1. Home/
  2. Services/
  3. Regulatory Compliance Management/
  4. CRA Cyber Resilience Act/
  5. CRA Cyber Resilience Act Conformity Assessment/
  6. CRA Cyber Resilience Act Self Assessment

Subscribe to Newsletter

Stay up to date with the latest trends and developments

By subscribing, you agree to our privacy policy.

A
ADVISORI FTC GmbH

Transformation. Innovation. Security.

Office Address

Kaiserstraße 44

60329 Frankfurt am Main

Germany

View on map

Contact

info@advisori.de+49 69 913 113-01

Mon-Fri: 9:00 AM - 6:00 PM

Company

Services

Social Media

Follow us and stay up to date.

  • /
  • /

© 2024 ADVISORI FTC GmbH. All rights reserved.

Your browser does not support the video tag.
Structured self-assessment for CRA compliance

CRA Cyber Resilience Act Self-Assessment

Professional support for structured self-assessment under the EU Cyber Resilience Act. We guide you through the complete self-assessment process for compliant digital products.

  • ✓Structured CRA Self-Assessment methodology and compliance framework
  • ✓Comprehensive risk assessment and security analysis of digital products
  • ✓Compliant documentation and declaration of conformity in accordance with CRA standards
  • ✓Continuous monitoring and updating of the self-assessment

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

info@advisori.de+49 69 913 113-01

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

CRA Self-Assessment: Module A for Standard Products

Our Self-Assessment Expertise

  • In-depth CRA knowledge and proven assessment methodologies
  • Industry-specific expertise for various digital product categories
  • Automated tools and frameworks for efficient assessment processes
  • End-to-end approach from assessment to continuous compliance
⚠

Compliance-critical success factor

Incomplete or flawed self-assessments can lead to market restrictions, liability risks, and regulatory sanctions. A structured, documented approach is essential for CRA compliance.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We conduct CRA Self-Assessments systematically and in a structured manner, based on proven cybersecurity frameworks and regulatory best practices.

Our Approach:

Product analysis and CRA scope definition

Structured cybersecurity risk assessment

Compliant documentation and assessment report

EU declaration of conformity and market release

Continuous monitoring and update management

"ADVISORI not only conducted our CRA Self-Assessment in a structured and efficient manner, but also established a sustainable compliance framework that continuously supports our product development. Their expertise saved us time and gave us confidence."
Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

LinkedIn Profile

Our Services

We offer you tailored solutions for your digital transformation

Structured CRA Self-Assessment

Comprehensive self-assessment of digital products in accordance with CRA standards, with a structured methodology and compliant documentation.

  • CRA-compliant assessment methodology
  • Comprehensive cybersecurity risk assessment
  • Structured vulnerability analysis
  • Compliant assessment documentation

Continuous Compliance Monitoring

Ongoing monitoring and management of CRA compliance with automated monitoring processes and regular updates.

  • Continuous security monitoring
  • Automated compliance monitoring
  • Regular assessment updates
  • Integration into DevSecOps workflows

Our Competencies in CRA Cyber Resilience Act Conformity Assessment

Choose the area that fits your requirements

CRA Cyber Resilience Act CE-Marking

CE marking under the Cyber Resilience Act (CRA) is essential for market access of digital products in the EU. We support you with complete conformity assessment and secure CE marking.

CRA Cyber Resilience Act External Audits

Professional support and preparation for external CRA audits by accredited testing bodies. We ensure successful certification and long-term compliance for critical digital products.

Frequently Asked Questions about CRA Cyber Resilience Act Self-Assessment

What is the CRA self-assessment under Module A and which products does it apply to?

The CRA self-assessment under Module A (internal production control) is a conformity assessment procedure where the manufacturer independently verifies that their digital product meets all cybersecurity requirements of the Cyber Resilience Act. This procedure applies to standard products — i.e. all products with digital elements not listed in Annex III (important products) or Annex IV (critical products). Typical examples include smart home devices, simple IoT sensors, mobile apps and computer games. The self-assessment involves creating technical documentation, a complete risk analysis and issuing the EU declaration of conformity.

