Module B is the third-party type-examination stage of the CRA B plus C route. It does not replace the manufacturer's technical documentation and does not by itself address ongoing production conformity. The notified body examines the technical design, development and vulnerability handling processes, evaluates evidence and relevant specimens, records its assessment and issues or refuses the EU-type examination certificate.
Module B Is EU-Type Examination
Annex VIII Part II defines Module B as EU-type examination. It is the part of the conformity assessment procedure in which a notified body examines the technical design and development of the product with digital elements and the vulnerability handling processes put in place by the manufacturer. The notified body assesses whether the product meets Annex I Part I and whether the manufacturer meets Annex I Part II.
- Notified-body assessment.
- Technical design and development.
- Product security requirements.
- Vulnerability handling processes.
- Annex I Parts I and II.
Module B Is a Third-Party Procedure
Unlike Module A internal control, Module B requires a notified body to perform the EU-type examination. The manufacturer prepares the product, technical documentation and supporting evidence, while the notified body independently evaluates the matters assigned to Module B. External security testing by an ordinary laboratory is not by itself equivalent to an EU-type examination by a CRA notified body.
- Manufacturer prepares the conformity case.
- Notified body performs Module B examination.
- Testing laboratory and notified body are not automatically the same role.
- Confirm the body's CRA notification scope.
Module B Examines Technical Design and Development
The notified body examines the adequacy of the technical design and development of the product through the technical documentation and supporting evidence. This can include architecture, security design, risk treatment, implementation decisions and other evidence needed to determine whether the technical solution meets the applicable Annex I Part I requirements. Module B therefore reaches deeper than checking whether a final product has a CE mark or passed one penetration test.
- Technical architecture.
- Security design.
- Cybersecurity risk treatment.
- Applicable Annex I requirements.
- Supporting technical evidence.
Module B Also Examines Vulnerability Handling
Annex VIII Part II expressly includes the vulnerability handling processes put in place by the manufacturer. The notified body examines whether those processes meet Annex I Part II. Relevant evidence can include the SBOM process, vulnerability intake, testing and review, remediation, coordinated vulnerability disclosure and secure update distribution. Module B is therefore both a product-design examination and an examination of the manufacturer's vulnerability handling system.
- SBOM and component process.
- Vulnerability intake.
- Security testing and review.
- Remediation.
- Coordinated vulnerability disclosure.
- Secure update distribution.
The Manufacturer Applies to a Single Notified Body
Annex VIII Part II requires the manufacturer to lodge the EU-type examination application with a single notified body of its choice. The application includes the manufacturer information and a written declaration that the same application has not been lodged with another notified body. This prevents parallel applications for the same EU-type examination being pursued with several bodies at once.
- Choose one notified body.
- Provide manufacturer information.
- Identify authorised representative where applicable.
- Declare that the same application has not been lodged elsewhere.
The Application Includes Technical Documentation
The Module B application includes technical documentation capable of allowing the notified body to assess conformity of the product with Annex I Part I and the manufacturer's vulnerability handling processes with Part II. Annex VIII requires that documentation to include an adequate analysis and assessment of the risks, specify the applicable requirements and cover the design, manufacture and operation of the product as relevant to the assessment.
- Applicable requirements.
- Adequate risk analysis and assessment.
- Design information.
- Manufacturing information where relevant.
- Operation of the product.
- Annex VII elements where applicable.
Supporting Evidence Is Separate From the Documentation Index
The application also includes supporting evidence for the adequacy of the technical design and development solutions and the vulnerability handling processes. Annex VIII requires this evidence to identify documents used, particularly where relevant harmonised standards or technical specifications have not been applied in full. Where necessary, the supporting evidence includes test results from the manufacturer's appropriate laboratory or another testing laboratory acting on its behalf and under its responsibility.
- Design evidence.
- Development evidence.
- Vulnerability-process evidence.
- Standards and specification references.
- Relevant test results.
Module B Includes Examination of Critical-Part Specimens
EU-type examination is carried out through review of the technical documentation and supporting evidence together with examination of specimens of one or more critical parts of the product. Annex VIII describes this as a combination of production type and design type. Manufacturers should therefore be prepared to provide the relevant product components or access needed for the notified body to perform the examination.
- One or more critical parts.
- Production-type element.
- Design-type element.
- Evidence and specimen examination are combined.
