CRA and how to comply through the EUCC Certification

21/11/2024

    This article is based on Jose Manuel Pulido (Consulting Manager at jtsec, and Applus+ Company) presentation during the EUCC scheme webinar organized by Applus+ Laboratories in October 2024, and updated in August 2026. 

    (August 2026 update)

    EUCC Becomes Operational 

    Since this article was originally published, the EUCC ecosystem has moved from preparation to implementation. The EUCC became fully applicable on 27 February 2025, and accredited Conformity Assessment Bodies (CABs) have already issued the first EUCC certificates. While the number of certifications remains relatively limited, the scheme is now operational and providing valuable practical experience with Common Criteria-based certifications under the Cybersecurity Act. 

    ENISA Pilot Programme Provides Real-World Validation 

    A major milestone since the publication of the original article has been the EUCC–CRA Interplay pilot programme coordinated by ENISA. Following the publication of ENISA's study on the use of EUCC to support CRA compliance, a series of pilots conducted during late 2025 and early 2026 brought together manufacturers, accredited laboratories and certification bodies to assess the proposed mappings using real products and real certification scenarios. 

    The pilots covered a broad range of technology sectors, including operating systems, mobile devices, smart cards, multifunction printers and network equipment. The programme concluded with a technical workshop in Athens in April 2026, where the European Commission, ENISA and pilot participants reviewed the results and identified areas requiring further refinement. 

    Focus Shifts from Feasibility to Implementation 

    One of the clearest conclusions from the pilots is that the discussion is no longer centred on whether EUCC can support CRA compliance, but on how this can be achieved in an efficient and scalable manner across different technology domains. 

    The practical exercises confirmed that the overall approach proposed by ENISA is technically viable. At the same time, they highlighted that implementation details matter. As a result, current work focuses on refining the mappings between CRA requirements and EUCC technical elements, incorporating lessons learned from specific product sectors and identifying practical ways to extend existing Protection Profiles. Among the approaches being considered are PP-Modules, Functional Packages and optional Protection Profile requirements that could address CRA-specific needs without requiring a complete redesign of existing certification practices. 

    Lessons Learned and Remaining Challenges 

    The pilots also highlighted several practical challenges that will influence future developments. 

    A first challenge concerns scope and coverage. In many cases, the Target of Evaluation (TOE) assessed under Common Criteria does not fully correspond to the complete product that is ultimately placed on the market and subject to CE marking under the CRA. Bridging this gap remains an important consideration when defining future conformity assessment approaches. 

    A second challenge relates to the evolution of Protection Profiles. While many existing PPs already cover a significant portion of the CRA essential requirements, updating legacy profiles and extending them with CRA-specific elements may require additional effort from both industry and certification stakeholders. This topic is particularly relevant for sectors where widely adopted Protection Profiles already exist. 

    Finally, certification lifecycle management emerged as a recurring theme. Topics such as security updates, vulnerability handling, certification maintenance and the scalability of evaluations will play an important role in ensuring that certification schemes remain practical within the continuous compliance model introduced by the CRA. 

    For some product categories and use cases, stakeholders are also exploring complementary conformity assessment approaches, including Module B supported by future harmonised European standards, as a pragmatic way to address CRA-specific requirements that fall outside the traditional scope of Common Criteria evaluations. 

    Looking Ahead 

    European standardisation work supporting the CRA is now well underway following the Commission's Standardisation Request, although harmonised standards are still under development. 

    The outcomes of the ENISA pilots are expected to contribute to the next revision of the EUCC–CRA Interplay study and to support ongoing discussions on the future Delegated Act under Article 27 of the CRA, which is expected by December 2026. Although important technical and procedural questions remain open, the pilot programme has provided valuable evidence that EUCC-based approaches can play a practical role in demonstrating CRA compliance across a broad range of product categories. 

     

    (October 2024 Original Article)

    The Cyber Resilience Act (CRA) is a regulatory framework designed to enforce mandatory cybersecurity requirements for all products with digital elements within the European Union. This presentation explores the key elements of the CRA, its impact on various product categories, and how the EUCC (European common criteria-based cybersecurity certification) scheme can help meet CRA requirements.

    Overview of the Cyber Resilience Act

    The CRA applies to a wide range of products, including hardware, software, firmware, and remote data processing solutions. It mandates cybersecurity requirements to ensure the protection of information and the security of products with digital elements The CRA sets obligations for manufacturers, such as conducting cybersecurity risk assessments, providing security patches, and reporting vulnerabilities.

    Key Deadlines and Requirements
    The CRA was adopted by the European Union Council in October 2024 and will start to apply by January 2028. The regulation defines essential security requirements, divided into two parts: security functionalities and properties (Part 1) and manufacturer obligations (Part 2). These requirements aim to ensure a consistent level of cybersecurity across all products with digital elements.

    Product Categories and Conformity Assessment

    The CRA categorizes products into critical, important (Class 1 and Class 2), and default (non-important and non-critical) categories. The conformity assessment methods vary based on the product's criticality. For critical and important products, assessment methods include NLF assessment methods through Module B plus Module C, and full quality assurance through Module H. Self-assessment is possible only for non-critical and non-important products. The CRA also introduces the concept of presumption of conformity, where products certified under a European cybersecurity certification scheme, such as EUCC, can be presumed to comply with CRA requirements.

    Mapping EUCC to CRA Requirements

    The EUCC scheme, based on common criteria, can help meet CRA requirements through its security functional requirements (SFRs) and security assurance requirements (SARs). By establishing an equivalence between EUCC and CRA requirements, manufacturers can demonstrate compliance with CRA through EUCC certification. The EUCC's vulnerability management obligations and patch management processes also align with CRA requirements.

    Addressing Gaps and Implementation Strategies

    To bridge gaps between existing certifications and CRA requirements, manufacturers may need to update security targets and protection profiles. The EUCC scheme can be adapted to include new SFRs and SARs, ensuring compliance with CRA. For products with remote data processing solutions, additional assessment methods, such as harmonized standards, may be required. For those products where the scope of the EUCC assessment is smaller than the full product, it might be required to demonstrate that the evaluated portion of the TOE guarantees the security of the full product.

    Industry Landscape and Protection Profiles

    The Common Criteria industry is dominated by protection profiles, with a significant portion of certifications being PP-compliant. Critical and important products, such as smart cards and network devices, can benefit from EUCC certification to meet CRA requirements. For non-important products, functional packages and assurance packages can be designed to model the mapping between CRA and EUCC requirements.

    Future Developments and Challenges

    The integration of EUCC with CRA is an ongoing process, with efforts to update protection profiles and develop new assessment methods. The goal is to avoid multiple compliance analyses and ensure a streamlined certification process. The industry must adapt to new regulations while maintaining high standards of cybersecurity.

    In conclusion, the Cyber Resilience Act represents a significant step towards enhancing cybersecurity across the European Union. By leveraging the EUCC scheme, manufacturers can ensure compliance with CRA requirements, providing a robust framework for the certification of digital products. The ongoing efforts to harmonize standards and update protection profiles will play a crucial role in achieving this goal.

    Download the full presentation

    Watch the full video:

    Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). Click HERE for more information. You can accept all cookies by pressing the "Accept" button or configure or reject their use by clicking here.

    Cookie settings panel