What steps does the internal conformity assessment under the Cyber Resilience Act involve?

The internal conformity assessment under Module A involves several structured steps: First, product classification — determining whether the product qualifies as a standard product. Second, risk analysis — systematic assessment of all cybersecurity risks per CRA Annex I. Third, technical documentation — creating evidence of design, development, manufacturing and security measures. Fourth, conformity verification against the essential requirements of the CRA. Fifth, issuing the EU declaration of conformity per Annex V. Sixth, CE marking the product. And seventh, establishing processes for security updates and vulnerability reporting throughout the product lifecycle.

What is the difference between self-assessment and third-party assessment under the CRA?

In self-assessment (Module A), the manufacturer independently carries out the conformity assessment without involving a notified body. This procedure is only permitted for standard products. In third-party assessment (Modules B+C or H), an independent EU-notified conformity assessment body is involved. This is mandatory for important products Class II (e.g. firewalls, intrusion detection systems) and critical products (e.g. smart cards, HSMs). Important products Class I (e.g. password managers, VPNs) may use self-assessment provided they apply harmonised standards or hold an EU cybersecurity certification.

What documentation is required for the EU declaration of conformity under the CRA?

The EU declaration of conformity per CRA Annex V requires: product identification (name, type, serial number), manufacturer details (name, address, contact), reference to the harmonised standards or technical specifications applied, a declaration that the product meets the essential requirements of Annex I, and the place, date and legally binding signature. Additionally, complete technical documentation must be prepared, covering the risk analysis, design specifications, test reports and software bill of materials (SBOM). These records must be retained for

10 years after placing the product on the market and made available to market surveillance authorities on request.

What are the deadlines for CRA self-assessment and when does it become mandatory?

The Cyber Resilience Act enters into force in stages: From

11 September 2026, reporting obligations for security incidents and actively exploited vulnerabilities apply. From

11 June 2026, the rules for notified bodies must be implemented. The full requirements — including conformity assessment and Module A self-assessment — apply from

11 December 2027. However, manufacturers should start preparing early, as creating technical documentation, conducting risk analysis and implementing security-by-design processes typically takes several months.

What cybersecurity requirements must a standard product meet under CRA Annex I?

CRA Annex I defines the essential cybersecurity requirements for all products with digital elements. These include: protection against unauthorised access through appropriate access controls, ensuring confidentiality of stored and transmitted data, integrity protection of all relevant data and functions, availability of essential functions even during attacks, minimisation of the attack surface, secure default configuration, protection against known vulnerabilities through regular updates, and the ability to log security-relevant events. Additionally, manufacturers must provide vulnerability management processes and security updates throughout the entire support period.

How does ADVISORI support manufacturers with CRA Module A self-assessment?

ADVISORI guides manufacturers through the entire self-assessment process: We start with product classification and verify whether your product is correctly categorised as a standard product or falls under Annex III/IV. We then conduct a structured gap analysis against the Annex I requirements. On this basis, we prepare the complete technical documentation and risk analysis. We draft the EU declaration of conformity and support CE marking. We also implement processes for continuous vulnerability management and security updates so your product remains CRA-compliant after placing it on the market. Our experience from numerous CRA projects accelerates the process and minimises compliance risks.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Klöckner & Co

Digital Transformation in Steel Trading

Case Study
Digitalisierung im Stahlhandel - Klöckner & Co

Results

Over 2 billion euros in annual revenue through digital channels
Goal to achieve 60% of revenue online by 2022
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Siemens

Smart Manufacturing Solutions for Maximum Value Creation

Case Study
Case study image for AI-Powered Manufacturing Optimization

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Festo

Intelligent Networking for Future-Proof Production Systems

Case Study
FESTO AI Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Bosch

AI Process Optimization for Improved Production Efficiency

Case Study
BOSCH KI-Prozessoptimierung für bessere Produktionseffizienz

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance

ADVISORI Logo
BlogCase StudiesAbout Us
info@advisori.de+49 69 913 113-01