FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
856of856items
Across 40 modules • Updated Jul 24, 2026
Author
Sorena AI
Published
Mar 10, 2026
Updated
Jul 24, 2026
CRA Blue Guide Concepts

Why does the Blue Guide matter for intended purpose and reasonably foreseeable use under the CRA?

Because the CRA uses the same product-law logic that compliance cannot be assessed only against the manufacturer's preferred use case.

The Commission's CRA FAQ relies on Blue Guide Concepts to explain that the cybersecurity risk assessment must take account of intended purpose, reasonably foreseeable use and reasonably foreseeable misuse, and that those choices also affect the user information that has to be provided.

Citations
Blue Guide 2022

Supports the answer on intended purpose, reasonably foreseeable use and misuse in CRA risk assessment and user information; sections 2.8 and 3.1.

CRA Blue Guide Concepts

How are CRA Blue Guide market-placement concepts applied to standalone software supplied digitally?

For software, the CRA follows the same NLF concepts, but the draft Commission guidance explains how they work in a digital delivery model.

According to the draft guidance, once the software manufacturing phase is complete and a given software product is first offered for distribution or use on the Union market in the course of a commercial activity, that software product is regarded as placed on the market. Later downloads or remote access to that same unchanged software product are instances of making available rather than fresh placing-on-the-market events.

Citations
Cyber Resilience Act

Supports the answer on draft CRA guidance on digital supply of standalone software and the first offering as placement; Article 3(21) and Article 3(22).

CRA Blue Guide Concepts

Under CRA Blue Guide concepts, does a later non-substantial software version get a new placing-on-the-market date?

No.

The draft guidance says later iterations that do not qualify as substantial modifications do not trigger a new conformity assessment and do not change the software product's date of placement on the market. A new placing-on-the-market date arises only where the later iteration qualifies as a substantial modification.

Citations
Cyber Resilience Act

Supports the answer on draft CRA guidance on non-substantial software iterations not creating a new placement date; Article 3(30) and recital 41.

CRA Blue Guide Concepts

Under CRA Blue Guide concepts, does the same software-placement rule apply to physical media or hardware bundles?

No.

The draft guidance says the "first offering creates the placing-on-the-market date" logic applies only to standalone software supplied via digital means. If the software is supplied on a USB flash drive or other physical medium, the physical item is the product supplied for distribution. If software is necessary for hardware to perform its intended functions, the hardware and that software together form the product placed on the market.

Citations
Cyber Resilience Act

Supports the answer on draft CRA guidance distinguishing standalone digital software from physical media and hardware bundles; Article 3(1).

CRA CE Marking

What does the CE marking mean under the CRA?

The CE marking is the manufacturer's visible self-declaration that the product with digital elements complies with the CRA and any other applicable EU harmonisation law that also requires CE marking.

The mark is not a standalone approval, security certificate, or authority-issued licence. Before launch, confirm that the evidence behind it is complete: conformity assessment, risk assessment, technical documentation, EU declaration of conformity, user information, and any required notified-body involvement.

Citations
Cyber Resilience Act

Articles 29 and 30 set the CRA CE-marking rules; Article 13 links affixing the mark to demonstrated conformity.

European Commission CRA FAQs

Section 6.7 explains CE marking as the manufacturer's visual self-declaration for CRA and other applicable New Legislative Framework laws.

Blue Guide 2022

Section 4.5.1.1 explains the general EU product-law meaning of CE marking and the manufacturer's responsibility.

CRA CE Marking

When can a manufacturer affix the CRA CE marking?

Only after the applicable CRA conformity assessment procedure has been completed with a positive result. The mark must be affixed before the product with digital elements is placed on the market.

For a launch review, do not treat CE marking as a packaging-only task. The manufacturer should first confirm the selected Article 32 route, the product's classification, the risk assessment, the essential-requirement coverage, the vulnerability-handling evidence, and the EU declaration of conformity.

Citations
Cyber Resilience Act

Article 13(12) requires technical documentation and conformity assessment before the EU declaration and CE marking; Article 30(3) requires affixing before placing on the market.

CRA CE Marking

Which CRA conformity assessment routes can lead to CE marking?

Article 32 recognises internal control under module A, EU-type examination followed by conformity to type under modules B+C, full quality assurance under module H, and, where available and applicable, specified European cybersecurity certification schemes.

Module A is self-assessment. Modules B+C and H involve a notified body. Important or critical products may have narrower route choices, especially where harmonised standards, common specifications, or qualifying certification schemes are not applied or do not exist for the relevant requirements.

Citations
Cyber Resilience Act

Article 32 lists module A, modules B+C, module H, and available applicable certification schemes; paragraphs 2 and 3 set additional rules for important and critical products.

CRA CE Marking

Does CRA CE marking require a notified body number?

Not always. Under the CRA, the notified body's identification number follows the CE marking where the notified body is involved in conformity assessment based on full quality assurance, module H.

For module B+C, a notified body examines the design and development and issues the relevant certificate, but Article 30(4) ties the identification number after the CE mark to module H. The launch evidence should therefore record both the route used and whether a notified-body number is legally expected next to the mark.

Citations
Cyber Resilience Act

Article 30(4) links the notified-body identification number after the CE marking to full quality assurance under module H.

CRA CE Marking

Where must the CE marking appear for hardware and physical products?

