Article 32(1) of the Cyber Resilience Act, Regulation (EU) 2024/2847, lets a manufacturer demonstrate conformity through "the internal control procedure (based on module A) set out in Annex VIII", and for a product that is not on Annex III or IV that is the route almost everyone will take. Which tier a product falls in decides whether module A is available; this article is about what it contains once it is. The Regulation gives it five points in Annex VIII Part I. The Commission's FAQ on the implementation, version 1.4 of 4 September 2026, section 6, turns them into a list of activities and answers the questions that follow: which methodology, what the file must look like, where the CE mark goes on software, what the declaration says, and when harmonised standards will exist to self-assess against.

Who may use module A

The FAQ's entry 6.1 lists three cases. Every product "that do not have the core functionality of a category of important or critical products", the default category. Important products of class I "if a harmonised standard has been applied in accordance with Article 32(2)". And important products of class I or II that are free and open-source software, "provided that the technical documentation is made available to the public, in accordance with Article 32(5)". Class II products that are not open source, and critical products, need a notified body or a certification scheme, and no notified body under the Regulation existed on the day the reporting duty started.

The five points of Annex VIII Part I

Point 1 defines the procedure: internal control is where "the manufacturer fulfils the obligations set out in points 2, 3 and 4 of this Part, and ensures and declares on its sole responsibility that the products with digital elements satisfy all the essential cybersecurity requirements set out in Part I of Annex I and the manufacturer meets the essential cybersecurity requirements set out in Part II of Annex I". Both halves of Annex I, the product properties and the vulnerability handling process, and "sole responsibility".

Point 2: "The manufacturer shall draw up the technical documentation described in Annex VII."

Point 3, on design, development, production and vulnerability handling: "The manufacturer shall take all measures necessary so that the design, development, production and vulnerability handling processes and their monitoring ensure compliance of the manufactured or developed products with digital elements and of the processes put in place by the manufacturer with the essential cybersecurity requirements set out in Parts I and II of Annex I." That sentence is the whole of what "assessment" means in module A: measures, processes, and their monitoring, on the manufacturer's side.

Point 4: affix the CE marking "to each individual product with digital elements that satisfies the applicable requirements", and draw up "a written EU declaration of conformity for each product with digital elements in accordance with Article 28 and keep it together with the technical documentation at the disposal of the national authorities for 10 years after the product with digital elements has been placed on the market or for the support period, whichever is longer".

Point 5: an authorised representative may carry out point 4 on the manufacturer's behalf "provided that the relevant obligations are specified in the mandate".

The activities the FAQ lists

Entry 6.1 restates the procedure as five activities: implement "the necessary cybersecurity mitigation measures in the product following the risk assessment"; verify "via testing or other mechanism" that the product complies with the relevant essential requirements; draw up the technical documentation; once the manufacturer "is in a position to demonstrate" compliance, affix the CE marking and "draw up and sign a declaration of conformity"; and "ensure that the production of the different units of the product with digital elements does not alter the compliance". For software, the last one is the release process: the thing that turns an assessed build into the copies customers download must not change what was assessed, which is the same discipline substantial modification asks for release by release.

No methodology is mandated, and testing is not deterministic

Entry 6.5 says what many vendors of tools would rather it did not: "The CRA does not mandate the use of any specific evaluation methodology, potentially including testing." Applying a harmonised standard or technical specification is "common practice", not a requirement. Tests may be run "in their own laboratories, if available, or in external ones", the Regulation "does not lay down any specific requirements on laboratories", and "the manufacturer assumes the sole responsibility for the conformity assessment". Market surveillance authorities "might perform tests or evaluation procedures during the relevant inspections", may use the manufacturer's methodology "especially if that methodology is part of harmonised standard", and "may apply a different methodology, on a justified basis". The FAQ's last sentence on the point is the one to keep: "cybersecurity testing is not deterministic as in other NLF-regulated fields and the results might not be unique". The defence is a documented method and the record of having applied it, not a particular tool.

The technical documentation: any language, not public, comprehensive and clear

Entry 6.6: the documentation "must contain the elements laid down in Annex VII", point by point. It "is not only an internal deliverable but it might be requested by the market surveillance authorities", so "it has to be comprehensive and clear", and the manufacturer "must be able to demonstrate that the product has been designed, developed and manufactured to comply with the essential requirements", which "includes specifications of vulnerability handling processes". It "can be written in any language", but if an authority asks for it "it needs to be provided in a language easily understood by this authority". And there is "no obligation to make the technical documentation available to a manufacturer's customers or to the public", with one exception: open-source manufacturers of class I or II products who self-assess under Article 32(5), whose documentation must be public.

