What is the CRA EU Declaration of Conformity?
It is the document in which the manufacturer declares that the product with digital elements complies with the Cyber Resilience Act and takes responsibility for that compliance.
For CRA purposes, the declaration states that fulfilment of the applicable essential cybersecurity requirements in Annex I has been demonstrated. It should therefore be consistent with the conformity assessment route, the , the cybersecurity risk assessment, and any harmonised standards, common specifications, cybersecurity certifications, or notified-body certificates relied on.
Before signature, match the declaration to the exact product name, type, compliance-relevant software version or other traceable identifier, applicable Union legislation, standards or specifications actually applied, and notified-body evidence where required. A declaration copied from a related model is not enough unless the stated object and supporting cover the supplied product.
Article 28(1) and 28(4) define the declaration and manufacturer responsibility.
Section 6.8 explains the declaration as the manufacturer's compliance statement.