Conformity Assessment - seedon198/Cyber-Resilience-Act GitHub Wiki
Conformity Assessment
CRA Conformity Assessment Procedures
Overview
Conformity assessment demonstrates that products meet CRA essential requirements before market placement.
Assessment Procedures by Product Class
Module A: Internal Production Control (Class I)
- Self-Assessment: Manufacturer conducts internal evaluation
- Documentation: Technical documentation preparation
- Declaration: EU Declaration of Conformity
- CE Marking: Affixing conformity marking
- No Third-Party: No notified body involvement required
Module B + C: Type Examination + Conformity to Type (Class II)
- Type Examination: Notified body evaluates product design
- Certificate: EU Type Examination Certificate issued
- Production Conformity: Ongoing compliance verification
- Surveillance: Periodic notified body oversight
Assessment Process
Phase 1: Pre-Assessment
- Product Classification: Determine Class I or Class II
- Standards Selection: Identify applicable harmonized standards
- Gap Analysis: Compare current state with requirements
- Documentation Planning: Prepare required documentation
Phase 2: Technical Documentation
- Product Description: Detailed product specifications
- Risk Assessment: Comprehensive security risk analysis
- Security Architecture: Design documentation
- Test Results: Conformity testing evidence
- Instructions: User and installation guidance
Phase 3: Testing and Evaluation
- Conformity Testing: Verify standard compliance
- Penetration Testing: Security validation
- Vulnerability Assessment: Identify weaknesses
- Documentation Review: Verify completeness
Phase 4: Certification (Class II Only)
- Notified Body Selection: Choose accredited assessor
- Application Submission: Provide complete documentation
- Technical Review: Expert evaluation
- Certificate Issuance: Formal compliance confirmation
Notified Bodies
Selection Criteria
- Accreditation: National authority designation
- Competence: Technical expertise in product area
- Independence: Impartial assessment capability
- Resources: Adequate testing facilities
Working with Notified Bodies
- Early Engagement: Discuss approach and requirements
- Documentation Submission: Provide complete technical files
- Technical Meetings: Clarify requirements and findings
- Ongoing Cooperation: Maintain certification validity
Documentation Requirements
Technical Documentation Contents
- General Description: Product functionality and purpose
- Conceptual Design: Architecture and components
- Risk Assessment: Security analysis and findings
- Technical Specifications: Detailed requirements
- Standards Applied: Harmonized standards compliance
- Test Reports: Conformity testing results
- Instructions: Installation and user guidance
Quality Requirements
- Completeness: All required elements included
- Accuracy: Technically correct information
- Clarity: Clear and unambiguous content
- Traceability: Version control and change management
- Maintenance: Regular updates and reviews
EU Declaration of Conformity
Required Elements
- Product identification
- Manufacturer details
- Applicable legislation
- Harmonized standards applied
- Notified body (if applicable)
- Authorized representative signature
- Date and place of issue
Legal Significance
- Manufacturer Declaration: Legal responsibility acceptance
- Market Access: Required for product placement
- Compliance Evidence: Demonstrates CRA conformity
- Liability: Manufacturer assumes product responsibility
Post-Market Obligations
Ongoing Compliance
- Technical Documentation: Maintain for 10 years
- Incident Reporting: Report cybersecurity incidents
- Security Updates: Provide necessary patches
- Market Surveillance: Cooperate with authorities
Certificate Maintenance (Class II)
- Validity Period: Typically 3-5 years
- Renewal Process: Periodic reassessment
- Change Notifications: Inform of product modifications
- Surveillance Audits: Ongoing compliance verification
For legal requirements details, see Legal Requirements. For technical implementation, visit Technical Implementation.