Skip to content

COMPARISON · CRA

Self-assessment vs Notified Body conformity assessment

Which conformity assessment route is available is determined by the product's CRA risk classification, not by manufacturer preference.

LAST REVIEWED

What is different

  • Who performs the assessment: self-assessment is carried out entirely by the manufacturer under its own quality and technical documentation; Notified Body assessment involves an accredited third-party organisation examining the technical file, and in some routes, the product itself.
  • Applicable products: self-assessment (internal control) is available for default-category products; products listed as 'important' (Annex III, Class I and II) face escalating requirements up to mandatory third-party involvement for Class II, and products listed as 'critical' (Annex IV) face the strictest route, generally including European cybersecurity certification once applicable schemes exist.
  • Evidence burden: self-assessment still requires a full technical documentation file and risk assessment, but the manufacturer is the sole party judging sufficiency; third-party assessment introduces an external, accountable judgement on the same evidence.
  • Timeline and cost: self-assessment can proceed on the manufacturer's own schedule; Notified Body assessment adds lead time for booking, review cycles and potential requests for further evidence, and carries a direct cost for the assessment itself.

What overlaps

Both routes require the same underlying substance: a risk assessment appropriate to the product, a technical documentation file meeting the CRA's Annex VII content requirements, evidence of a secure development lifecycle, and a vulnerability handling process operating for the product's expected support period. The difference is who reviews that evidence and how formally, not whether it needs to exist. A manufacturer that only builds evidence sufficient for self-assessment will need to redo work if a product's classification changes or a customer contractually demands third-party assurance regardless of the legal minimum.

In both routes, use of harmonised standards, once published, creates a presumption of conformity that simplifies the manufacturer's own argument, whether that argument is reviewed internally or by a Notified Body.

Which applies to you

  • Your product does not appear in Annex III or Annex IV: self-assessment (internal control) is generally available, provided you can produce complete technical documentation and evidence.
  • Your product appears in Annex III as 'important', Class I (e.g. certain identity management systems, firewalls, browsers): you can generally still self-assess if you fully apply harmonised standards, otherwise third-party assessment is required.
  • Your product appears in Annex III as 'important', Class II, or in Annex IV as 'critical': third-party involvement is generally mandatory regardless of standards applied, and critical products may require certification under a European cybersecurity certification scheme once available.
  • You are unsure of your product's classification: resolve this first, since it determines not only the assessment route but also the depth of evidence you need to prepare from the outset.

Frequently asked questions

What is 'internal control' under the CRA?

Internal control (Module A) is the CRA's self-assessment conformity route, where the manufacturer alone verifies and declares conformity based on its own technical documentation, without third-party review. It is available for products that are not classified as important or critical under the CRA's annexes.

What makes a product 'important' or 'critical' under the CRA?

Annex III lists product categories deemed 'important' due to their function or attack surface, split into Class I and Class II by increasing risk. Annex IV lists 'critical' product categories, currently a narrow list, subject to the strictest assessment requirements including potential mandatory certification.

Can a manufacturer choose Notified Body assessment even if not required?

Yes. Some manufacturers seek third-party assessment voluntarily to strengthen market credibility or satisfy customer procurement requirements, even where self-assessment would be legally sufficient.

Does self-assessment mean less documentation is needed?

No. The CRA requires the same technical documentation content, per Annex VII, regardless of assessment route. Self-assessment removes the external review step, not the underlying documentation obligation.

Are Notified Bodies for the CRA the same as for other EU product regulations?

Notified Bodies must be specifically designated and notified for CRA conformity assessment tasks. An organisation accredited as a Notified Body under another regulation is not automatically authorised to perform CRA assessments unless separately designated for that purpose.