Default category
What the category covers
Every product with digital elements that appears neither in Annex III nor in Annex IV. That covers the vast majority of the market: business software, mobile applications, games, office tools, connected objects with no security function, general-purpose libraries.
The category is therefore defined by subtraction, not by a list. The classification sheet must accordingly demonstrate that the product was tested against the Annex III and Annex IV lists and ruled out of each — not merely assert that it is “standard”.
The conformity route: module A
Module A — internal control of production (Annex VIII, Part I) is open without condition. The manufacturer:
- carries out and documents the cybersecurity risk assessment;
- designs, develops and produces the product in accordance with the Annex I essential requirements;
- compiles the Annex VII technical documentation;
- takes the measures needed for the manufacturing process to ensure series conformity;
- draws up the EU declaration of conformity (Annex V);
- affixes the CE marking.
No notified body is involved, and no body number is affixed next to the marking.
What “self-assessment” does not mean
This is the most widespread misreading in the field, and an expensive one.
| What module A removes | What module A does not remove |
|---|---|
| Having the file verified by an accredited third party | Compiling the technical documentation |
| Paying a notified body | Carrying out and documenting the risk assessment |
| Waiting for an assessment slot | Producing a machine-readable SBOM |
| Freezing a version for type examination | Establishing a coordinated disclosure policy |
| — | Determining and publishing a support period |
| — | Reporting within 24 hours actively exploited vulnerabilities |
| — | Retaining file and declaration for ten years |
The substance of the obligations is identical to that of a class II product. Only external verification disappears.
The real risk
It lies not in the classification but in the inspection. A market surveillance authority may, at any time and without prior grounds, demand the technical documentation for a product it bought off the shelf. Three situations follow:
- Complete file: the demonstration takes days, and the matter ends there.
- Incomplete file: an order to bring the product into conformity within a set period, with a risk of restriction on making it available while the gaps are closed.
- No file at all, despite an affixed CE marking: this is formal non-compliance compounded by an inaccurate declaration. The penalty ceiling for supplying incorrect or misleading information to authorities applies on top.
The point. Self-assessment shifts the burden of proof; it does not remove it. A self-declared but empty file is worse than an absent marking, because it is a false statement rather than an omission.
Module A checklist
- Signed PDE qualification sheet
- Classification sheet demonstrating that Annexes III and IV were ruled out
- Documented and dated cybersecurity risk assessment
- Coverage of the Annex I, Part I requirements, with justification for those ruled out
- Operational Annex I, Part II vulnerability handling process
- SBOM generated, validated, signed, archived
- Coordinated disclosure policy published, contact point live
- Support period determined, justified, communicated to the buyer
- Annex II information and instructions to the user shipped
- Annex VII technical documentation complete
- Annex V EU declaration of conformity signed
- CE marking affixed in accordance with the rules
- Ten-year archiving configured