Under the Cyber Resilience Act (CRA), the EU declaration of conformity and CE marking are release outputs, not substitutes for the conformity work that comes before them. Once the applicable conformity assessment has demonstrated that the product with digital elements and the manufacturer's relevant processes meet the applicable Annex I requirements, Article 13(12) requires the manufacturer to draw up the EU declaration of conformity under Article 28 and affix the CE marking under Article 30.
For release teams, the practical objective is to make that final step reproducible. The declaration should identify the exact product being released, reflect the assessment route and technical basis actually used, and stay linked to the technical-documentation baseline that supports it. The CE marking then needs to be applied in the form and location required for the product, including the CRA's specific rule for software.
The CRA's main manufacturer obligations apply from 11 December 2027. Preparing the release package before that date helps teams treat conformity evidence, declaration approval and CE-marking checks as controlled release gates rather than end-of-project paperwork.
Follow the sequence: evidence, assessment, declaration, CE marking
The CRA creates a clear order of operations:
- build and maintain the technical documentation required by Article 31 and Annex VII;
- perform the applicable conformity assessment procedure under Article 32 and Annex VIII;
- when conformity with the applicable Annex I requirements has been demonstrated, draw up the EU declaration of conformity under Article 28; and
- affix the CE marking under Articles 29 and 30 before the product is placed on the market.
A signed declaration should represent the outcome of a completed conformity process for a defined product state. It should not be drafted first and then supported retrospectively by whatever evidence can be found.
The conformity-assessment route depends on the product's CRA classification and the conditions in Article 32. The Commission's current guidance notes that many products can use manufacturer self-assessment, while certain important and critical products can require a notified-body or other eligible third-party route. The release package should identify the route actually used rather than assuming every product follows the same path.
What the EU declaration of conformity does
Article 28 requires the EU declaration of conformity to state that fulfilment of the applicable essential cybersecurity requirements in Annex I has been demonstrated. By drawing up the declaration, the manufacturer assumes responsibility for the product's compliance.
The declaration therefore belongs to a specific product identity and should remain consistent with the conformity assessment and technical documentation supporting that product. Article 28 also requires it to follow the model structure in Annex V, contain the elements required by the relevant Annex VIII procedure, be updated as appropriate, and be made available in the languages required by the Member State where the product is placed or made available on the market.
If a product is subject to more than one Union legal act requiring an EU declaration of conformity, Article 28 permits a single EU declaration of conformity covering all of those acts. The document must identify the relevant Union legislation and publication references. A manufacturer that already maintains one controlled declaration for other applicable EU harmonisation legislation should therefore assess whether the CRA needs to be added to that declaration rather than creating a parallel document that can drift out of sync.
Annex V: build the declaration from traceable product facts
Annex V defines the minimum information for the CRA EU declaration of conformity. In practical terms, the declaration needs to capture:
- the product name and type, plus information that uniquely identifies it;
- the manufacturer's name and address and, where applicable, the authorised representative;
- a statement that the declaration is issued under the responsible party's sole responsibility;
- the object of the declaration, identified in a way that allows traceability;
- a statement that the declared product conforms with the relevant Union harmonisation legislation;
- references to relevant harmonised standards, common specifications or cybersecurity certification used as a basis for the conformity claim;
- where applicable, the notified body's name and number, the conformity-assessment procedure performed and the certificate issued; and
- signing information, including place and date, the signatory's name and function, and signature.
The key release-control question is whether those fields refer to the same product baseline. The product identifier in the declaration should map to the same variant, software or firmware release, technical-documentation revision, assessment evidence and certificate scope used for the release decision.
Useful identifiers can include the commercial product name, model or type, hardware revision, software or firmware version, configuration identifier and release reference. The CRA does not prescribe one universal software-version field for every declaration; the objective is to make the object of the declaration identifiable and traceable.
Keep standards and notified-body references current
Annex V requires the declaration to identify the relevant Union harmonisation legislation and, where applicable, the harmonised standards, common specifications or cybersecurity certification used. These references should be controlled data rather than copied indefinitely from an old template.
Before approval, verify which EU acts apply, which standards or specifications were actually used, whether their legal status still supports the conformity argument, and whether any notified-body certificate still covers the released product state. A standard can be technically useful without creating a CRA presumption of conformity, so the conformity record should distinguish technical use from formal status.
Where a notified body is involved, Annex V requires the declaration to identify the body, procedure and certificate as applicable. Article 30(4) also contains a specific marking rule: the CE marking is followed by the notified body's identification number where that body is involved in the full quality-assurance procedure based on Module H. Do not append a notified-body number automatically merely because some third-party assessment occurred.
Full declaration versus simplified declaration
Article 13(20) requires a copy of the EU declaration of conformity, or a simplified EU declaration of conformity, to accompany the product with digital elements.
Annex VI provides the simplified model. It identifies the manufacturer and product type, states conformity with Regulation (EU) 2024/2847, and gives the internet address where the full EU declaration of conformity is available.
The simplified version is therefore a distribution mechanism, not a replacement for maintaining the full declaration and its supporting conformity evidence. If it is used, verify that the referenced URL points to the correct full declaration, corresponds to the correct product scope and remains under controlled ownership. The simplified declaration is also subject to the Article 28 language requirement.
CE marking is the manufacturer's conformity statement
Article 29 applies the general CE-marking principles from Article 30 of Regulation (EC) No 765/2008. Under those principles, the CE marking is affixed only by the manufacturer or its authorised representative. By affixing it, the manufacturer indicates responsibility for the product's conformity with the applicable requirements of the relevant Union harmonisation legislation.
