Cyber Resilience Act
Module C: conformity to type
Practical term
Module C carries the full name “conformity to type based on internal production control” in the Cyber Resilience Act (CRA) and is set out word for word in Annex VIII, Part III. It is not a procedure in its own right but the second half of a two-stage one. A notified body examines the type first, and the manufacturer then ensures, on its own, that the products actually produced conform to that type.
Article 32 therefore never names the two steps separately. Article 32(1), point (b), Article 32(2), point (a) and Article 32(3), point (a) all use the same formula: EU-type examination under module B followed by conformity to EU-type based on internal production control. Assessing conformity on your own responsibility without any type examination is module A; having a quality system assessed instead of a type is module H.
What the manufacturer declares under module C
The declaration in Annex VIII, Part III, point 1 has three components, and the first is often mistaken for the whole:
- the products concerned are in conformity with the type described in the EU-type examination certificate;
- they satisfy the essential cybersecurity requirements in Part I of Annex I;
- the manufacturer meets the essential cybersecurity requirements in Part II of Annex I, that is, the requirements on vulnerability handling.
Annex I appears there twice in express terms, not merely by way of the type. Matching the examined type is therefore no substitute for the shipped product actually meeting the requirements.
Two obligations, and no more
Annex VIII, Part III imposes only points 2 and 3 on the manufacturer. Point 2 covers production. The manufacturer takes all measures necessary so that production and its monitoring ensure conformity of the manufactured products with the approved type and with Part I of Annex I, and ensures that it meets the essential cybersecurity requirements in Part II of Annex I. Point 3 covers marking and declaration.
The CE marking goes on each individual product that conforms to the described type and satisfies the applicable requirements. The written declaration of conformity, by contrast, is drawn up for a product model and must identify which one. It has to be kept at the disposal of national authorities for ten years from placing on the market, or for the support period where that runs longer. A copy goes to the relevant authorities on request.
An authorised representative may discharge the point 3 obligations on the manufacturer’s behalf and under its responsibility, provided the relevant obligations are specified in the mandate. Production under point 2 stays with the manufacturer.
Nobody inspects the production line from outside
Module C itself involves no external examination. The notified body plays its part in module B, but two threads run on from there. It carries out periodic audits of the vulnerability handling processes under Annex VIII, Part II, point 8, and under point 7 every modification to the approved type or to the vulnerability handling processes that may affect conformity with Annex I or the conditions of validity of the certificate must be reported to it and requires an addition to the original certificate.
None of this becomes visible on the product. Article 30(4) lets the identification number of the notified body follow the CE marking only where that body is involved in the module H procedure. After modules B and C the CE marking stands without a number. Annex V, point 7 requires the EU declaration of conformity, on the other hand, to state the name and number of the body, describe the conformity assessment procedure performed and identify the certificate issued, where applicable. After modules B and C that “where applicable” is met.
Software has a production stage too
“Internal production control” sounds like a factory floor. Recital 92 makes clear that software is not carved out. Compiling, building, packaging, making available for download and copying onto physical media should, it says, be considered activities amounting to production when the relevant conformity assessment modules are applied. What is being controlled is therefore also the build and release chain.
Anyone who has to describe it will find the hook in Annex VII, point 2(c). The technical documentation has to contain the necessary information and specifications on the production and monitoring processes of the product and on the validation of those processes. The controls that module C calls for are themselves subject to documentation.
The link to series production
Module C is the procedural face of a duty the manufacturer carries anyway. Article 13(14) requires procedures to be in place so that products in a series of production remain in conformity with the Regulation, and lists what must be adequately taken into account: changes in the development and production process, changes in the design or characteristics of the product, and changes in the harmonised standards, European cybersecurity certification schemes or common specifications referred to in Article 27 by reference to which conformity is declared or by application of which it is verified.
The third item is the one most easily missed. A standard can change without a single line of the product being touched. The conformity declared, however, refers to the version relied on at the time.
What Annex VIII, Part III leaves open
The wording is terse and stays that way. It sets no sample size, no test frequency and no method. “All measures necessary” is left to the manufacturer, to be calibrated to the nature of the product and to the risk. Article 32 provides for no variant of the module involving supervised product checks.
How far an approved type reaches is also left open. The CRA neither defines “product model” nor says how many models a single certificate can carry. What governs is the certificate itself, which under Annex VIII, Part II, point 6 contains the data necessary to identify the approved type and may state conditions for its validity. Which module is available for which product class is covered under Conformity assessment procedures.
Practical questions
-
Annex VIII, Part III, point 3.2 attaches the declaration to the product model, not to the type, and requires it to identify the model it was drawn up for. If the three variants are three product models, that means three declarations. The CRA never defines “product model”, so the dividing line has to be drawn from the product identification that Annex V, point 1 requires for the EU declaration of conformity and from the scope of the approved type. Where it is unclear, settle it in advance with the notified body that fixed that scope.
-
It depends on whether the change touches the approved type. Annex VIII, Part II, point 7 requires the manufacturer to inform the notified body of all modifications to the approved type and to the vulnerability handling processes that may affect conformity with Annex I or the conditions of validity of the certificate; such modifications require an addition to the original certificate. Where the component has no bearing on cybersecurity, the change is a matter for internal production control and for the procedures under Article 13(14). Recital 41 sets the direction: where a conformity assessment involves a third party, a change that might lead to a substantial modification should be notified to that third party.
-
No. Annex VIII, Part III addresses the manufacturer throughout. Only the obligations in point 3, meaning the CE marking and the declaration of conformity, may be discharged by an authorised representative on the manufacturer’s behalf and under its responsibility, and a contract manufacturer is not an authorised representative. Checks and records can of course be assigned by contract, but responsibility for every unit matching the type stays with the manufacturer. The position differs where an importer or distributor places the product on the market under its own name or trade mark: under Article 21 it is then considered to be the manufacturer and is subject to Articles 13 and 14.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.