The CRA rule is product first: the CE marking must be visible, legible, and indelible on the product with digital elements. If that is not possible or not warranted because of the product's nature, it must be put on the packaging and on the EU declaration of conformity accompanying the product.

Aesthetics alone are not a sound reason to move the mark away from the product. For physical products, a website-only CE marking is not the CRA fallback; the website option is specific to software products.

Citations
European Commission CRA FAQs

Section 6.7 explains the visibility rule, the general size rule, and why reduced visibility cannot be justified by aesthetics alone.

CRA CE Marking

Where does the CE marking go for software products?

For a product with digital elements in the form of software, the CRA allows the CE marking either on the EU declaration of conformity or on the website accompanying the software product.

If the website route is used, the relevant website section must be easily and directly accessible to consumers. Practical evidence should include the URL, the page content, the release or product version covered, and a way to prove that the page was live and accessible when the software was placed on the market.

Citations
Cyber Resilience Act

Article 30(1) gives the CRA-specific software placement option for the EU declaration of conformity or accompanying website.

CRA CE Marking

What size, format, and visibility checks matter before release?

The CE marking must follow the general CE-marking principles in Regulation (EC) No 765/2008 and the CRA's visible, legible, and indelible placement rule. The CRA expressly allows the marking to be lower than 5 mm where the nature of the product warrants it, provided the mark remains visible and legible. Otherwise, the general CE-marking proportions and minimum-height rule apply.

Review the final product, packaging, declaration, software website page, screenshots, labels, and manuals together before launch. The mark should not be hidden in a location that is not easily visible in the product's intended use.

Citations
Cyber Resilience Act

Article 29 applies the general CE-marking principles; Article 30(1) and (2) set CRA affixing and proportion requirements.

European Commission CRA FAQs

Section 6.7 discusses the general 5 mm rule and visibility expectations; the binding CRA-specific exception is in Article 30(2).

Blue Guide 2022

Section 4.5.1.4 provides general CE-marking placement guidance for products, packaging, and accompanying documents.

CRA CE Marking

What must be ready in the EU declaration of conformity?

The EU declaration of conformity is the document where the manufacturer declares that the product complies with the CRA and takes responsibility for that conformity. It must use the CRA Annex V model structure, be updated as appropriate, and be available in the languages required where the product is placed or made available on the market.

Where several EU harmonisation acts apply, the CRA requires one EU declaration of conformity covering all those acts. The Commission FAQ also explains that the product may be accompanied by the full declaration or by the simplified declaration from Annex VI with an internet address where the full declaration can be accessed.

Citations
Cyber Resilience Act

Article 28 and Annex V define the EU declaration of conformity; Annex VI provides the simplified declaration text.

European Commission CRA FAQs

Section 6.8 explains full and simplified declaration formats, single declarations for multiple EU acts, and the link to positive conformity assessment.

CRA CE Marking

What technical documentation supports CRA CE marking?

The technical documentation must contain the data and details needed to show that the product with digital elements and the manufacturer's processes comply with the CRA essential cybersecurity requirements. It must include at least the Annex VII elements.

In practice, the CE-marking evidence file should include the cybersecurity risk assessment, product description and versions, design and development evidence, vulnerability-handling process evidence, applied standards or technical specifications, test or evaluation results, user information, declaration materials, and records explaining why any essential requirement is not applicable.

Citations
Cyber Resilience Act

Article 31 and Annex VII define the technical documentation; Article 13(4) requires the cybersecurity risk assessment to be included.

European Commission CRA FAQs

Sections 4.1.8 and 6.6 explain that the technical documentation must be comprehensive enough for market surveillance authorities.

CRA CE Marking

Do harmonised standards, common specifications, or certification schemes replace the CRA risk assessment?

No. Harmonised standards, common specifications, and qualifying certification schemes can help show conformity, but they do not replace the manufacturer's cybersecurity risk assessment. The manufacturer still has to identify the relevant risks and essential requirements, check which parts are actually covered, and document any gaps or alternative solutions.

First assess the risks. Then determine whether a harmonised standard, common specification, or certification scheme covers them fully or only in part, and explain in the technical documentation how the remaining requirements are met. If none of those tools is used for a relevant requirement, the evidence file needs a clear technical explanation.

Citations
Cyber Resilience Act

Article 27 addresses presumption of conformity; Annex VII requires listing applied standards, common specifications, certification schemes, and alternative solutions.

European Commission CRA FAQs

Section 4.1.7 explains that harmonised standards do not replace legally binding essential requirements or the manufacturer's risk assessment.

CRA CE Marking

Can a manufacturer use non-CE-marked components and still CE mark the final product?

Yes, the CRA does not require manufacturers to integrate only CE-marked components. The final product manufacturer must exercise due diligence so third-party components, including free and open-source software components, do not compromise the cybersecurity of the product.

A CE-marked component can support the evidence file through its declaration and accompanying documentation, but it does not automatically make the finished product compliant. Component evidence should be tied back to the final product's risk assessment, vulnerability handling, and essential-requirement coverage.

Citations
Cyber Resilience Act

Article 13(5) and recitals 34 and 35 require component due diligence and mention checking CE marking as one possible action.

Blue Guide 2022

Section 2.1 explains the general product-law point that CE-marked components do not automatically make the finished product compliant.

Page 3 of 58