CRA harmonised standards — citation and assessment checks
How to check the role of harmonised standards in CRA assessment: exact citation, requirement coverage, route conditions and evidence. This is not a live OJ ledger.
By CenitiaUpdated
A work programme, draft standard or published EN title is different from an OJ citation conferring a particular presumption of conformity. Check the act-specific citation, date, edition, scope and restrictions. The current application does not automatically ingest the STAN4CR programme, all OJ notices or clause-level standard deltas.
Conformity assessment A, B+C and H
Annex VIII offers internal control (A), EU-type examination plus conformity to type (B+C), and full quality assurance (H). Standard products may use A. Important Class I A depends on Article 32(2) full coverage through applicable harmonised standards, common specifications or qualifying certification; otherwise B+C or H. Class II uses B+C or H under Article 32(3). Article 32(5) allows qualifying important free/open-source software with public technical documentation to use A. Critical products require assessment of Article 8 certification conditions; absent the mandated suitable scheme conditions, Article 32(4) provides B+C or H. Classify the main product function against Annexes III/IV and implementing technical descriptions 2025/2392, not a component name alone.
Cybersecurity and vulnerability handling
Part I point 1 establishes risk-based appropriate cybersecurity. Point 2(a)-(m) addresses known exploitable vulnerabilities, secure defaults, updates, access control, confidentiality, integrity, data minimisation, availability, network effects, attack surface, exploitation mitigation, logging, and secure permanent erasure/easy secure transfer of data. Apply requirements on the statutory risk-based conditions. Part II covers vulnerability identification/documentation including SBOM, remediation, testing, disclosure, contact, secure distribution and timely security updates. A proposed control or file count is not evidence that the control was tested.
Conformity assessment
For Article 3(1) requirements, Article 17(2) permits A, B+C or H. For Article 3(2)/(3), Article 17(3) permits A, B+C or H where applicable OJ-listed harmonised standards are fully applied; absent/partially applied standards, Article 17(4) requires B+C or H. Check exact editions, scope and OJ restrictions. EN 18031 citations under 2025/138 carry limitations; neither EN 18031 nor ETSI EN 303 645 automatically gives CRA presumption of conformity.
Evidence to keep with the product
Record the intended purpose, responsible economic operator, target market, first placing date and exact hardware/firmware configuration. For each applicable requirement, link the actual test or assessment record, dated standard/specification, scope and reviewer decision. Proposed controls and supplier marketing statements are not evidence that the final configuration has passed an assessment.
Separate an open question from a completed assessment. A report outside the laboratory's relevant scope, a different firmware build or an unverified exemption needs a reasoned decision before it supports a declaration. Keep original evidence and the issued declaration alongside any AI-assisted working draft.
Using Cenitia for this work
Cenitia assists with a limited regulatory catalogue and draft documents. The manufacturer must confirm applicability, actual applied specifications and completed assessment procedures. AI scores are quality signals, not a probability of conformity. Source monitoring raises a review prompt when validated source text changes; it does not automatically verify amendments, update the corpus or monitor every national rule and OJ standard edition. Public QR verification records issuance, not product certification.
Review status
This guide was substantively corrected by Cenitia on 2 October 2026 using the primary references below. It is an editorial summary, not an authoritative legal quotation or an independently signed expert opinion. Product-specific and licensed-standard questions remain subject to a real technical review.
Primary references
FAQ
Frequently asked questions
Does an AI draft or QR verification prove conformity?
No. The manufacturer must establish scope and satisfy applicable requirements using actual evidence. QR verification records issuance, not product certification.
What information must be checked for this product?
Confirm intended use, role, market/date, final configuration, dated specifications, assessment route and evidence scope. Record unresolved questions and a real reviewer decision.
Continue reading
Related guides
reference
EN 18031 — OJ citation, restrictions and assessment checks
An overview of RED cybersecurity scope, EN 18031 citation and restriction checks, assessment routes and the 2027 delegated-act transition.
3 min read
reference
Official Journal monitoring for hardware compliance — a quarterly review workflow
A practical workflow for tracking EU product legislation, OJ standards citations, restrictions and transition dates, with a review record for each affected product.
4 min read
guide
CRA readiness countdown — scope, reporting, assessment and release checkpoints
Planning checkpoints before CRA main product obligations apply on 11 December 2027, with reporting already in force, class-specific routes and release evidence.
5 min read
tutorial
Coordinated Vulnerability Disclosure Policy for Hardware Manufacturers
Build a usable hardware vulnerability disclosure policy with intake owners, safe testing boundaries and a security.txt example.
4 min read
Put this into practice
Free tools & references
- CRA Readiness CheckerScore your product against the Cyber Resilience Act essential requirements.Open tool →
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.