The Notified Body Reviews Standards and Technical Solutions
The notified body examines the technical documentation and supporting evidence and determines whether relevant harmonised standards or other technical specifications have been applied correctly where they are relied upon. Where those solutions have not been applied, the notified body carries out or has carried out appropriate examinations and tests to determine whether the manufacturer's alternative solutions meet the corresponding essential cybersecurity requirements.
- Review applicable standards.
- Review correct application.
- Assess alternative technical solutions.
- Carry out appropriate examinations and tests where needed.
The Notified Body Can Carry Out or Arrange Tests
Module B is not limited to document review. Annex VIII provides for appropriate examinations and tests, or for the notified body to have those tests carried out, where needed to verify whether the adopted solutions satisfy the corresponding essential cybersecurity requirements. The scope should follow the technical design, identified risks and conformity questions rather than assume one generic test package is sufficient for every product.
- Product examinations.
- Security testing where required.
- Alternative-solution verification.
- Risk-based assessment scope.
- Agreed test location.
The Notified Body Produces an Evaluation Report
After the Module B assessment activities, the notified body draws up an evaluation report recording the activities undertaken and their outcomes. The evaluation report is distinct from the EU-type examination certificate. It records the assessment work, while the certificate is issued where the approved type and vulnerability handling processes meet the applicable Annex I requirements.
- Assessment activities.
- Assessment outcomes.
- Evaluation report.
- Separate certificate decision.
Successful Module B Leads to an EU-Type Examination Certificate
Where the type and the vulnerability handling processes meet the essential cybersecurity requirements in Annex I, the notified body issues an EU-type examination certificate to the manufacturer. The certificate identifies the manufacturer, conclusions of the examination, any validity conditions and the information needed to identify the approved type and vulnerability handling processes. It can include annexes containing further relevant information.
- Approved product type.
- Approved vulnerability handling processes.
- Examination conclusions.
- Conditions for validity where applicable.
- Identification information.
Module B Can End in Refusal
If the type and vulnerability handling processes do not satisfy the applicable Annex I requirements, the notified body refuses to issue the EU-type examination certificate and informs the applicant with detailed reasons. The manufacturer must address the underlying non-conformities rather than treating the assessment as complete merely because the examination has taken place.
- Certificate is not automatic.
- Non-conformity can result in refusal.
- Detailed reasons are provided.
- Manufacturer addresses the identified deficiencies.
Changes to the Approved Type Must Be Controlled
A Module B certificate is tied to the examined type and vulnerability handling processes. Security-relevant changes after approval can affect the basis of the certificate. Manufacturers should maintain change control and inform the notified body of modifications where required by Annex VIII so that the body can determine whether further approval is necessary. Historical evidence should remain traceable to the product version actually examined.
- Control product modifications.
- Control vulnerability-process changes.
- Assess effect on approved type.
- Engage the notified body where required.
- Preserve version traceability.
Module B Must Be Followed by Module C in the B Plus C Route
Article 32 does not present Module B as a standalone complete conformity route. It lists EU-type examination based on Module B followed by conformity to EU-type based on internal production control under Module C. Module B establishes the approved type and vulnerability handling processes. Module C addresses whether manufactured or developed products and the manufacturer's relevant processes remain in conformity with that approved EU type.
- Module B examines and approves the EU type.
- Module C follows Module B.
- Module C addresses conformity to the approved EU type.
- B plus C forms the complete Article 32 route.
Module B and Module A Solve Different Conformity Problems
Module A is internal control under the manufacturer's sole responsibility. Module B is a notified-body examination of the technical design, development and vulnerability handling processes. The procedures therefore differ both in who performs the conformity assessment and in their legal structure. A manufacturer should not describe ordinary external penetration testing during Module A as Module B unless the formal notified-body EU-type examination procedure is actually being used.
- Module A: manufacturer internal control.
- Module B: notified-body EU-type examination.
- Module A can be a complete route where permitted.
- Module B is followed by Module C in the B plus C route.
A Practical Module B Preparation Package
Before lodging a Module B application, manufacturers should have the cybersecurity risk assessment, Annex VII technical documentation, architecture and design records, Annex I control mapping, vulnerability handling documentation, standards and specification evidence, relevant test reports, product-version information and specimens or access to the critical parts ready for examination. Preparing this material before the notified-body review reduces avoidable assessment gaps.
- Cybersecurity risk assessment.
- Annex VII technical documentation.
- Architecture and security design.
- Annex I mapping.
- Vulnerability handling evidence.
- Standards evidence.
- Test results.
- Critical-part specimens or access.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.