Conformity · by 11 Dec 2027

CRA conformity & CE marking, without the last-minute scramble

By 11 December 2027 the CRA’s full regime applies, and a product with digital elements can’t be placed on the EU market without a CE mark backing it. Conformity is where everything else comes together: a technical file, a Declaration of Conformity, and the mark. Done in the right order, it’s mostly the assembly of evidence you’ve already been collecting.

Updated 7 Jul 2026·~10 min read·For compliance & GRC leads

The reporting obligation gets the attention because it lands first. But the CRA's centre of gravity is December 2027, when you can no longer sell a product with digital elements in the EU unless it carries a CE mark — and the CE mark means you've done, documented, and declared everything the regulation asks. Conformity is that act of pulling it together.

What conformity means under the CRA

The CRA follows the EU's standard New Legislative Framework pattern, the same one behind the CE mark on a toy or a power tool. You demonstrate that the product meets the essential requirements (Annex I), you compile a technical file that shows it, you sign a Declaration of Conformity, and you affix the CE marking. The mark is not a badge you apply because you feel ready — it's a legal statement that the paperwork behind it exists and holds up.

How much scrutiny that involves depends entirely on how the product is classified. So classification is the first move.

Classification decides the route

The CRA sorts products into three tiers, and the tier determines whether you can assess yourself or must involve a third party.

ClassExamplesConformity route (in outline)
DefaultThe large majority of productsSelf-assessment — Module A (internal control)
Important, Class I (Annex III)Password managers, VPNs, network management, and similarSelf-assess if harmonised standards / schemes are applied; otherwise a third-party route
Important, Class II (Annex III)Higher-risk items in Annex III, e.g. firewalls, tamper-resistant microprocessorsThird-party route — EU-type examination or full quality assurance
Critical (Annex IV)The highest-risk categories, e.g. hardware security modules, smart-meter gatewaysThird-party, and potentially mandatory European cybersecurity certification

The practical takeaway: most products self-assess, which is good news — but if yours lands in important or critical, the route is longer and involves people outside your company, so classify early and don't discover a notified-body requirement in late 2027.

The assessment modules, briefly

The routes above map to standard conformity-assessment "modules." You don't need them memorised, but knowing which one applies tells you how much external involvement to plan for:

  • Module A — internal production control. You assess and declare, no third party. The default path, and the one most manufacturers will use.
  • Module B + C — EU-type examination, then conformity to type. A notified body examines the design; you then attest that production matches it. A third-party route for higher-risk products.
  • Module H — full quality assurance. A notified body assesses your quality system across design and production. An alternative third-party route.
  • European cybersecurity certification. For critical products, conformity may hinge on certification under an EU scheme at a defined assurance level.

The technical file: what it must contain

The technical documentation is the heart of conformity — the evidence that the product meets the essential requirements. Whatever the route, it has to exist, and it has to be kept for at least ten years after the product is placed on the market (or the support period, if that's longer). At minimum it includes:

  • A general description of the product and its intended use.
  • Design, development and production information.
  • The assessment against the Annex I essential requirements.
  • A cybersecurity risk assessment.
  • The software bill of materials — see SBOM for the CRA.
  • Information on the support period and the vulnerability-handling process.
  • The standards applied, and any test reports.
The key insight

Most of the technical file is evidence you already produce. The SBOM, the vulnerability determinations, the VEX records, the triage rationale, the reports you filed — these are exactly the artifacts the file is built from. If they live in an immutable, retained evidence trail, the technical file assembles from them rather than being re-authored from scratch in the weeks before a deadline.

The Declaration of Conformity

The EU Declaration of Conformity is short, singular, and consequential. In it, the manufacturer declares — on its own responsibility — that the product meets the applicable CRA requirements. It identifies the product and the manufacturer, references the CRA and any standards or certifications applied, and is signed on the manufacturer's behalf. Drawing it up and holding it is a precondition for the CE mark; there is no CE marking without a DoC standing behind it.

CE marking

The CE mark is the visible end of the process. Once the technical file is complete, the applicable conformity assessment is done, and the Declaration of Conformity is signed, you affix the CE marking to the product — visibly and legibly, or to its packaging or documentation where the product itself doesn't allow it. From December 2027, a product with digital elements in scope of the CRA cannot be made available on the EU market without it. The mark asserts conformity with all the EU legislation that applies, the CRA included.

Harmonised standards & presumption of conformity

Meeting the essential requirements is easier when there's an agreed way to demonstrate it. That's what harmonised standards do: conform to one published in the Official Journal, and you get a presumption of conformity with the requirement it covers. It's the difference between arguing your approach is adequate and pointing to a standard that says it is.

As of mid-2026, no CRA harmonised standard has been published. Build on open standards so your evidence adapts to whatever lands.

Until the harmonised standards arrive, anchoring your SBOMs, VEX and advisories to established open formats — CycloneDX, SPDX, OpenVEX, CSAF — keeps your technical file aligned with where the ecosystem is heading, rather than tied to one interpretation a later standard might contradict.

From evidence to conformity

The mistake to avoid is treating December 2027 as a separate, standalone project that starts in 2027. It isn't. The reporting obligation you met in 2026, and the vulnerability handling you ran throughout, generate almost everything the technical file needs. Run the programme as one continuous thread and conformity becomes an assembly step; run the obligations as disconnected fire drills and it becomes a scramble against a hard deadline.

That's the throughline of the whole CRA: SBOMcorrelationevidence-backed determinationsreporting → a retained evidence trail that is the raw material for the technical file. Conformity isn't a new pile of work; it's the last shape the evidence takes. The CRA guide puts the full sequence in order.

Frequently asked

Do I need a notified body for CE marking under the CRA?

For most products, no. Default-class products self-assess under Module A, without a notified body. Important and critical products face stricter routes: important Class I can self-assess if it applies the relevant harmonised standards, while important Class II and critical products generally require a third-party route such as EU-type examination or, for critical, European cybersecurity certification.

What goes in the CRA technical documentation?

A general product description, design and development information, the assessment against the Annex I essential requirements, a risk assessment, the SBOM, information on the support period and vulnerability handling, the standards applied, and test reports. It is kept for at least ten years after the product is placed on the market, or the support period if longer.

What is an EU Declaration of Conformity?

The single document in which the manufacturer declares the product meets the applicable CRA requirements. It identifies the product and manufacturer, references the CRA and any standards applied, and is signed on the manufacturer's behalf. It is a precondition for affixing the CE marking.

Are CRA harmonised standards available yet?

As of mid-2026, none has been published in the Official Journal. Once they are, conforming to them gives a presumption of conformity with the corresponding essential requirements. Until then, building on established open standards keeps your evidence adaptable.

Design partners

Build the technical file as you go — not in the last quarter of 2027.

See how the evidence you collect for reporting and vulnerability handling becomes the technical documentation the CE mark needs. Ask us for the CRA technical-file checklist.