Default: self-assessment under internal control Art. 32(1), Annex VIII
For a product that is not an important or critical category, the manufacturer chooses freely among the procedures in Article 32(1): the internal control procedure (module A), EU-type examination (module B) followed by conformity to type (module C), full quality assurance (module H), or, where available and applicable, a European cybersecurity certification scheme. Internal control means you assess your own product and processes against the essential requirements and declare conformity on your own responsibility, without a notified body.
For most SMEs shipping ordinary software, this is the route, which makes compliance a documentation and process exercise you can run yourself rather than an external audit.
Class I: self-assessment only with standards applied in full Art. 32(2), Art. 7
An important product in Class I (Annex III) narrows the choice. You can still use internal control, but only where you have applied harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial" in full to the relevant essential requirements. Where you have not, or where such standards do not exist for the requirement in question, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both of which involve a notified body.
Class II and critical products Art. 32(3), Art. 32(4), Art. 8
A Class II important product removes plain self-assessment altogether. It must use EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". There is no internal-control-only path for Class II.
Critical products (Annex IV) go a step further. Where the Commission has required a European cybersecurity certificate at assurance level at least "substantial" for the category (under Article 8(1)), that certificate is the route. Where those conditions are not met, the critical product falls back to the Class II procedures.
Open-source relief and SME fees Art. 32(5), Art. 32(6)
Two proportionality features matter here. First, a manufacturer of free and open-source software that falls under an Annex III category may demonstrate conformity using the ordinary Article 32(1) procedures (including internal control) despite the important-product listing, provided the technical documentation is made available to the public when the product is placed on the market. Second, the specific interests and needs of SMEs, including start-ups, must be taken into account when setting conformity assessment fees, and those fees must be reduced proportionately.
The modules behind the names Annex VIII
Annex VIII spells out the procedures the article refers to. Module A (internal control) is the self-assessment where you draw up the technical documentation, ensure compliance, affix the CE marking, and declare conformity. Module B (EU-type examination) is where a notified body examines your design and vulnerability handling and attests conformity; it is paired with module C (conformity to type). Module H (full quality assurance) is the notified-body route based on an approved quality system rather than examining a specimen.