- Supports cross-cutting EU product-law practice for CE marking, declarations of conformity, technical documentation, and conformity assessment concepts.
"The CE marking is a key indicator"
A guide based on official sources for manufacturers deciding how to demonstrate CRA conformity before placing products with digital elements on the EU market.
Use it to align product classification, standards coverage, technical documentation, the EU declaration of conformity, and CE marking controls.
Structured answer sets in this page tree.
Cited legal and guidance references.
Under the Cyber Resilience Act, CE marking is the visible outcome of a completed . The route is not chosen by convenience alone: it depends on the product category, the coverage of harmonised standards or other recognised conformity bases, and whether the manufacturer can evidence both product cybersecurity requirements and vulnerability-handling processes. These manufacturer conformity and marking duties generally apply to products first placed on the EU market from 11 December 2027. A product placed on the market earlier generally enters the remaining CRA requirements only if it undergoes a substantial modification from that date, although Article 14 reporting starts separately on 11 September 2026 for in-scope products.
Classify the product before choosing a route. The CRA separates products with digital elements into the default category, important products of class I, important products of class II, and critical products. The Commission FAQ explains that important or critical classification turns on the product's core functionality. An important or critical component inside a larger product does not determine the finished product's category by itself. Use Annexes III and IV together with Commission Implementing Regulation (EU) 2025/2392, which supplies the binding technical descriptions for those categories.
This distinction matters for finished-product systems. Integrating a browser, secure element, operating system component, or other listed component does not automatically pull the whole finished product into that component's conformity route. The finished product still needs its own classification and cybersecurity risk assessment.
Article 32 recognises internal control under Module A, EU-type examination under Module B followed by conformity to type under Module C, full quality assurance under Module H, and European cybersecurity certification schemes that the Commission has specified for CRA conformity under Article 27(9).
Default-category products can use Module A. Important class I products can use Module A only where the manufacturer applies the relevant harmonised standards or common specifications, or an applicable specified European cybersecurity certification scheme at assurance level at least substantial, for the relevant requirements. If those instruments do not exist, are only partly applied, or do not cover the relevant requirements, the manufacturer needs Module B plus C or Module H for those requirements.
A European cybersecurity certificate replaces the relevant CRA conformity-assessment steps only when the Commission has specified the scheme under Article 27(9). The specification identifies which Annex I requirements the scheme can cover, and the certificate must meet the stated assurance level and coverage conditions.
Until an applicable scheme has been specified for the product and requirements in question, use Module A where Article 32 permits self-assessment or use Module B plus C or Module H where third-party assessment is required. Record the scheme, certificate scope, assurance level, covered requirements, validity, and any remaining CRA requirements rather than treating certification as a blanket exemption.
Annex VII sets the minimum technical documentation content. It is the file that lets the manufacturer, a notified body, or a market surveillance authority assess conformity against Annex I product requirements and Annex I vulnerability-handling requirements.
The record should connect classification, risk assessment, requirements, standards coverage, tests, software versions, vulnerability processes, support-period reasoning, and the . Where standards, common specifications, or certification schemes are not used in full, the file needs to identify what was applied and describe the alternative solutions used to meet the essential requirements.
Assessment Autopilot can turn Cyber Resilience Act conformity assessment and CE marking work into route decisions, evidence requests, review checkpoints, and release controls in Sorena.
Turn the selected CRA conformity route into owners, technical-file evidence, declaration checks, and CE marking release controls.
Review product classification, standards coverage, notified-body needs, and evidence gaps before launch.
For Module B plus C, Annex VIII requires the notified body to assess the product's technical design and development, supporting evidence, specimens of critical parts, and the manufacturer's vulnerability-handling processes.
For Module H, the notified body assesses the full quality system and checks whether the manufacturer can consistently identify applicable CRA requirements, perform the necessary examinations, and keep products compliant through design and production. That makes change control, release governance, and vulnerability-management evidence central to the assessment.
After a positive , the manufacturer draws up the under Article 28 and affixes CE marking under Articles 29 and 30. The declaration is the manufacturer's responsibility statement that the product with digital elements complies with the CRA.
The CRA allows either the full declaration following Annex V or a simplified declaration following Annex VI that gives the internet address for the full declaration. Where several EU harmonisation acts require an EU declaration for the same product, Article 28 requires a single declaration covering the applicable acts.
CRA CE marking must be visible, legible, and indelible. For software products, Article 30 allows CE marking either on the or on the website accompanying the software product, provided the relevant section is easily and directly accessible to consumers.
Article 30 requires the notified body's identification number to follow the CE marking only where that body is involved through full quality assurance under Module H. Module B plus C uses a notified body for EU-type examination, but does not require that body's number next to the CRA CE marking. Market surveillance authorities can treat a missing Module H number, wrongly affixed marking, or unsupported marking as formal non-compliance and require corrective action.
"The CE marking is a key indicator"
"The conformity assessment is a legal procedure"
"Products with digital elements should bear the CE marking"