A notified body may participate in the required conformity-assessment route for certain products, but the CE marking is not a separate cybersecurity certificate issued by that body. The release checklist should therefore require an authorised internal decision that the conformity evidence is complete and the declaration is approved before the marking is released with the product.
Where the CRA requires the CE marking
Article 30 sets CRA-specific placement rules.
For a physical product with digital elements, the marking must normally be visible, legible and indelible on the product. If that is not possible or not warranted because of the product's nature, it must be placed on the packaging and on the EU declaration of conformity accompanying the product.
For a product with digital elements in the form of software, the CE marking can be placed either on the EU declaration of conformity or on the website accompanying the software product, provided the relevant website section is easily and directly accessible to consumers.
The marking must be affixed before the product is placed on the market. Article 30 also permits the CE mark to be smaller than 5 mm where the nature of the product warrants that, provided it remains visible and legible.
For software delivery, treat the website option as a controlled release surface. Record the page used, verify that the mark remains directly accessible and assign ownership so a redesign cannot silently remove it.
Build one controlled release package
A practical CRA release package should connect the declaration and CE-marking decision to the evidence that justifies them. A useful package can include:
- product and release identity;
- CRA classification and conformity-assessment route;
- cybersecurity risk-assessment baseline and Annex I mapping;
- technical-documentation revision;
- relevant test and verification evidence;
- standards, specifications or certification relied on;
- notified-body records and certificates where applicable;
- approved EU declaration of conformity;
- simplified declaration and full-declaration URL where used;
- CE-marking location and representation check;
- required user information;
- release approval and signatory record; and
- controlled references to the exact evidence used for the decision.
The purpose is not to duplicate every technical artifact. The package should act as an index showing which evidence supported this release and where the controlled records live.
Add declaration and CE checks to release governance
The declaration can become stale when product changes are treated as purely engineering changes. Add explicit release questions:
- Has the product, variant, software or firmware baseline changed in a way that affects the declared scope?
- Has the cybersecurity risk assessment or conformity-assessment route changed?
- Are the standards or specifications referenced by the declaration still the ones actually applied?
- Does any notified-body certificate still cover the current product state?
- Does the declaration need to be updated under Article 28?
- Does the CE-marking location still satisfy Article 30 for this delivery form?
- If a simplified declaration is supplied, does its full-declaration URL still resolve to the correct document?
Not every release requires a new conformity conclusion, but every release process should be able to determine whether the existing package remains valid and preserve that determination.
Retain the declaration with the technical documentation
Article 13(13) requires manufacturers to keep the technical documentation and EU declaration of conformity available to market-surveillance authorities for at least 10 years after the product is placed on the market or for the support period, whichever is longer.
Retention therefore needs more than storing only the latest declaration. Preserve the declaration that applied to the relevant product state together with enough context to retrieve the corresponding technical documentation later. Useful controls include stable release identifiers, approval and signature history, declaration revision history, the technical-documentation baseline, notified-body records where applicable, and evidence of the CE-marking form and location used for the release.
Do not silently overwrite a signed declaration when the product or a relevant reference changes. Preserve the historical record and issue the updated declaration through the controlled process.
Common failures to prevent
Several failure modes are predictable:
- Wrong product scope. A generic family name can hide differences between variants or releases. Resolve the mapping before approval.
- Declaration and technical documentation drift. Manage references to standards, certificates and product versions through one release change process.
- CE marking treated as artwork. Placement and timing are release requirements, so product, packaging, documentation and website teams need controlled inputs.
- Notified-body number applied too broadly. Match the marking configuration to the actual assessment procedure.
- Simplified declaration points to an unstable URL. Treat the public location of the full declaration as part of the controlled release package.
- Only the newest declaration is retained. Market-surveillance questions can concern an earlier product state.
Austria: include these steps in the market-placement checklist
The Austrian Federal Chancellery's CRA FAQ presents the placing-on-the-market sequence in the same operational order: prepare Article 31 technical documentation, perform the Article 32 conformity assessment, issue the EU declaration of conformity under Articles 13(12) and 28, affix the CE marking under Articles 29 and 30, and provide the required product information.
For Austrian manufacturers, that makes declaration and marking natural release-control items. The checklist should still verify any other Union legislation applicable to the product rather than treating the CRA as the only possible CE-marking regime.
Keep the release evidence connected
The declaration and CE mark are concise outputs backed by a larger evidence chain. Teams still need to preserve which requirements, risk decisions, technical documentation, assessment evidence and approvals belonged to the exact release represented by those outputs.
AA-sec is designed around traceability between requirements, security evidence, decisions and exact product or lifecycle context. That can support a release-governance workflow in which the declaration, supporting evidence and release decision stay connected to the same product state.
Key takeaway
Treat the CRA EU declaration of conformity and CE marking as the controlled completion of a product-security conformity workflow. Before market placement, confirm that the applicable assessment is complete, the declaration identifies the exact product and basis used, the CE mark is applied correctly for the product form, and the release package points to the technical evidence supporting the decision.
The strongest release process is the one that can show, years later, which product was declared, which evidence supported it, which assessment route was used, and why the CE marking was valid for that release.
Official sources
- Regulation (EU) 2024/2847 — Cyber Resilience Act — EUR-Lex
- Regulation (EC) No 765/2008 — accreditation and market surveillance requirements — EUR-Lex
- Cyber Resilience Act - Conformity assessment — European Commission
- Cyber Resilience Act - Manufacturers — European Commission
- Fragen und Antworten zur Cyberresilienz-Verordnung — Austrian Federal Chancellery