The CE mark, on software

Entry 6.7 with Article 30(1): for products "in the form of software, the CE marking shall be affixed either to the EU declaration of conformity referred to in Article 28 or on the website accompanying the software product. In the latter case, the relevant section of the website shall be easily and directly accessible to consumers." The mark is "a simple visual self-declaration", it "cannot be affixed if the manufacturer has not performed a conformity assessment procedure, with a positive result", and on physical products it is at least 5 mm. The CE-mark article has the rest.

The declaration of conformity: two forms, one per product

Entry 6.8 with Article 28 and Annexes V and VI. The full declaration follows Annex V: the product's name and type and "any additional information enabling the unique identification", the manufacturer's name and address, "a statement that the EU declaration of conformity is issued under the sole responsibility of the provider", the object of the declaration, the statement of conformity with the relevant Union harmonisation legislation, "references to any relevant harmonised standards used or any other common specification or cybersecurity certification in relation to which conformity is declared", the notified body where one was involved, and a signature with place, date, name and function. The simplified declaration of Annex VI is one sentence with the address of the full one: "Hereby, … [name of manufacturer] declares that the product with digital elements type … is in compliance with Regulation (EU) 2024/2847. The full text of the EU declaration of conformity is available at the following internet address: …".

Three FAQ points on it: the declaration "is a document linked to the individual product and not only to the type or model", though "it is not needed that it includes the unique identifier"; "a new version of the product might need a new declaration of conformity, especially when it implements a substantial modification"; and where several Union acts apply, Article 28(3) requires "a single declaration of conformity in respect of all such Union acts", which "may be a dossier made up of relevant individual Declarations of conformity".

Harmonised standards: what self-assessment will be measured against

Until a harmonised standard's reference is published in the Official Journal, module A means assessing against Annex I directly and documenting "the solutions adopted", as Annex VII point 5 puts it. Entry 6.10 gives the plan. The standardisation request M/606 asked CEN, CENELEC and ETSI for 15 horizontal standards, clustered into three deliverables: one on designing, developing and producing products "in such a way that they ensure an appropriate level of cybersecurity based on the risks", and one on vulnerability handling, both "to be adopted by the ESOs by 30 August 2026"; and one covering the product properties of Annex I Part I, "to be adopted by the ESOs by 30 October 2027". It asked for 26 vertical standards, "which the ESOs are addressing through 31 separate deliverables", for the Annex III and IV categories, "to be adopted by the ESOs by 30 October 2026". Adoption by the standards bodies is not publication: under Article 27(6) the Commission then assesses each standard under Regulation (EU) No 1025/2012 before citing it. A draft amendment to the request published in July 2026 moves the 2026 dates back by about two months, and the FAQ's own line on the point is unchanged: "the use of harmonised standards is voluntary", and conformity "via other technical means" documented in the technical file remains open.

For a default product that means the self-assessment you do in 2027 is the one Annex VIII describes, with or without a standard: the risk assessment, the measures, the verification, the file, the mark, the declaration. For a class I product it means the self-assessment route does not open until the vertical standard for its category is cited, and the file built against Annex I in the meantime is what the notified body, when one exists, will read.

What to keep

The module A record for one product is short: the risk assessment and the measures it led to; the method used to verify each essential requirement and its results, dated; the technical file under Annex VII; the declaration in the Annex V form, signed, with the Annex VI sentence where the product accompanies it; the CE mark's location, declaration or website; and the release control that keeps shipped copies equal to the assessed build. StandardOS keeps the technical file and its evidence as living records with the ten-year retention Annex VIII point 4.2 sets, which is longer than most companies keep anything.

Sources

  • Regulation (EU) 2024/2847, Article 27(1) and (6), Article 28, Article 30(1), Article 32(1), (2) and (5), Annex V, Annex VI, Annex VII point 5, Annex VIII Part I.
  • European Commission, FAQs on the Cyber Resilience Act, version 1.4 of 4 September 2026, entries 6.1, 6.5, 6.6, 6.7, 6.8, 6.9 and 6.10.
  • European Commission, standardisation request M/606, C(2025) 618, and the draft amendment of July 2026.

This is not legal advice. Annex VIII Part I is five points on one page, and the FAQ's section 6 is eight; together they are the definition of "self-assessment", and worth reading before buying a tool that promises it.