Back to all articles
Compliance path·30 July 2026·5 min read

One assessment for a range of variants

Six variants of the same product do not need six risk assessments. The Commission's guidance sets out when one covers the group, and the deciding factor is narrower than you might expect.

Hardware ranges rarely ship as one product. There is the base model, the one with more memory, the one in white, the one with a different radio. Assessing each from scratch is the kind of work that makes the CRA feel impossible for a small manufacturer.

Section 7.4 of the guidance says you often do not have to.

When a family holds

Where variants share the same architecture, the same security-relevant design and the same intended purpose, and face the same cybersecurity risks, the CRA does not require treating each as an entirely separate product. The group can rely on a single risk assessment, a single set of technical documentation and a single conformity assessment procedure, with one EU declaration of conformity covering them, provided it clearly identifies every variant it applies to.

That last condition is the one people forget. A declaration covering a family has to name the variants. A DoC that silently covers products it does not list is worse than three separate ones.

The deciding factor

Para 176 puts it plainly: what matters is whether the differences are relevant to cybersecurity.

Variations that do not affect cybersecurity properties do not require separate assessments. The guidance names colour, form factor and memory size as examples.

Differences that affect how the essential requirements are implemented do require attention, and it names different communication interfaces, software stacks, update mechanisms and remote connectivity. Where those exist, they must be reflected in the risk assessment and, where necessary, in the conformity assessment and technical documentation.

DifferenceSplits the family?
Colour, housing, form factorNo
Memory or storage sizeNo
Different communication interface, for example adding cellularYes
Different software stack or operating systemYes
Different update mechanismYes
Backend connectivity on one variant onlyYes

The limit

Para 177 keeps responsibility where it belongs. Reliance on a single conformity assessment holds only so far as the variants do not differ in their cybersecurity properties, and where a new variant introduces new risks or changes how the essential requirements are implemented, the existing assessment and documentation have to be updated.

A family is not a filing convenience. It is a statement that these products are, for security purposes, the same product.

Vandorisk lets you group variants, records how they differ, and tells you whether one assessment still covers the group, using these two lists rather than a judgement call.