FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Module B+C

What does CRA module C add after module B?

Module C is the production-control step.

After obtaining the EU-type examination certificate, the manufacturer must ensure and declare that the products actually manufactured remain in conformity with the approved type and continue to satisfy the essential cybersecurity requirements.

Citations
Cyber Resilience Act

Defines Module C as conformity to type based on internal production control after the Module B certificate.

CRA Module B+C

Under CRA Module B+C, does module C mean the notified body supervises the production phase directly?

Not in the way module H does.

Under module C, the manufacturer itself must take the necessary measures so that production and production monitoring ensure conformity with the approved type and the applicable essential cybersecurity requirements. Module C is therefore not a full-quality-assurance route supervised like Module H.

Citations
CRA Module B+C

What must the manufacturer do under CRA module C before placing products on the market?

The manufacturer must:

- ensure that production conforms to the approved type

- affix the CE marking to each individual compliant product

- draw up a written declaration of conformity for the product model

Citations
Cyber Resilience Act

Requires production conformity, CE marking on each compliant product, and a written declaration of conformity for the product model.

CRA Module B+C

Under CRA module C, is the declaration of conformity for each individual product or for the product model?

It is for the product model.

Annex VIII Part III point 3.2 requires a written declaration of conformity for a product model. That differs from module A wording, which refers to each product with digital elements.

Citations
Cyber Resilience Act

States that Module C uses a declaration of conformity for a product model and identifies that model.

CRA Module B+C

Does the CE marking still have to go on each individual product under CRA Module B+C?

Yes.

Even though the declaration under module C is for the product model, the CE marking must still be affixed to each individual product with digital elements that conforms to the approved type.

Citations
Cyber Resilience Act

Requires CE marking on each individual product that conforms to the approved type and satisfies the CRA.

CRA Module B+C

What happens under CRA Module B+C if the approved type or vulnerability-handling processes change after certification?

The manufacturer must inform the notified body that holds the technical documentation relating to the certificate of any modifications that may affect conformity or the conditions for validity of the certificate.

Those modifications require additional approval in the form of an addition to the original EU-type examination certificate.

Citations
Cyber Resilience Act

Requires manufacturer notification and certificate additions for modifications that may affect conformity or certificate-validity conditions.

CRA Module B+C

Is CRA Module B+C reassessment required only for "substantial modifications"?

Not only for that label.

Annex VIII Part II point 7 is framed more broadly: the trigger is any modification to the approved type or the vulnerability-handling processes that may affect conformity with Annex I or the conditions for validity of the certificate.

Citations
Cyber Resilience Act

Uses a conformity-or-certificate-validity trigger for post-certificate modifications, not only a label such as substantial modification.

CRA Module B+C

Does CRA Module B+C include surveillance after the certificate is issued?

Yes, but it is limited.

The notified body must carry out periodic audits to ensure that the vulnerability-handling processes in Part II of Annex I are implemented adequately. This is not the same as the broader quality-system surveillance under module H.

Citations
Cyber Resilience Act

Requires periodic notified-body audits of the manufacturer's vulnerability-handling processes.

CRA Module B+C

Under CRA Module B+C, who gets informed about issued, refused, withdrawn, suspended, or restricted EU-type examination certificates?

The notified body must inform its notifying authorities and the other notified bodies about those certificate outcomes.

The Commission and Member States can also obtain copies of the certificates and, on request, copies of the technical documentation and examination results.

Citations
Cyber Resilience Act

Sets the notified body's information duties for certificate issuance, withdrawal, refusal, suspension, restriction, and requests by authorities.

CRA Module B+C

How long must the manufacturer keep CRA Module B+C records?

The manufacturer must keep:

- the EU-type examination certificate, its annexes and additions, together with the technical documentation

- the declaration of conformity for the product model

Those records must be kept at the disposal of national authorities for 10 years after the product is placed on the market or for the support period, whichever is longer.

Citations
Cyber Resilience Act

Requires retention of the certificate package and product-model declaration for 10 years after market placement or the support period, whichever is longer.

CRA Module B+C

Can an authorised representative handle some CRA Module B+C steps?

Yes, but only where the mandate expressly covers them.

Under Annex VIII Part II point 11, the authorised representative may lodge the module B application and fulfil the obligations relating to modifications and record retention. Under Annex VIII Part III point 4, the authorised representative may fulfil the declaration obligations in module C.

Citations
Cyber Resilience Act

Allows an authorised representative to handle specified Module B+C obligations only where the mandate covers them.

CRA Module B+C

Can important free-and-open-source software still use CRA Module B+C?

Yes.

Article 32(5) allows manufacturers of Annex III products qualifying as free and open-source software to use one of the procedures listed in Article 32(1), provided the technical documentation is made public at the time of placing on the market. That means they may use module A, but they may also choose Module B+C.

Citations
Cyber Resilience Act

Allows Annex III free-and-open-source software manufacturers to use Article 32(1) procedures, including Module B+C, if the technical documentation is public at market placement.

CRA Module B+C

Under the Cyber Resilience Act, do older EU-type certificates issued under other Union product laws automatically disappear on 11 December 2027?

No.

Article 69(1) provides a transition rule: EU-type examination certificates and approval decisions issued regarding cybersecurity requirements for products with digital elements under other Union harmonisation legislation remain valid until 11 June 2028, unless they expire earlier or that other legislation specifies otherwise.

Citations
Cyber Resilience Act

Keeps certain pre-CRA cybersecurity EU-type certificates and approval decisions valid during the CRA transition period, subject to expiry and other-law limits.

CRA Module B+C

What usually makes a CRA Module B+C file workable in practice?

A workable file is one that lets the notified body trace the compliance claim, the supporting design choice, the evidence, and the tested specimen without gaps.

Based on Annex VIII Part II and Annex VII, that usually means the application clearly identifies the applicable requirements, includes the risk analysis and assessment, explains any reliance on or departure from harmonised standards or technical specifications, and contains the supporting evidence and test results needed for the notified body's examination.

Citations
Cyber Resilience Act

Connects the Module B application file to the technical documentation contents, risk analysis, standards mapping, supporting evidence, and tests.

CRA Module B+C

Does CRA Module B+C require the notified body's identification number next to the CE marking?

No.

Under Article 30(4), the CE marking is followed by the notified body's identification number only where that body is involved in the conformity assessment procedure based on module H. Under Module B+C, the manufacturer still affixes the CE marking to each individual compliant product under module C, but the CRA does not require a notified-body number next to that marking.

Citations
Page 25 of 58