Skip to main content
Version status: Published | Document consolidation status: No known changes
Version date: 20 November 2024 - onwards

Annex VIII Conformity assessment procedures

Part I Conformity assessment procedure based on internal control (based on module A)

1. Internal control is the conformity assessment procedure whereby themanufacturer fulfils the obligations set out in points 2, 3 and 4 of this Part, and ensures and declares on its sole responsibility that the products with digital elements satisfy all the essential cybersecurity requirements set out in Part I of Annex I and the manufacturer meets the essential cybersecurity requirements set out in Part II of Annex I.

2. The manufacturer shall draw up the technical documentation described in Annex VII.

3. Design, development, production and vulnerability handling of products with digital elements

The manufacturer shall take all measures necessary so that the design, development, production and vulnerability handling processes and their monitoring ensure compliance of the manufactured or developed products with digital elements and of the processes put in place by themanufacturer with the essential cybersecurity requirements set out in Parts I and II of Annex I.

4. Conformity marking and declaration of conformity