top of page

CE Conformity Protocol

Structured and Traceable CE Conformity Documentation

Regulation (EU) 2024/2847 - CRA

7 minutes

Regulation (EU) 2024/2847 - CRA
Immeuble de bureaux

Structured Assessment Logic (SAL) – Your Roadmap for Compliance

SAL Type V(b) – Specific Public Interest Framework – NLF-based Comprehensive Non-Safety Public Interest Framework with non-structural (partial) classification logic

Mapping of CRA (EU) 2024/2847


To implement the requirements of CRA (EU) 2024/2847 in a transparent and structured way, the regulatory assessment process can be represented using a Structured Assessment Logic (SAL). This logic ensures that all technical and regulatory requirements are systematically evaluated and that compliance is supported by documented evidence.


The SAL comprises the following steps:


  1. Product qualification – Is the product actually within the scope of the CRA?

  2. Classification and selection of the conformity assessment procedure - B+C, H, European cybersecurity certification schemes

  3. Risk Assessment – Identification of the applicable essential cybersecurity requirements (Annex I, Part I) – Which essential cybersecurity requirements apply to the product?

    The assessment of the cybersecurity risks associated with a product is required not only to evaluate and mitigate hazards, but also to identify which of the essential cybersecurity requirements related to the product properties (set out in Part I of Annex I) are relevant for the type of product concerned.

  4. Means of compliance assessment – Standards, specifications and certification schemes – Which standards, specifications or schemes cover the requirements, and where are there gaps?

  5. Design and process capability for vulnerability handling (Annex I, Part II)

  6. Does the product architecture and the manufacturer's processes enable the effective notification, distribution, verification, download and installation of security updates, thereby ensuring that the vulnerability handling obligations can be fulfilled throughout the support period?

  7. Technical documentation – Which records demonstrate compliance?

  8. Information obligations

  9. EU Declaration of Conformity & CE marking – Official confirmation of compliance, ready for the EU market.


Note: SAL is not an end in itself. It provides a repeatable methodology that translates regulatory principles into a clear, structured assessment logic.


This diagram illustrates the SAL workflow visually:


Product qualification

↓

Classification │ Conformity assessment procedure

↓

Risk Assessment – Identification of the applicable essential cybersecurity requirements

↓

Conformity assessment procedure

↓

Means of compliance assessment – Standards, specifications and certification schemes

↓

Design and process capability for vulnerability handling

↓

Technical documentation

↓

Information obligations

↓

CE marking & Declaration of Conformity


Interfaces to Related Legislation


CRA compliance requires consideration of overlaps with adjacent regulatory frameworks, in particular the Machinery Regulation (EU) 2023/1230 and the Radio Equipment Directive 2014/53/EU, including Commission Delegated Regulation (EU) 2022/30.

Relevant interface considerations are addressed in FAQs on the CRA implementation (Sections 2.4 and 2.6).

A coordinated assessment is necessary to avoid regulatory gaps or duplication. The SAL therefore operates as a cross-legislative compliance framework rather than a standalone assessment tool.


Overview: Regulation (EU) 2024/2847


  • Number: (EU) 2024/2847

  • Title: Regulation on horizontal cybersecurity requirements for products with digital elements

  • Publication: OJ L, 2024/2847, 20.11.2024

  • Purpose: Establishes a framework for the making available on the EU market of products with digital elements to ensure the cybersecurity of such products

  • Public interest: Cybersecurity

  • Guidance: Guidelines on CRA (EU) 2024/2847: FAQs on the CRA implementation and Draft Commission guidance on the Cyber Resilience Act


Product qualification


The CRA (EU) 2024/2847 applies to products with digital elements made available on the market, the intended purpose or reasonably foreseeable use of which includes a direct or indirect logical or physical data connection to a device or network.

A product with digital elements is hardware or software placed on the EU market whose intended or reasonably foreseeable use involves a direct or indirect data connection to another device or network.

Note: This overview is limited to physical products (hardware). Although standalone software is also covered by the CRA, it is not addressed in this SAL.


Physical product

 

↓

 

Can the product process,store or transmit digital data?

