Cyber Resilience Act

Module A: internal control

Practical term

Module A is the conformity assessment procedure based on internal control. The Cyber Resilience Act (CRA) names it in Article 32(1), point (a), and sets it out in full in Annex VIII, Part I. What characterises it is what is absent: no external body, no certificate, nothing that can expire or be withdrawn.

Point 1 of Annex VIII, Part I states what the procedure amounts to. The manufacturer fulfils the obligations set out in points 2, 3 and 4, and ensures and declares on its sole responsibility that the products satisfy all the essential cybersecurity requirements in Part I of Annex I, and that the manufacturer itself meets the requirements in Part II of Annex I. Those are two statements, not one: the second concerns not the product but the manufacturer’s vulnerability handling processes.

What Annex VIII, Part I requires

  • Point 2: the manufacturer draws up the technical documentation described in Annex VII.
  • Point 3: it takes all measures necessary so that the design, development, production and vulnerability handling processes and their monitoring ensure conformity.
  • Point 4.1: it affixes the CE marking to each individual product that satisfies the applicable requirements.
  • Point 4.2: it draws up a written EU declaration of conformity under Article 28 for each product and keeps it, together with the technical documentation, at the disposal of the national authorities for ten years after placing on the market, or for the support period where that runs longer. A copy goes to the relevant authorities on request.

Two turns of phrase repay a second look. Point 4.1 speaks of each individual product, not of the product model. And point 4.2 names the “national authorities”, whereas Article 13(13) orders the same retention for market surveillance authorities. The set of bodies that can ask to see the file is drawn more widely in the Annex.

Point 3 is the duty that gets skimmed

Points 2 and 4 can be ticked off: a document, a mark, a declaration. Point 3 cannot. It bites on the processes themselves and expressly on their monitoring, and it names vulnerability handling in the same breath as design, development and production.

Module A therefore describes a state, not a moment. Drawing up the declaration is a commitment that the processes described keep running. Article 13(14) draws the same line for series production: changes in the development and production process, in the design or characteristics of the product, and in the harmonised standards, European cybersecurity certification schemes or common specifications under Article 27 that the declaration relies on must all be adequately taken into account.

What is missing when nobody checks from outside

After module A the CE marking stands alone. Article 30(4) lets the identification number of a notified body follow the marking only where that body is involved in the procedure based on full quality assurance. Module A involves no such body, and therefore carries no number.

There is equally nothing to renew: no period of validity, no surveillance audit, no counterpart reviewing interim results. The first outside look normally comes when a market surveillance authority asks, and at that point the technical documentation carries the case on its own. Article 28(4) spells out what the declaration commits you to: by drawing it up, the manufacturer assumes responsibility for the conformity of the product.

When module A is available

For products the CRA classifies as neither important nor critical, module A is a free choice. For important products in class I, Article 32(2) makes the route conditional on harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least “substantial” being applied in full. Which classification leads to which procedure is set out in the entry on Conformity assessment procedures.

Two points are easily lost here. Under recital 91 any manufacturer remains free to choose a stricter procedure involving a third party even where module A would suffice. And choosing wrongly carries a fine: infringements of Article 32(1), (2) and (3) fall under Article 64(3) into the tier of up to EUR 10 million or 2 % of total worldwide annual turnover for the preceding financial year, whichever is higher.

What an authorised representative may take on

Point 5 of Annex VIII, Part I allows an authorised representative to fulfil the obligations in point 4 on the manufacturer’s behalf and under its responsibility, provided the mandate specifies them. That covers the CE marking, the declaration of conformity and keeping the file available.

Points 2 and 3 are not on that list. The technical documentation and the measures taken on the development and vulnerability handling processes stay with the manufacturer. Handing Union representation to a service provider moves the formalities, not the substance.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.