Cyber Resilience Act
Module A: internal control
Practical term
Module A is the conformity assessment procedure based on internal control. The Cyber Resilience Act (CRA) names it in Article 32(1), point (a), and sets it out in full in Annex VIII, Part I. What characterises it is what is absent: no external body, no certificate, nothing that can expire or be withdrawn.
Point 1 of Annex VIII, Part I states what the procedure amounts to. The manufacturer fulfils the obligations set out in points 2, 3 and 4, and ensures and declares on its sole responsibility that the products satisfy all the essential cybersecurity requirements in Part I of Annex I, and that the manufacturer itself meets the requirements in Part II of Annex I. Those are two statements, not one: the second concerns not the product but the manufacturer’s vulnerability handling processes.
What Annex VIII, Part I requires
- Point 2: the manufacturer draws up the technical documentation described in Annex VII.
- Point 3: it takes all measures necessary so that the design, development, production and vulnerability handling processes and their monitoring ensure conformity.
- Point 4.1: it affixes the CE marking to each individual product that satisfies the applicable requirements.
- Point 4.2: it draws up a written EU declaration of conformity under Article 28 for each product and keeps it, together with the technical documentation, at the disposal of the national authorities for ten years after placing on the market, or for the support period where that runs longer. A copy goes to the relevant authorities on request.
Two turns of phrase repay a second look. Point 4.1 speaks of each individual product, not of the product model. And point 4.2 names the “national authorities”, whereas Article 13(13) orders the same retention for market surveillance authorities. The set of bodies that can ask to see the file is drawn more widely in the Annex.
Point 3 is the duty that gets skimmed
Points 2 and 4 can be ticked off: a document, a mark, a declaration. Point 3 cannot. It bites on the processes themselves and expressly on their monitoring, and it names vulnerability handling in the same breath as design, development and production.
Module A therefore describes a state, not a moment. Drawing up the declaration is a commitment that the processes described keep running. Article 13(14) draws the same line for series production: changes in the development and production process, in the design or characteristics of the product, and in the harmonised standards, European cybersecurity certification schemes or common specifications under Article 27 that the declaration relies on must all be adequately taken into account.
What is missing when nobody checks from outside
After module A the CE marking stands alone. Article 30(4) lets the identification number of a notified body follow the marking only where that body is involved in the procedure based on full quality assurance. Module A involves no such body, and therefore carries no number.
There is equally nothing to renew: no period of validity, no surveillance audit, no counterpart reviewing interim results. The first outside look normally comes when a market surveillance authority asks, and at that point the technical documentation carries the case on its own. Article 28(4) spells out what the declaration commits you to: by drawing it up, the manufacturer assumes responsibility for the conformity of the product.
When module A is available
For products the CRA classifies as neither important nor critical, module A is a free choice. For important products in class I, Article 32(2) makes the route conditional on harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least “substantial” being applied in full. Which classification leads to which procedure is set out in the entry on Conformity assessment procedures.
Two points are easily lost here. Under recital 91 any manufacturer remains free to choose a stricter procedure involving a third party even where module A would suffice. And choosing wrongly carries a fine: infringements of Article 32(1), (2) and (3) fall under Article 64(3) into the tier of up to EUR 10 million or 2 % of total worldwide annual turnover for the preceding financial year, whichever is higher.
What an authorised representative may take on
Point 5 of Annex VIII, Part I allows an authorised representative to fulfil the obligations in point 4 on the manufacturer’s behalf and under its responsibility, provided the mandate specifies them. That covers the CE marking, the declaration of conformity and keeping the file available.
Points 2 and 3 are not on that list. The technical documentation and the measures taken on the development and vulnerability handling processes stay with the manufacturer. Handing Union representation to a service provider moves the formalities, not the substance.
Practical questions
-
For products the CRA classifies as neither important nor critical, yes. Recital 91 says so expressly: the internal control procedure stays open even where a manufacturer chooses not to apply an applicable harmonised standard in whole or in part. The price is paid in the documentation. Annex VII, point 5 then calls for descriptions of the solutions adopted to meet the requirements in Parts I and II of Annex I, together with a list of the other technical specifications applied. The effort moves from applying a standard to justifying what you did instead.
-
The CRA does not answer this directly. Annex VIII, Part I, point 4.2 requires a written declaration for each product with digital elements and requires that declaration to identify the product it was drawn up for. The test is therefore unambiguous identification, not the number of documents. Annex V, the model to which Article 28(2) ties the declaration, calls in point 1 for the name and type plus any additional information allowing unambiguous identification. In practice that rests on the marking required by Article 13(15), meaning a type, batch or serial number or another identifying mark, and for software on the versions that the technical documentation has to list in any case under Annex VII, point 1(b).
-
Recital 41 considers it appropriate, where a substantial modification occurs that may affect conformity or where the intended purpose changes, that conformity be verified and the product undergo a new conformity assessment where applicable; it draws no distinction between procedures. Where the manufacturer has a third party involved in the assessment, a change that might lead to a substantial modification should be notified to that party. Under module A there is no third party, so assessment, decision and evidence all stay in house. That does not make the step smaller, only less visible, and it pushes the entire burden of proof into the technical documentation.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.