CRA Module A: internal control (self-assessment)

Last reviewed: 11 September 2026~7 min read

Most products can self-assess. If your product is not on the Annex III list of important products or the Annex IV list of critical products, Module A applies and no notified body is involved. The Commission's own estimate is that roughly nine in ten products with digital elements fall in this default category.

Which route applies to you

Conformity assessment routes by product category
CategoryRoute availableNotified body?
Default (not listed)Module A — internal controlNo
Important, Class I (Annex III)Module A if harmonised standards, common specifications or a certification scheme are applied in full; otherwise Module B+C or Module HConditional
Important, Class II (Annex III)Module B+C, Module H, or a European cybersecurity certification scheme at assurance level substantialYes
Critical (Annex IV)European cybersecurity certification scheme where mandated by delegated act; otherwise the Class II routesYes

See the full Annex III and Annex IV lists →

The Class I trap. Module A is available to Class I products only where the relevant harmonised standards have been applied in full. As of today the CRA harmonised standards are still in development. A Class I manufacturer who plans to self-assess is betting on standards being published, cited in the Official Journal, and implementable in time. Have a notified body plan in reserve, and start the conversation early — capacity is finite and everyone will arrive in 2027.

What Module A actually requires

Module A is described as internal production control. It has four parts, and people who assume "self-assessment means light touch" tend to skip the last two.

  1. Draw up the technical documentation. The complete Annex VII set. Nothing is reduced because no notified body will read it. What Annex VII requires →
  2. Carry out the conformity assessment. Establish and record that the product and the vulnerability handling processes meet the Annex I essential requirements. This is an activity that produces evidence, not a conclusion you assert.
  3. Take the measures that ensure the manufacturing process keeps the product conforming. For software this means your build, release and update process — reproducibility, signing, and control over what actually ships.
  4. Affix CE and draw up the declaration of conformity, then keep both the declaration and the technical documentation for ten years or the support period, whichever is longer.

The evidence a self-assessment should leave behind

Self-assessment is only defensible if it produced artefacts. If a market surveillance authority asks how you concluded the product meets Annex I, these are what answer the question:

  • A cybersecurity risk assessment tied to the product's intended and reasonably foreseeable use, dated and versioned.
  • A requirement-by-requirement mapping of Annex I Part I to the design decision, control or test that satisfies it — including the requirements you judged not applicable, with the reasoning.
  • Test reports: the security testing you ran, what it covered, what it found and what you did about the findings.
  • A documented vulnerability handling process meeting Annex I Part II, with the SBOM, the coordinated disclosure policy and the secure update mechanism.
  • A support period determination with the reasoning behind the length chosen.
  • A sign-off record: who reviewed it, when, and against which product version.
The honest summary. Module A does not reduce what you must do. It removes the third party who would otherwise tell you whether you had done it. For a competent team that is a gift; for an unprepared one it is a trap, because nobody stops you shipping and the first review of your work may be adversarial.

Module B+C and Module H, briefly

Module B + Module C is EU type-examination followed by conformity to type. A notified body examines the design and issues a certificate; you then declare each product conforms to the certified type. Suited to hardware and to products with a stable design.

Module H is full quality assurance. A notified body approves and audits your quality system covering design, development and final inspection. Suited to organisations already running certified quality systems and shipping frequently — which describes most software companies. If you are a Class II software vendor, Module H is usually the less painful of the two.

Sources