Module A is often described as CRA self-assessment, but it is not an exemption or paperwork-only route. The manufacturer becomes the conformity assessor for the applicable case and carries the responsibility for demonstrating that both product security and vulnerability handling meet the CRA. No notified body performs the ordinary Module A assessment.
Module A Is Internal Control
Annex VIII Part I defines Module A as the conformity assessment procedure based on internal control. The manufacturer fulfils the obligations in the module and ensures and declares on its sole responsibility that the product with digital elements satisfies all applicable essential cybersecurity requirements in Annex I Part I and that the manufacturer meets the Part II vulnerability handling requirements.
- Internal-control procedure.
- Manufacturer performs the conformity work.
- Manufacturer carries sole responsibility.
- Part I product requirements are covered.
- Part II vulnerability handling is covered.
Module A Is Self-Assessment, Not an Exemption
Using Module A does not exempt the product from Annex I, Article 13 or Article 31. The procedure changes who performs the conformity assessment, not what the product and manufacturer processes must achieve. The manufacturer needs a defensible technical basis for the declaration of conformity and remains responsible if the evidence does not support the compliance claim.
- Annex I still applies.
- Cybersecurity risk assessment still applies.
- Technical documentation still applies.
- Verification still applies.
- Manufacturer remains responsible.
Module A Requires Annex VII Technical Documentation
Point 2 of Annex VIII Part I requires the manufacturer to draw up the technical documentation described in Annex VII. The evidence should therefore cover the product description, relevant software versions, design and system architecture, vulnerability handling processes, cybersecurity risk assessment, support-period information, applicable standards or technical solutions and test reports. Module A should not be treated as a route where documentation can be created only if an authority later asks for it.
- Product description.
- Architecture and design.
- Vulnerability handling.
- Cybersecurity risk assessment.
- Support-period evidence.
- Standards and technical solutions.
- Test reports.
The Manufacturer Controls Design and Development
Annex VIII Part I requires the manufacturer to take all measures necessary so that design and development ensure conformity with Annex I. This means product-security requirements need to influence architecture, secure defaults, access control, confidentiality, integrity, resilience, update design and other applicable security properties during engineering rather than being checked only after the release candidate exists.
- Security requirements.
- Architecture controls.
- Secure development.
- Risk treatment.
- Design review.
- Implementation verification.
The Manufacturer Controls Production
Module A also covers production. For software and connected products, production can include build pipelines, release processes, firmware generation, signing, configuration and distribution controls. The manufacturer should ensure that the marketed product corresponds to the assessed design and that uncontrolled production changes do not invalidate the conformity evidence.
- Controlled builds.
- Release approval.
- Signing controls.
- Configuration management.
- Product-version traceability.
Vulnerability Handling Is Part of Module A
Annex VIII Part I expressly includes vulnerability handling processes and their monitoring. The manufacturer therefore needs operational evidence for Annex I Part II, including component and SBOM management, vulnerability intake, testing and review, remediation, coordinated vulnerability disclosure and secure update distribution. A product can have strong technical security controls and still have an incomplete Module A conformity case if the manufacturer's vulnerability handling process is not addressed.
- SBOM and component management.
- Vulnerability intake.
- Security testing and review.
- Risk-based remediation.
- Coordinated vulnerability disclosure.
- Secure update distribution.
Monitoring the Relevant Processes Is Part of Internal Control
Annex VIII does not stop at establishing design, development, production and vulnerability handling processes. It also refers to their monitoring. Manufacturers should therefore have practical controls for determining whether those processes continue to operate as intended. Evidence can include release checks, process reviews, vulnerability metrics, audit records, failed-control escalation and corrective-action records.
- Release checks.
- Process monitoring.
- Security review records.
- Vulnerability handling metrics.
- Corrective actions.