No → Not a PDE

 

 

Yes ↓

 

Does the intended purpose or reasonably foreseeable use include a direct or indirect logical or physical data connection to another device or network?

No → Not a PDE

Yes ↓

 

Product withDigital Elements(PDE)

 

 Relevant types of connectivity under the CRA:

Type of Connectivity

Description

Example

Logical Connectivity

Data exchange through software interfaces, protocols, or communication services

REST API, MQTT communication, TCP/IP connection, OPC UA, CAN over IP

Physical Connectivity

Data exchange through wired, wireless, electrical, optical, or mechanical interfaces

Ethernet, USB, Bluetooth, RS-485, CAN bus, Zigbee

Indirect Connectivity

Connection to another device or network through an intermediary system

Sensor → Gateway → Internet

 

Note: The concept of indirect connectivity is often overlooked in practice. A direct internet connection is not required. Connectivity through an intermediary device (for example a gateway, PLC or industrial controller) may already bring the product within the scope of the CRA.


Typical Physical Products that Qualify as PDEs

  • Smart home devices

  • Wi-Fi cameras

  • Smart thermostats

  • Smartwatches

  • Fitness trackers

  • Routers

  • Network printers

  • Industrial control systems, inter alia

    • PLCs Remote

    • I/O modules

    • Industrial gateways

    • Drives

    • HMIs

  • IoT sensors

  • Connected household appliances


Classification │ Selection of the conformity assessment procedure


For the purpose of conformity assessment, the CRA distinguishes four categories of Products with Digital Elements, each determining the applicable conformity assessment procedure.

Important Products – Class I constitute the only category in which the availability and full application of relevant harmonised standards, common specifications or European cybersecurity certification schemes determines whether the manufacturer may use Module A (Internal Production Control) or must involve a notified body (Modules B+C or H).


Available conformity assessment modules / routes:

Categories of products

Default products

Important Class I

Important Class II

Critical products

Product not listed in Annex III or IV

Product listed in Annex III Class I

Product listed in Annex III Class III

Product listed in Annex IV

 

 

Are relevant harmonised standards, common specifications or European cybersecurity certification schemes covering the essential cybersecurity requirements fully applied?

 

 

 


 

Yes

ↆ

No

ↆ

 

 

Conformity assessment procedures

A, B+C, H

A, B+C, H

B+C, H

B+C, H, or a European cybersecurity certification scheme pursuant to Art. 32(3)

European cybersecurity certification scheme under Art. 8(1); if the conditions of Art. 8(1) are not met: B+C, H, or a European cybersecurity certification scheme pursuant to Art. 32(3)

 

Note: Unlike other product categories, the conformity assessment route for Important Products – Class I depends not only on the product classification but also on the extent to which the applicable essential cybersecurity requirements are covered by harmonised standards, common specifications or European cybersecurity certification schemes.

 

Risk Assessment – Identification of the applicable essential cybersecurity requirements (Annex I, Part I)

 

As with other risk-based Union harmonisation legislation based on the New Legislative Framework (NLF), the manufacturer must perform a cybersecurity risk assessment in order to determine which essential cybersecurity requirements set out in Annex I, Part I apply to the product. The risk assessment therefore serves not only to identify and evaluate cybersecurity risks, but also to establish the scope of the applicable essential requirements.


Under the traditional NLF approach, manufacturers generally identify the essential requirements that are applicable to the product on the basis of the risk assessment. Requirements that are clearly irrelevant or incompatible with the nature of the product may simply be disregarded without any specific justification being included in the risk assessment or other technical documentation.

The Cyber Resilience Act adopts a different approach. Pursuant to Article 13(4), where the manufacturer concludes that one or more essential cybersecurity requirements set out in Annex I, Part I are not applicable, the cybersecurity risk assessment must include a clear and documented justification for each such requirement. According to Recital 55, this may be the case where an essential cybersecurity requirement is incompatible with the nature of the product. The FAQs on the CRA implementation (Section 4.1.3) further clarify that a justification may also be provided where no cybersecurity risks exist that require mitigation in relation to the essential cybersecurity requirement concerned.


