Class II: A Third Party in Every Case
Article 32(3) closes internal control to Class II products entirely. Whatever standards the manufacturer applies, one of three routes is required: Module B plus Module C, Module H, or a European cybersecurity certification scheme at assurance level at least substantial.
The four Class II categories are hypervisors and container runtime systems, firewalls and intrusion detection or prevention systems, tamper-resistant microprocessors, and tamper-resistant microcontrollers. Note what is not in that list: hardware security modules and smart meter gateways are Annex IV critical products, and industrial control components are classified on their own function like anything else.
Because a notified body takes part in the production-control phase on these routes, the CE marking is followed by that body's four-digit identification number under Article 30(6). Assessment capacity is the practical constraint: bodies could only be designated from 11 June 2026, and demand concentrates ahead of full application on 11 December 2027, so engagement belongs on the launch plan early rather than at the end.
Annex IV Critical Products and Certification Schemes
Article 32(4) deals with the critical products listed in Annex IV. Conformity is demonstrated through a European cybersecurity certification scheme under Regulation (EU) 2019/881 where the Commission has required one by delegated act under Article 8(1). Where that condition is not met, the Class II routes apply: Module B plus Module C, Module H, or a qualifying certification scheme.
For important products, a European cybersecurity certification scheme at assurance level at least substantial can serve as the route in its own right. The EUCC, adopted by implementing regulation and based on Common Criteria, is the first such scheme in place.
Certificates issued under other regimes are useful evidence for the technical file, but they do not substitute for a CRA conformity assessment: a certificate proves conformity with whatever it was issued against.
When can a class I product still self-assess?
Important products of class I escape third-party conformity assessment only where the manufacturer has applied relevant harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial. Commission guidance C(2026) 5252 sets two conditions that must both hold.
All the applicable requirements of a relevant harmonised standard need to be applied, and the standard's scope needs to cover at least all the cybersecurity risks associated with the product's core functionality. Applying a standard in part does not qualify.
A product will often be broader than the standard. The manufacturer must still carry out the Article 13(2) risk assessment across the whole product, and where the standard does not cover every risk, document the additional measures taken to treat the rest. Doing so preserves eligibility for the internal control procedure across the product as a whole.
Presumption of conformity behaves differently from eligibility. It extends only as far as the standard reaches. An antivirus product whose core functionality is covered by a harmonised standard, but which also offers disk cleaning and anti-tracking features the standard does not address, may use internal control for the whole product while benefiting from presumption of conformity only for the core functionality.
Important products qualifying as free and open-source software may follow the default-category procedures under Article 32(5), whether they are class I or class II.
CVD Portal helps you comply with Article 32 automatically.
Public submission portal, 48-hour acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Start your free portalFrequently asked
How do I determine whether my product is default class, Class I, or Class II?+
Check Annex III and Annex IV against what the product actually does. Annex III Class I holds nineteen categories and Class II four; Annex IV holds three critical categories. A product listed in neither annex is default tier. Classification follows function rather than product name, so a general-purpose microcontroller is default while the same part with security-related functionality is Class I. Record the categories you considered and why each does or does not apply.
Can I voluntarily use a third-party notified body for a default-class product?+
Yes. The CRA sets minimum requirements - manufacturers can exceed them. Using a notified body for a default-class product provides additional assurance and may be required by certain customers (particularly in B2B and public procurement contexts). Many enterprise customers include conformity assessment requirements in procurement specifications that go beyond what the CRA mandates.
What is the expected timeline for a notified body assessment of a Class II product?+
Plan in months rather than weeks. The assessment itself is a review cycle with findings to close, and the binding constraint is usually notified body capacity: bodies could only be designated from 11 June 2026, and demand concentrates before full application on 11 December 2027. Arriving with a complete, traceable technical file against Annex VII is the single biggest lever on elapsed time.
What happens if I modify a product after it has received a notified body certificate?+
A substantial modification means the product is treated as newly placed on the market, so conformity has to be demonstrated again for the requirements the change affects and the documentation updated. On a Module B route the manufacturer must inform the notified body of modifications to the approved type that may affect conformity, and those require additional approval. Security updates that do not change the intended purpose or the product's functions are not substantial modifications.
Does the conformity assessment for a software product work the same way as for hardware?+
The same assessment modules apply, but the specific technical assessment activities differ. For software-only products, the assessment focuses on software architecture, code review, penetration testing, and vulnerability management processes rather than physical hardware characteristics. Notified bodies with software assessment expertise are the appropriate choice for software product assessments.
Related CRA Articles
Need a CVD policy that satisfies Article 32?
Download a free CRA-compliant template and deploy it in minutes.