SPA contributes to Eurosmart paper on scaling CRA conformity assessment through Module H
The Smart Payment Association (SPA) has contributed to a new paper from Eurosmart, a European trade association representing the smart security industry, examining how manufacturers can scale conformity assessment under the EU Cyber Resilience Act (CRA) across large product families, using Module H — Full Quality Assurance — as the assessment route.
Why this matters for payment card manufacturers
Payment card manufacturers typically manage extensive product families and legacy products, some of which fall into the CRA’s Important or Critical categories. Assessing each product through separate, isolated processes risks unnecessary duplication of effort. Module H offers an alternative: rather than building a standalone cybersecurity management process for every product, manufacturers can integrate CRA-specific cybersecurity requirements into the quality assurance system they already operate — commonly built on ISO 9001.
Key points from the paper
- CRA-specific cybersecurity processes can be integrated directly into an existing ISO 9001 Quality Assurance System (QAS)
- No separate Information Security Management System (ISMS) is required
- The approach scales across product families and legacy products, including those classed as Important or Critical
- Notified Bodies independently assess and supervise the extended QAS, along with product-specific evidence
- Product-specific evidence remains central to each assessment, even as the underlying system is assessed once
Taken together, these elements offer a proportionate path to CRA compliance: one that makes more efficient use of Notified Body capacity and supports timely implementation, without lowering the required level of cybersecurity assurance.
Read the full paper
Eurosmart’s paper, “CRA Full Quality Assurance – Leveraging ISO 9001 for Module H Conformity Assessment,” sets out the approach in full, including the role of ISO 9001 as a foundation for the extended QAS, how CRA-specific cybersecurity processes are integrated, and how Notified Bodies assess both the system and the product-specific evidence.
Download the full Eurosmart paper
SPA will continue to work with Eurosmart and other industry partners to support a workable, proportionate approach to CRA implementation for the payment card ecosystem.