Skip to content
#software testing Open access

CRA Product Classification and Conformity-Assessment Governance

Sep 2026 · Zenodo (CERN European Organization for Nuclear Research)

Abstract

This flagship white paper develops an engineering governance architecture for product classification and conformity assessment under the Cyber Resilience Act (CRA). Its central thesis is that product classification is not a marketing label and conformity assessment is not a one-time paperwork choice. The exact product must be classified according to its core functionality and the current legal category structure, after which the applicable conformity route must be determined from the product class, evidence coverage, presumption mechanisms, certification state, third-party assessment requirements, cross-regime rules, and application-date conditions. The paper distinguishes product identity, classification determination, evidence state, conformity route, authorization decision, and actual market outcome as separate control objects. It introduces a Classification & Conformity Envelope and Classification Passport that bind the exact product baseline, intended purpose, core functionality, Annex III/IV category, legal-description version, evidence coverage, conformity route, notified-body or certification state, cross-regime state, validity and re-open triggers. The analysis covers ordinary products, Important Class I and Class II products, critical products, the core-functionality integration rule, Implementing Regulation (EU) 2025/2392, harmonised-standard and common-specification coverage, and the distinction between Article 27(8) certification-based presumption and the separate Article 27(9) certification route. It emphasizes that the existence of a standard or cybersecurity certificate does not by itself establish complete CRA conformity or release authority. The paper also addresses the mandatory third-party boundary for Class II products, live Article 8 certification conditions for critical products, the special Article 32(5) route for qualifying important free and open-source software, the Article 32(5a) EHR-system route introduced through the European Health Data Space framework, and CRA Article 12 coordination with high-risk AI systems. A further contribution is the treatment of notified-body and certificate status as live execution context. Scope, validity, conditions, change approvals, suspension or withdrawal must remain current at the point of market release; a historical certificate alone is not sufficient authority for a changed product state. Building on Execution Governance (EG), the paper applies the principle that ability is not authority to the CRA conformity boundary. Technical readiness, successful testing, a CE mark, or possession of a certificate does not independently authorize the exact market effect. The authorization decision must remain bound to current product identity, classification, legal route, evidence coverage, third-party state and release scope. The paper further provides requirement and decision matrices, a manufacturer reference architecture, Proceed/Review/Hold/Block failure semantics, illustrative Classification Passport and conformity-authorization JSON records, and a 30-day implementation sprint for moving from spreadsheet-based classification toward evidence-backed, authorization-bound conformity governance. Its series doctrine is: “Classify the product. Qualify the route. Prove the coverage. Complete the assessment. Authorize the market effect. Verify the released state.” This publication is an independent research and engineering contribution. It is not legal advice, an official CRA implementation guide, a conformity assessment, a notified-body opinion, a harmonised-standard mapping, a European cybersecurity certificate, or regulatory approval. Version 1.1.2 is bounded to the regulatory and implementation state as of 10 September 2026.

View source

Similar papers

#computer vision Review Sep 2017

Agile Software Development Methods: Review and Analysis

This publication proposes a definition and a classification of agile software development approaches and analyses ten software development methods that can be characterized as being "agile" against the defined criterion.

P. Abrahamsson, O. Salo, Jussi Ronkainen et al. · 727 citations · ⚡54
#computer vision Jun 2008

The impact of agile practices on communication in software development

The study shows that agile practices improve both informal and formal communication, but indicates that, in larger development situations involving multiple external stakeholders, a mismatch of adequate communication mechanisms can sometimes even hinder the communication.

M. Pikkarainen, Jukka Haikara, O. Salo et al. · 401 citations · ⚡48
#machine learning Review Open access Oct 2014

Software development in startup companies: A systematic mapping study

The results indicate that software engineering work practices are chosen opportunistically, adapted and configured to provide value under the constrains imposed by the startup context.

Nicolò Paternoster, Carmine Giardino, M. Unterkalmsteiner et al. · 394 citations · ⚡54
#computer vision Review Mar 2008

Agile methods in European embedded software development organisations: a survey on the actual use and usefulness of Extreme Programming and Scrum

The results show that the embedded industry has been able to apply agile methods in its development processes and that the appreciation of the agile methods and their individual practices appears to increase once adopted and applied in practice.

O. Salo, P. Abrahamsson · 238 citations · ⚡9
#computer vision Open access Jul 2017

What happens when software developers are (un)happy

Consequences of happiness and unhappiness that are beneficial and detrimental for developers' mental well-being, the software development process, and the produced artifacts are found.

D. Graziotin, Fabian Fagerholm, Xiaofeng Wang et al. · 236 citations · ⚡13
#computer vision Open access Oct 2004

Mobile-D: an agile approach for mobile application development

The Mobile-D approach is briefly outlined here and the experiences gained from four case studies are discussed, which helped develop an agile development approach for mobile application development.

P. Abrahamsson, Antti Hanhineva, H. Hulkko et al. · 225 citations · ⚡18

Related blog posts

GPT-Lab Sep 17, 2026

Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering

AI is making software generation faster, but speed does not remove the need for expertise. As more work is delegated to AI, tacit knowledge may become one of the most important human advantages in software engineering. The post Beyond Prompt Engineering: The Role of Tacit Knowledge in Software Engineering appeared first on GPT-Lab.

MIT News · Artificial Intelligence Aug 17, 2026

Q&A: Rethinking how innovation happens

In his latest book, Professor Eugene Fitzgerald examines the forces that turn breakthroughs into value — and why innovation resists simple formulas.

Microsoft Research Blog Aug 12, 2026

MindTopo reveals VLMs’ spatial reasoning abilities

A path, a fence, a knot. MindTopo sets a new benchmark for testing how AI understands topological relationships and highlights new opportunities to strengthen spatial reasoning and planning. The post MindTopo reveals VLMs’ spatial reasoning abilities appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.