CRA Product Classification and Conformity-Assessment Governance
Abstract
This flagship white paper develops an engineering governance architecture for product classification and conformity assessment under the Cyber Resilience Act (CRA). Its central thesis is that product classification is not a marketing label and conformity assessment is not a one-time paperwork choice. The exact product must be classified according to its core functionality and the current legal category structure, after which the applicable conformity route must be determined from the product class, evidence coverage, presumption mechanisms, certification state, third-party assessment requirements, cross-regime rules, and application-date conditions. The paper distinguishes product identity, classification determination, evidence state, conformity route, authorization decision, and actual market outcome as separate control objects. It introduces a Classification & Conformity Envelope and Classification Passport that bind the exact product baseline, intended purpose, core functionality, Annex III/IV category, legal-description version, evidence coverage, conformity route, notified-body or certification state, cross-regime state, validity and re-open triggers. The analysis covers ordinary products, Important Class I and Class II products, critical products, the core-functionality integration rule, Implementing Regulation (EU) 2025/2392, harmonised-standard and common-specification coverage, and the distinction between Article 27(8) certification-based presumption and the separate Article 27(9) certification route. It emphasizes that the existence of a standard or cybersecurity certificate does not by itself establish complete CRA conformity or release authority. The paper also addresses the mandatory third-party boundary for Class II products, live Article 8 certification conditions for critical products, the special Article 32(5) route for qualifying important free and open-source software, the Article 32(5a) EHR-system route introduced through the European Health Data Space framework, and CRA Article 12 coordination with high-risk AI systems. A further contribution is the treatment of notified-body and certificate status as live execution context. Scope, validity, conditions, change approvals, suspension or withdrawal must remain current at the point of market release; a historical certificate alone is not sufficient authority for a changed product state. Building on Execution Governance (EG), the paper applies the principle that ability is not authority to the CRA conformity boundary. Technical readiness, successful testing, a CE mark, or possession of a certificate does not independently authorize the exact market effect. The authorization decision must remain bound to current product identity, classification, legal route, evidence coverage, third-party state and release scope. The paper further provides requirement and decision matrices, a manufacturer reference architecture, Proceed/Review/Hold/Block failure semantics, illustrative Classification Passport and conformity-authorization JSON records, and a 30-day implementation sprint for moving from spreadsheet-based classification toward evidence-backed, authorization-bound conformity governance. Its series doctrine is: “Classify the product. Qualify the route. Prove the coverage. Complete the assessment. Authorize the market effect. Verify the released state.” This publication is an independent research and engineering contribution. It is not legal advice, an official CRA implementation guide, a conformity assessment, a notified-body opinion, a harmonised-standard mapping, a European cybersecurity certificate, or regulatory approval. Version 1.1.2 is bounded to the regulatory and implementation state as of 10 September 2026.