What is Module A under the Cyber Resilience Act?
Module A is the CRA conformity assessment procedure based on internal production control.
Under Annex VIII Part I, the manufacturer ensures and declares, on its sole responsibility, that the product with digital elements satisfies the applicable product cybersecurity requirements in Annex I Part I and that the manufacturer's vulnerability-handling processes satisfy Annex I Part II. The route applies to products placed on the Union market from 11 December 2027, subject to the Article 32 eligibility rules.
Annex VIII Part I defines internal control and places responsibility for product and vulnerability-handling conformity on the manufacturer; Article 71(2) sets the 11 December 2027 main application date.
The module table describes Module A as internal production control covering design and production, with no conformity-assessment body involvement.