What certificate does a notified body issue under Module B?
If the product type and vulnerability-handling processes meet the applicable essential cybersecurity requirements, the notified body issues an EU-type examination certificate. The certificate identifies the manufacturer, states the conclusions of the examination, records any validity conditions, and includes the data needed to identify the approved type and vulnerability-handling processes.
If the type or vulnerability-handling processes do not meet the requirements, the notified body must refuse the certificate and give detailed reasons. Modifications that may affect conformity or certificate validity require additional approval as an addition to the original EU-type examination certificate.
Annex VIII Part II points 6 and 7 set the EU-type examination certificate contents, refusal duty, and approval route for relevant modifications.