Cyber Resilience Act (CRA) › Chapter III — Conformity of the product with digital elements Taking into account the level of technical development and the approach on conformity assessment of a third country, the Union may conclude Mutual Recognition Agreements with third countries, in accordance with Article 218 TFEU, in order to promote and facilitate international trade.
In practice Meroi Security’s note, not part of the regulation
The article allows the Union to conclude these agreements under Article 218 TFEU, and the Blue Guide says what they do. Mutual recognition agreements are established between the Union and third countries which are on a comparable level of technical development and have a compatible approach concerning conformity assessment. They are based on the mutual acceptance of certificates, marks of conformity and test reports issued by the conformity assessment bodies of either party in conformity with the legislation of the other party. That description comes from the Blue Guide and is not mandated by the CRA.
Source: the Regulation, Article 34 ; Blue Guide 2022 (2022/C 247/01) §9.2, horizontal product-law guidance that predates the CRA
Need help applying this in practice?
Reading the regulation is the easy part. We help manufacturers work out
what it means for a specific product, and what evidence a notified body
will expect.
CRA compliance services
Source and currency. Text of Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements, reproduced from
EUR-Lex
(CELEX 32024R2847) as at 16 August 2026. © European Union,
1998–2026. Reuse is authorised under
the EUR-Lex legal notice .
Only the Official Journal of the European Union is authentic and produces
legal effect. This reader is provided for convenience and does not
constitute legal advice.