Complete our quick form
Assessment and future certification of the product cybersecurity management system in accordance with the Cyber Resilience Act.
The Cyber Resilience Act (CRA) Module H defines a conformity pathway based on full assurance of the product cybersecurity management system, covering its entire lifecycle—from design and development to post-market activities.
Unlike other conformity routes focused on product-by-product assessments, Module H enables organizations to demonstrate CRA compliance through a robust and centralized management system, consistently integrating:
This approach is particularly suitable for manufacturers with multiple products, higher technical complexity, or stringent assurance requirements, as it allows for consistent and scalable regulatory compliance management. Module H is expected to become one of the preferred pathways for CRA compliance, especially for products classified as Important and Critical. However, its effective implementation will depend on the European accreditation and notification framework, which is currently under development.
CRA Module H requires organizations to demonstrate that they have mature, effective, and consistent processes capable of ensuring ongoing compliance with CRA requirements. Applus+ Laboratories is currently in the process of accreditation and notification as a Notified Body.
Once the scheme is fully operational, the Module H assessment will be based on a combination of services, including:
Comprehensive evaluation of the processes and controls supporting product cybersecurity, including:
This evaluation verifies alignment between quality processes and both horizontal and vertical requirements for each product type within the CRA scope.
Process audits conducted against:
The approach focuses on demonstrating the actual maturity and effectiveness of the management system, not just the existence of documentation.
Structured review of:
This review ensures traceability between identified risks, implemented controls, and assessment outcomes.
Structured sampling of products to verify the correct implementation of the management system in real products representative of the certified family or product line.
In-depth analysis of critical processes required under the CRA, including:
Once certification is issued and the scheme is officially available:
The CRA Module H service—Cybersecurity Management System Assessment—is intended for organizations requiring a structural, scalable, and long-term approach to Cyber Resilience Act compliance, particularly:
While the European accreditation and notification framework for CRA Module H is still under definition, Applus+ Laboratories offers a set of progressive preparation services tailored to each organization’s maturity level.
For organizations at earlier stages:
For organizations with a higher level of readiness or established management systems:
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.
Based on your behavior on the website (where you click, how long you browse, etc.) we establish parameters and a profile for you to display ads that correspond to your interests. See the cookies we store in our Cookies Policy.