Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge
  • English (US)
  • English (UK)
  • Deutsch
All context cards

Context card

Module H under the CRA: BSI TR-03183-H builds full quality assurance on ISO/IEC 27001

How can a manufacturer demonstrate CRA conformity through its processes rather than product by product, and what does BSI TR-03183-H add?

By knowledge.aitechdoc.world

Reviewed

Review log and changes

The short answer

Through Module H, full quality assurance under Annex VIII of the CRA: a notified body approves and periodically audits the manufacturer's quality system for design, development, production and vulnerability handling. TR-03183-H describes one way to build that quality system on an ISO/IEC 27001 information security management system, refined and extended for products with digital elements and complemented by ISO 9001 elements. It is not a new management system standard, and its approval still includes a product-type-specific review of technical documentation.

For: Quality and information security managers, product compliance managers, notified body liaisons and technical writers maintaining technical documentation

Key points

  • Module H certifies the manufacturer's processes; Module B+C examines the product type (EU-type examination) and adds conformity to type. Under the CRA, both are among the procedures for important products.
  • TR-03183-H (version 1.1.0) refines and adds to ISO/IEC 27001 clauses 4 to 10 and gives CRA-specific guidance for ISO/IEC 27002 controls; everything it does not change applies unchanged.
  • The scope covers placing products on the market and providing the remote data processing that belongs to them; one ISMS may cover several product types and lines if all lifecycle processes are in scope.
  • Harmonized standards or common specifications cited for presumption of conformity are the "conformance specifications" to apply; deviations need a risk-based justification. TR-03183-1 is not a conformance specification and can be used only as guidance.
  • Under the CRA, Module H always includes a review of the technical documentation for one model of each product category and an auditor with product expertise, so the difference from Module B+C is smaller than in other EU legislation.

The context

Two ways to involve a notified body

For products that need third-party conformity assessment, the Cyber Resilience Act offers procedures that look at different things. Module B+C has a notified body examine the product type (EU-type examination) and the manufacturer ensure conformity to that type. Module H (Annex VIII, full quality assurance) has the notified body approve and audit the manufacturer's quality system for design, development, final product inspection and testing, and vulnerability handling over the support period.

What TR-03183-H does

The BSI guideline describes one way to demonstrate conformity through Module H using an ISO/IEC 27001 information security management system. It is not a new management system standard. It:

  • refines and adds to the requirements of ISO/IEC 27001 (clauses 4 to 10 apply unchanged where it says nothing), for instance on interested parties — the manufacturer and the third parties affected by the product's cybersecurity risks — scope, risk assessment and treatment, change planning and documented information;
  • gives CRA-specific guidance on ISO/IEC 27002 controls such as threat intelligence, technical vulnerabilities, the secure development lifecycle, security testing and change management;
  • adds elements of ISO 9001 quality management where Module H needs them, because a QMS alone does not anticipate changing a product after it is placed on the market, and an ISMS alone does not cover product quality assurance.

The ISMS covers both business services: placing products with digital elements on the market and providing the remote data processing that belongs to them. Updates and other measures from vulnerability handling count as changes and go through the design, development and production process.

Standards inside the quality system

The guideline calls harmonized standards and common specifications cited for presumption of conformity "conformance specifications". They are to be used to interpret, implement and assess the essential requirements; deviating needs a justification based on the risks, intended purpose, conditions of use and expected time in use. Where none exists, sector standards and best practice apply. TR-03183-1 is expressly not a conformance specification; it can serve as guidance without a conformity claim.

Benefits and risks

Because the certificate covers the quality system, one approval can cover a whole category of products and frequent updates without a new type examination each time; certification typically runs in three-year cycles with annual surveillance audits. The risk is the reverse: if the certificate is lost, conformity of everything produced under it is at stake, and products made without a valid certificate generally cannot regain it. Changes to the quality system have to be notified to the notified body and may trigger a reassessment.

Not a pure process certificate under the CRA

Under the CRA, Module H includes a review of the technical documentation for one model of each product category and an auditing team with at least one assessor experienced in the product field. Module B+C, in turn, comes with regular audits of the vulnerability handling requirements. The guideline concludes that the two are less distinct under the CRA than in other EU legislation. Choosing a module never replaces meeting the essential requirements.

Questions readers ask next

Does an ISO/IEC 27001 certificate satisfy Module H?
No. Module H needs a quality system approved by a notified body under Annex VIII of the CRA, covering product development, production and vulnerability handling and including a technical documentation review. TR-03183-H shows how an existing ISMS can be extended to get there.
Can the manufacturer change its processes freely once Module H is approved?
No. Planned changes to the quality system have to be reported to the notified body, which decides whether the approval still holds or a reassessment is needed; extending the scope to new product categories usually needs one.

Sources

  1. Technical Guideline TR-03183-H: Cyber Resilience Requirements for Manufacturers and Products, Conformity based on full quality assurance (Module H), version 1.1.0 — Federal Office for Information Security (BSI), May 30, 2026
  2. Regulation (EU) 2024/2847 (Cyber Resilience Act) — Official Journal of the European Union, November 20, 2024
  3. BSI TR-03183: overview of the four parts — CyberKlartext, August 13, 2026

Review log and changes

Every context card is checked against its sources before it is published, and again whenever it changes; the date under the byline is the last review. Corrections (something was wrong) and additions (something was missing) are logged below with date and time (Berlin time). Typos, formatting and link fixes are not listed.

Reviewed

No corrections or additions since publication.