Cyber Resilience Act
Module B: EU-type examination
Practical term
Module B of the Cyber Resilience Act (CRA) is called EU-type examination and is set out in full in Annex VIII, Part II. It denotes the part of a conformity assessment procedure in which a notified body examines the technical design and development of a product with digital elements together with the vulnerability handling processes put in place by the manufacturer. Where the examination succeeds, the body attests that the product meets the essential cybersecurity requirements in Part I of Annex I and that the manufacturer meets those in Part II.
The wording says “part of a conformity assessment procedure”, and it means it literally. Module B never stands alone. Article 32 names it only in combination with module C, conformity to type based on internal production control. Neither the CE marking nor the EU declaration of conformity follows from the certificate, because both arise only there. A manufacturer that prefers an approved and monitored quality system over this pairing takes module H, and one entitled to assess on its own responsibility takes module A. Which route is open to which product class is covered under Conformity assessment procedures.
Two subjects of examination
A product and a set of processes are examined. The yardstick for the product is Part I of Annex I, and for the vulnerability handling processes Part II. One certificate covers both, and both remain subject to continuing duties once it has been issued.
Point 2 defines how the examination is carried out: by assessing the adequacy of the technical design and development, on the basis of the technical documentation and the supporting evidence, together with an examination of specimens of one or more critical parts of the product. The Regulation calls this a combination of production type and design type. A complete production unit is therefore not what is required.
The application
The application goes to a single notified body of the manufacturer’s choice. Point 3 lists what accompanies it:
- the name and address of the manufacturer, plus those of the authorised representative where that representative lodges the application
- a written declaration that the same application has not been lodged with any other notified body
- the technical documentation, which must include an adequate analysis and assessment of the risks and, wherever applicable, at least the elements listed in Annex VII
- supporting evidence for the adequacy of the technical design and development solutions and of the vulnerability handling processes; it has to mention any documents that were used, in particular where relevant harmonised standards or technical specifications were not applied in full
That last point drives the effort. The further a product departs from the available standards, the more evidence the manufacturer has to produce on its own, and the harder it becomes to predict how long the procedure will run.
What the body does
- It examines the technical documentation and supporting evidence against Parts I and II of Annex I (point 4.1).
- It verifies that the specimens were developed or manufactured in conformity with the technical documentation, and separates the elements designed in accordance with relevant standards from the rest (point 4.2).
- It carries out appropriate examinations and tests, or has them carried out. Where standards were applied, the question is whether they were applied correctly; where they were not, whether the manufacturer’s own solutions meet the requirements (points 4.3 and 4.4).
- It agrees with the manufacturer on where the examinations and tests take place (point 4.5).
It then draws up an evaluation report recording those activities and their outcomes. That report is released, in full or in part, only with the manufacturer’s agreement, without prejudice to the body’s obligations towards its notifying authorities.
The certificate
Where the type and the vulnerability handling processes meet the requirements of Annex I, the body issues an EU-type examination certificate. It carries the name and address of the manufacturer, the conclusions of the examination, any conditions for its validity and the data needed to identify the approved type and the vulnerability handling processes. One or more annexes may be attached. Certificate and annexes must hold all relevant information needed to judge later whether the products manufactured or developed conform to the examined type and whether the vulnerability handling processes conform, and to allow for in-service control. Where type and processes fall short, the body refuses the certificate and states its reasons in detail.
One consequence regularly comes as a surprise. Under Article 30(4) the identification number of the notified body follows the CE marking only where that body took part in the module H procedure. After modules B and C the CE marking stands alone, even though a body examined the product here too.
After the certificate is issued
Issuing the certificate does not end the relationship with the body. Point 7 obliges it to keep itself apprised of changes in the generally acknowledged state of the art which indicate that the approved type and the vulnerability handling processes may no longer comply with the requirements of Annex I, and to determine whether such changes call for further investigation. Where they do, it informs the manufacturer. Running the other way, the manufacturer must inform the body of every modification to the approved type and to the vulnerability handling processes that may affect conformity or the conditions of validity. Such modifications require additional approval in the form of an addition to the original certificate.
Point 8 adds periodic audits by the body, so that the processes under Part II of Annex I stay adequately implemented. Where it finds that the product no longer complies, it requires corrective measures and suspends or withdraws the certificate if necessary (Article 47(5) and (6)).
Retention and information flows
The manufacturer keeps a copy of the certificate, its annexes and additions together with the technical documentation at the disposal of national authorities for ten years after the product was placed on the market, or for the support period where that runs longer. The body keeps its own copy, along with the technical file, until the validity of the certificate expires.
Alongside that run information flows the manufacturer does not control. Every notified body informs its notifying authority of the certificates it has issued and withdrawn, and makes available to it, periodically or on request, the list of those refused, suspended or otherwise restricted. The application under point 3 and the duties in points 7 and 10 may be taken over by the authorised representative, provided the mandate specifies them.
What the CRA leaves open
Three questions that arise before the application is lodged go unanswered in the Regulation. Point 9 speaks of the validity of the certificate expiring, yet nowhere fixes a period; which conditions of validity apply is left to the body under point 6. Nor does the CRA set any deadline by which a procedure has to be completed. And what counts as a specimen of a critical part for software alone remains unregulated. All three belong in the first conversation with the body, not in the period after the application has gone in.
Practical questions
-
The body has to give detailed reasons for its refusal and to require appropriate corrective measures from the manufacturer (Annex VIII, Part II, point 6 and Article 47(4)). Every Member State must make an appeal procedure against notified body decisions available under Article 48. Quietly moving on to the next body, by contrast, does not go unnoticed. Bodies carrying out similar conformity assessments for the same products supply one another with relevant information on negative results (Article 49(2)).
-
Both are possible. A notified body may pass tasks to a subsidiary or a subcontractor, but only with the manufacturer’s agreement; it retains full responsibility and informs its notifying authority (Article 41). The supporting evidence includes, where necessary, the results of tests carried out by an appropriate laboratory of the manufacturer, or by another testing laboratory on its behalf and under its responsibility (Annex VIII, Part II, point 3.4). They do not replace the body’s own assessment, because point 4 requires it to carry out appropriate examinations and tests itself or have them carried out.
-
No. The duty in point 7 attaches to modifications of the approved type and of the vulnerability handling processes that may affect conformity with Annex I or the conditions for validity of the certificate. The threshold therefore sits below a substantial modification, since “may affect” is already enough. Recital 39 makes clear that a security update which does not change the intended purpose is not a substantial modification, and recital 41 expects a change that might lead to one to be notified to the third party involved. In practice the change process needs a criterion that picks exactly those cases out.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.