CRA Cyber Resilience Act Self-Assessment
Professional support for structured self-assessment under the EU Cyber Resilience Act. We guide you through the complete self-assessment process for compliant digital products.
- ✓Structured CRA Self-Assessment methodology and compliance framework
- ✓Comprehensive risk assessment and security analysis of digital products
- ✓Compliant documentation and declaration of conformity in accordance with CRA standards
- ✓Continuous monitoring and updating of the self-assessment
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










CRA Self-Assessment: Module A for Standard Products
Our Self-Assessment Expertise
- In-depth CRA knowledge and proven assessment methodologies
- Industry-specific expertise for various digital product categories
- Automated tools and frameworks for efficient assessment processes
- End-to-end approach from assessment to continuous compliance
Compliance-critical success factor
Incomplete or flawed self-assessments can lead to market restrictions, liability risks, and regulatory sanctions. A structured, documented approach is essential for CRA compliance.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
We conduct CRA Self-Assessments systematically and in a structured manner, based on proven cybersecurity frameworks and regulatory best practices.
Our Approach:
Product analysis and CRA scope definition
Structured cybersecurity risk assessment
Compliant documentation and assessment report
EU declaration of conformity and market release
Continuous monitoring and update management

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
Structured CRA Self-Assessment
Comprehensive self-assessment of digital products in accordance with CRA standards, with a structured methodology and compliant documentation.
- CRA-compliant assessment methodology
- Comprehensive cybersecurity risk assessment
- Structured vulnerability analysis
- Compliant assessment documentation
Continuous Compliance Monitoring
Ongoing monitoring and management of CRA compliance with automated monitoring processes and regular updates.
- Continuous security monitoring
- Automated compliance monitoring
- Regular assessment updates
- Integration into DevSecOps workflows
Our Competencies
Choose the area that fits your requirements
CE marking under the Cyber Resilience Act (CRA) is essential for market access of digital products in the EU. We support you with complete conformity assessment and secure CE marking.
Professional support and preparation for external CRA audits by accredited testing bodies. We ensure successful certification and long-term compliance for critical digital products.
Frequently Asked Questions about CRA Cyber Resilience Act Self-Assessment
What is the CRA self-assessment under Module A and which products does it apply to?
The CRA self-assessment under Module A (internal production control) is a conformity assessment procedure where the manufacturer independently verifies that their digital product meets all cybersecurity requirements of the Cyber Resilience Act. This procedure applies to standard products, i.e. all products with digital elements not listed in Annex III (important products) or Annex IV (critical products). Typical examples include smart home devices, simple IoT sensors, mobile apps and computer games. The self-assessment involves creating technical documentation, a complete risk analysis and issuing the EU declaration of conformity.
What steps does the internal conformity assessment under the Cyber Resilience Act involve?
The internal conformity assessment under Module A involves several structured steps: First, product classification, determining whether the product qualifies as a standard product. Second, risk analysis, systematic assessment of all cybersecurity risks per CRA Annex I. Third, technical documentation, creating evidence of design, development, manufacturing and security measures. Fourth, conformity verification against the essential requirements of the CRA. Fifth, issuing the EU declaration of conformity per Annex V. Sixth, CE marking the product. And seventh, establishing processes for security updates and vulnerability reporting throughout the product lifecycle.
What is the difference between self-assessment and third-party assessment under the CRA?
In self-assessment (Module A), the manufacturer independently carries out the conformity assessment without involving a notified body. This procedure is only permitted for standard products. In third-party assessment (Modules B+C or H), an independent EU-notified conformity assessment body is involved. This is mandatory for important products Class II (e.g. firewalls, intrusion detection systems) and critical products (e.g. smart cards, HSMs). Important products Class I (e.g. password managers, VPNs) may use self-assessment provided they apply harmonised standards or hold an EU cybersecurity certification.
What documentation is required for the EU declaration of conformity under the CRA?
The EU declaration of conformity per CRA Annex V requires: product identification (name, type, serial number), manufacturer details (name, address, contact), reference to the harmonised standards or technical specifications applied, a declaration that the product meets the essential requirements of Annex I, and the place, date and legally binding signature. Additionally, complete technical documentation must be prepared, covering the risk analysis, design specifications, test reports and software bill of materials (SBOM). These records must be retained for 10 years after placing the product on the market and made available to market surveillance authorities on request.
What are the deadlines for CRA self-assessment and when does it become mandatory?
The Cyber Resilience Act enters into force in stages: From 11 September 2026, reporting obligations for security incidents and actively exploited vulnerabilities apply. From 11 June 2026, the rules for notified bodies must be implemented. The full requirements, including conformity assessment and Module A self-assessment, apply from 11 December 2027. However, manufacturers should start preparing early, as creating technical documentation, conducting risk analysis and implementing security-by-design processes typically takes several months.
What cybersecurity requirements must a standard product meet under CRA Annex I?
CRA Annex I defines the essential cybersecurity requirements for all products with digital elements. These include: protection against unauthorised access through appropriate access controls, ensuring confidentiality of stored and transmitted data, integrity protection of all relevant data and functions, availability of essential functions even during attacks, minimisation of the attack surface, secure default configuration, protection against known vulnerabilities through regular updates, and the ability to log security-relevant events. Additionally, manufacturers must provide vulnerability management processes and security updates throughout the entire support period.
How does ADVISORI support manufacturers with CRA Module A self-assessment?
ADVISORI guides manufacturers through the entire self-assessment process: We start with product classification and verify whether your product is correctly categorised as a standard product or falls under Annex III/IV. We then conduct a structured gap analysis against the Annex I requirements. On this basis, we prepare the complete technical documentation and risk analysis. We draft the EU declaration of conformity and support CE marking. We also implement processes for continuous vulnerability management and security updates so your product remains CRA-compliant after placing it on the market. Our experience from numerous CRA projects accelerates the process and minimises compliance risks.
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance