
Email: contact@nordcs.de
Phone: +49 176 240 73665
Address: Rheinpromenade 11, 40789, Monheim am Rhein
latest news
About 90% of products under the EU Cyber Resilience Act only need self-assessment, not third-party certification. Here is how the three conformity routes actually work, and why market surveillance is what keeps self-assessment from being a paper exercise.

On 11 September 2026, three days from now, the EU Cyber Resilience Act's reporting duties become enforceable. Long before that date, most manufacturers will never see a notified body, a conformity certificate, or an auditor from an accredited lab. About 90% of products in scope reach CE marking through self-assessment alone. That number gets treated as good news or as a loophole, depending on who you ask. It is neither. It only works because of what backs it up.
The Cyber Resilience Act (Regulation 2024/2847) does not send every product down the same conformity path. Where a product lands depends on its risk classification.
Self-assessment covers the large majority of products, the default risk tier where the manufacturer performs its own risk assessment, applies the essential requirements in Annex I, and declares conformity without external sign-off.
Presumption of conformity applies where a product complies with a harmonised European standard (hEN) specific to its category. Legally this is the cleanest route, compliance with the standard is treated as compliance with the regulation, but as of this writing there are no finished harmonised standards for the CRA yet. The standardisation work is real and underway, but it is not a route manufacturers can lean on in practice today.
Notified body assessment is mandatory for the higher risk Annex III Class II products and the Annex IV critical products, hardware security modules, industrial automation and control components used in critical infrastructure, and similar. Here an accredited third party actually reviews the product before it can carry the CE mark.
In the meantime, Germany's BSI publishes a non-binding Technical Guideline (TR-03183) aimed specifically at the roughly 90% of products with no harmonised standard to lean on. It is pragmatic, not legally binding, and openly described by BSI itself as under continuous development, but for most manufacturers building a self-assessment file today, it is the most concrete guidance actually available.
Conflating those two ideas is the most common mistake engineering teams make reading about this. Self-assessment means the manufacturer, not a notified body, performs the conformity check. It does not mean nobody checks.
Every product carrying a CE mark under the CRA, self-assessed or not, sits under the ongoing oversight of a market surveillance authority, BSI in Germany's case, which monitors conformity both reactively, responding to reports and complaints, and actively, through its own spot checks. That oversight applies to every product on the EU market regardless of where the manufacturer is based, an EU manufacturer and one with no EU presence at all face identical exposure once their product is sold into the EU.
A self-assessment file that would not survive that kind of scrutiny is not a compliance shortcut. It is a liability sitting in a drawer, waiting for a spot check or a serious incident report to surface it.
The CRA's obligations do not all start on the same date, and the gap between them is easy to misread in a way that carries real exposure.
No CRA obligations apply before 11 September 2026. From that date, only the reporting duties apply, notification of actively exploited vulnerabilities and severe security incidents to ENISA and the relevant national CSIRT, and this applies even to products already on the market, there is no grandfathering for existing product lines on this specific obligation. The full set of CRA requirements, essential requirements and conformity assessment included, only becomes mandatory from 11 December 2027, and even then only for new products and new versions of existing product lines.
That gap matters because it is easy to read "full compliance by December 2027" and conclude there is no urgency yet. There is. The reporting duty is live in days, and the two triggering definitions are narrower than most teams assume. An actively exploited vulnerability, under Article 3(42) and Article 14(1), requires credible evidence of actual exploitation by a malicious actor, a published exploit with no observed exploitation does not trigger the duty on its own. A severe security incident, under Article 3(44) and Article 14(5), requires the incident to actually affect the product's own confidentiality, integrity, or availability, or lead to malicious code execution, a ransomware event that never touches the product's own security is not automatically CRA reportable. Getting that distinction wrong in either direction, reporting noise or missing a genuine trigger, both carry real cost.
Confirm which of the three routes actually applies to your product, do not assume self-assessment by default, Annex III and Annex IV both list specific categories that require more.
Do not wait on harmonised standards that do not exist yet. Build the self-assessment file against Annex I directly, using BSI's TR-03183 as practical scaffolding where it applies.
Stand up an actual reporting process for actively exploited vulnerabilities and severe incidents before 11 September 2026, not a policy document, a process someone can execute inside 24 hours of finding out. ENISA's Single Reporting Platform accepts one submission covering every EU member state where the product is sold, which removes any excuse to file per country separately.
This is precisely the operational gap Nord CS built Aitigrity to close. Aitigrity automates the full CRA lifecycle in one connected workflow, threat modeling, requirements, the security concept, security testing, and continuous monitoring and reporting once the product is live, so a compliance file stays current instead of going stale the day after CE marking. Run your product through Nord CS's free CRA Scope and Classification Check to see where it lands, or contact Nord CS directly with questions about your specific product.
Sources:
BSI, Cyber Resilience Act information
BSI, CRA notification (national notifying authority)
BSI, Technical Guideline TR-03183