Module A Still Needs Verification Evidence
The manufacturer cannot support a conformity declaration only by asserting that controls exist. Annex VII requires reports of tests used to verify conformity of the product and vulnerability handling processes with Annex I. Depending on risk and product design, Module A evidence can include automated security testing, access-control testing, update verification, resilience testing, code review, architecture review, configuration inspection and process validation.
- Map tests to Annex I requirements.
- Identify the tested version.
- Record expected results.
- Record actual results.
- Remediate failures.
- Retest as needed.
Module A Does Not Normally Involve a Notified Body
Ordinary Module A is manufacturer internal control and does not require a notified body to perform the conformity assessment. This is the key procedural difference from Module B plus C and Module H. A manufacturer can still obtain external testing or specialist advice, but using a consultant or laboratory does not transfer the Module A conformity responsibility away from the manufacturer.
- No ordinary notified-body assessment.
- External laboratories can support testing.
- Consultants can support evidence preparation.
- Manufacturer retains the conformity responsibility.
Module A Is Not the Same as Module C
Module A and Module C both involve manufacturer-controlled activities, but they serve different procedural roles. Module A is a complete internal-control conformity procedure where Article 32 permits it. Module C is conformity to an EU type after that type has already been examined and approved under Module B. Manufacturers should not treat the terms internal control and internal production control as interchangeable labels for the same legal route.
- Module A: internal-control conformity procedure.
- Module B: EU-type examination.
- Module C: conformity to the approved EU type.
- B plus C is a combined route.
Module A Ends With the EU Declaration of Conformity
Once the manufacturer has completed the Module A obligations and demonstrated conformity, the manufacturer draws up the written EU declaration of conformity for the product in accordance with Article 28. The declaration should identify the product covered by the conformity conclusion and remain consistent with the technical documentation and product release.
- Complete the conformity evidence.
- Reach the conformity conclusion.
- Draw up the EU declaration of conformity.
- Identify the covered product correctly.
The Manufacturer Affixes the CE Marking
Annex VIII Part I requires the manufacturer to affix the CE marking to each individual product with digital elements that satisfies the applicable requirements. Article 30 provides the broader CE-marking rules. The marking therefore follows the conformity conclusion; it is not a substitute for completing the Module A assessment.
- Conformity first.
- EU declaration of conformity.
- CE marking.
- Market placement.
Keep the Declaration and Technical Documentation
Annex VIII Part I requires the written EU declaration of conformity to be kept together with the technical documentation at the disposal of national authorities for 10 years after the product has been placed on the market or for the support period, whichever is longer. Evidence storage should therefore be designed for long-term retrieval and not depend only on short-lived development systems.
- Keep technical documentation.
- Keep the EU declaration of conformity.
- 10 years after market placement.
- Or the support period where longer.
- Maintain retrievable evidence.
An Authorised Representative Has a Limited Module A Role
Annex VIII Part I permits the manufacturer's obligations concerning the conformity marking and declaration in point 4 to be fulfilled by an authorised representative on the manufacturer's behalf and under its responsibility where those obligations are specified in the mandate. This does not turn the authorised representative into the manufacturer responsible for all Module A design, development, production and vulnerability handling obligations.
- Mandate must cover the relevant obligations.
- Representative acts on the manufacturer's behalf.
- Manufacturer retains responsibility.
- Do not transfer unrelated manufacturer duties by assumption.
A Practical Module A Evidence Package
A practical Module A package can include the Article 13 cybersecurity risk assessment, Annex VII technical documentation, product architecture, Annex I control mapping, security design evidence, SBOM and vulnerability handling documentation, production and release controls, test reports, conformity review record, EU declaration of conformity and release-specific CE-marking record. The CRA does not prescribe one folder structure, but the evidence should support the manufacturer's sole-responsibility declaration.
- Cybersecurity risk assessment.
- Technical documentation.
- Annex I control mapping.
- Vulnerability handling evidence.
- Security test reports.
- Release evidence.
- EU declaration of conformity.
- CE-marking evidence.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.