31 Aug 2026 CRA – ISO 9001 and Module H: A scalable approach to CRA conformity assessment
As the implementation of the Cyber Resilience Act (CRA) moves forward, manufacturers need conformity assessment approaches that are both robust and scalable, particularly when managing large product portfolios and product families.
In its latest paper, Eurosmart explores the use of Full Quality Assurance (Module H) as a conformity assessment route under the CRA and examines how existing ISO 9001-based Quality Assurance Systems can provide a strong foundation for integrating CRA-specific cybersecurity requirements.

ISO 9001 and Module H:
A scalable approach to CRA conformity assessment
Executive Summary
The Cyber Resilience Act provides Full Quality Assurance, based on Module H of the New Legislative Framework, as a conformity assessment route for Important and Critical Products with Digital Elements (PwDEs). This approach is particularly relevant for manufacturers managing large product portfolios, product families and legacy products.
ISO 9001 provides a natural and scalable management-system foundation for CRA Module H. CRA-specific cybersecurity processes can be integrated into an existing Quality Assurance System (QAS), without requiring a separate Information Security Management System (ISMS).
ISO 9001 provides the foundation upon which CRA-specific requirements and product-specific evidence can be integrated and assessed under Module H. Notified Bodies assess and supervise the extended QAS, its CRA-specific cybersecurity processes and the relevant product-specific evidence against the applicable CRA requirements.
By combining established quality assurance practices, cybersecurity expertise and product-specific evidence, Module H provides a proportionate and scalable approach to conformity assessment. It can reduce unnecessary duplication, make efficient use of Notified Bodies’ capacity and facilitate the timely implementation of the CRA while maintaining the required level of cybersecurity assurance.
Read the full paper
The Eurosmart paper provides further analysis of the Module H approach, the role of ISO 9001 as a QAS foundation, the integration of CRA-specific cybersecurity processes and the role of Notified Bodies in assessing both the quality assurance system and product-specific evidence.