Consequently, the cybersecurity risk assessment under the CRA performs a dual function:

  • it identifies and evaluates the cybersecurity risks associated with the product; and

  • it determines and documents which essential cybersecurity requirements of Annex I, Part I are applicable and, where appropriate, provides a reasoned justification for requirements considered not applicable.


Practical note: Particular attention should be paid to the "catch-all" requirement in Annex I, Part I, point (1). Even where individual essential cybersecurity requirements are considered inapplicable, the general obligation to design, develop and produce products with an appropriate level of cybersecurity remains applicable and must be taken into account throughout the assessment. This overarching function of Annex I, Part I, point (1) is also emphasised in the Draft Commission guidance on the Cyber Resilience Act (paras. 149 et seq.). (149 sq.).


Means of Compliance – Harmonised standards, common specifications and cybersecurity certification schemes


Identify recognised technical means that enable a presumption of conformity and determine where alternative compliance evidence is required.

Technical specifications facilitating compliance

  • Use provides a presumption of conformity

  • Developed by recognised European standardisation organisations or established as common specifications via Commission implementing acts


Design and process capability for vulnerability handling (Annex I, Part II)


This step ensures that the product design and the supporting organisational processes enable the manufacturer to fulfil the vulnerability handling obligations during the entire support period as required under Article 13(8) and Annex I, Part II of the Cyber Resilience Act.


The focus is not limited to post-market activities but extends to the design phase, requiring that products with digital elements are developed in a way that allows the effective implementation of vulnerability remediation measures throughout their lifecycle.


Depending on the nature and severity of the risk, vulnerability remediation measures may take different forms, including immediate security patches, advisories providing temporary workarounds to be followed by subsequent software updates, updates to user documentation, or configuration guidance to disable affected features.


Manufacturers should therefore ensure, both at the level of product design and organisational processes, that products with digital elements include technical functionalities enabling the notification, distribution, download, and installation of security updates. In particular, for consumer products, updates should be capable of being deployed automatically, while still allowing users to provide final approval for the download and installation where appropriate.


This design obligation reflects the approach outlined in the FAQs on the CRA implementation (Section 4.3) and Draft Commission guidance on the Cyber Resilience Act (paras. 114 et seq.), which emphasise the need for built-in update mechanisms and appropriate user control, as well as the Draft Commission Guidance on the Cyber Resilience Act, which further elaborates on the technical and organisational expectations for vulnerability handling capabilities throughout the support period.


Technical documentation


The technical documentation shall contain all elements required under Annex VII of the Cyber Resilience Act and serve as the primary evidence of conformity with the applicable requirements.


Information obligations


Manufacturers shall ensure that products with digital elements are accompanied by the information and instructions for use required under Annex II of the Cyber Resilience Act.


CE Marking


  • Mandatory before placing the product on the EU market

  • Must be visible, legible, and permanent

  • Notified Body number required if involved


Conclusion


With SAL, the mapping as a roadmap, and consideration of interfaces to related legislation, it becomes clear how CRA (EU) 2024/2847 is systematically applied. The final workflow logically follows from scope through requirements, standards, and assessment procedures to CE marking – providing a clear orientation for manufacturers, assessors, and all stakeholders seeking regulatory clarity.

You might also be interested in these articles:
Regulation (EU) 2024/2847 - CRA

Regulation (EU) 2024/2847 - CRA

Add paragraph text. Click “Edit Text” to update the font, size and more. To change and reuse text themes, go to Site Styles.

Read More
Regulation (EU) 2023/2854 – Data Act

Regulation (EU) 2024/2847 - CRA

Add paragraph text. Click “Edit Text” to update the font, size and more. To change and reuse text themes, go to Site Styles.

Read More
Regulation (EU) 2016/425 - Personal Protective Equipment (PPE)

Regulation (EU) 2024/2847 - CRA

Add paragraph text. Click “Edit Text” to update the font, size and more. To change and reuse text themes, go to Site Styles.

Read More
Directive 2014/29/EU – Simple Pressure Vessels Directive (SPVD)

Regulation (EU) 2024/2847 - CRA

Add paragraph text. Click “Edit Text” to update the font, size and more. To change and reuse text themes, go to Site Styles.

Read More

© 2026 by Dr. Matthias K Bauer

bottom of page