Default category

What the category covers

Every product with digital elements that appears neither in Annex III nor in Annex IV. That covers the vast majority of the market: business software, mobile applications, games, office tools, connected objects with no security function, general-purpose libraries.

The category is therefore defined by subtraction, not by a list. The classification sheet must accordingly demonstrate that the product was tested against the Annex III and Annex IV lists and ruled out of each — not merely assert that it is “standard”.

The conformity route: module A

Module A — internal control of production (Annex VIII, Part I) is open without condition. The manufacturer:

  1. carries out and documents the cybersecurity risk assessment;
  2. designs, develops and produces the product in accordance with the Annex I essential requirements;
  3. compiles the Annex VII technical documentation;
  4. takes the measures needed for the manufacturing process to ensure series conformity;
  5. draws up the EU declaration of conformity (Annex V);
  6. affixes the CE marking.

No notified body is involved, and no body number is affixed next to the marking.

What “self-assessment” does not mean

This is the most widespread misreading in the field, and an expensive one.

What module A removes What module A does not remove
Having the file verified by an accredited third party Compiling the technical documentation
Paying a notified body Carrying out and documenting the risk assessment
Waiting for an assessment slot Producing a machine-readable SBOM
Freezing a version for type examination Establishing a coordinated disclosure policy
Determining and publishing a support period
Reporting within 24 hours actively exploited vulnerabilities
Retaining file and declaration for ten years

The substance of the obligations is identical to that of a class II product. Only external verification disappears.

The real risk

It lies not in the classification but in the inspection. A market surveillance authority may, at any time and without prior grounds, demand the technical documentation for a product it bought off the shelf. Three situations follow:

  • Complete file: the demonstration takes days, and the matter ends there.
  • Incomplete file: an order to bring the product into conformity within a set period, with a risk of restriction on making it available while the gaps are closed.
  • No file at all, despite an affixed CE marking: this is formal non-compliance compounded by an inaccurate declaration. The penalty ceiling for supplying incorrect or misleading information to authorities applies on top.

The point. Self-assessment shifts the burden of proof; it does not remove it. A self-declared but empty file is worse than an absent marking, because it is a false statement rather than an omission.

Module A checklist

  • Signed PDE qualification sheet
  • Classification sheet demonstrating that Annexes III and IV were ruled out
  • Documented and dated cybersecurity risk assessment
  • Coverage of the Annex I, Part I requirements, with justification for those ruled out
  • Operational Annex I, Part II vulnerability handling process
  • SBOM generated, validated, signed, archived
  • Coordinated disclosure policy published, contact point live
  • Support period determined, justified, communicated to the buyer
  • Annex II information and instructions to the user shipped
  • Annex VII technical documentation complete
  • Annex V EU declaration of conformity signed
  • CE marking affixed in accordance with the rules
  • Ten-year archiving configured