Conformity assessment and CE marking
Conformity assessment requires manufacturers to demonstrate that their products with digital elements meet all essential cybersecurity requirements defined in the CRA. Once compliance is verified and documented, the manufacturer must affix a CE mark to the product as visible proof that it can be legally placed on the EU market.
What it means
The intent of this requirement is to ensure that security is not an afterthought but is baked into the product lifecycle before it reaches the consumer. It creates a legal obligation for manufacturers to prove—rather than simply claim—that their products are secure by design and default.
In practice, the scope depends on the risk classification of the product. While "default" (lower-risk) products may be eligible for self-assessment, higher-risk categories (Critical Class I and II) require more stringent oversight, often involving third-party audits conducted by a notified body.
Regardless of the class, this process results in a technical file that maps every essential requirement to a specific implementation or justification within the product. The CE mark serves as the final regulatory signal that these steps have been completed successfully.
How to meet it
- Determine your product's risk classification (Default, Critical Class I, or Critical Class II) based on the criteria provided in the regulation.
- Conduct a gap analysis between your current security controls and the CRA’s essential cybersecurity requirements.
- Execute the required conformity assessment procedure: either a self-assessment for default products or an audit by a notified body for critical classes.
- Compile a comprehensive Technical Documentation file containing design specifications, risk assessments, and evidence of testing.
- Author an EU Declaration of Conformity, formally stating that the product meets all applicable requirements of the Act.
- Affix the CE mark to the physical product or, in the case of software-only products, within the digital interface or accompanying documentation.
Evidence an auditor asks for
- The Technical Documentation file, including architecture diagrams and a detailed Software Bill of Materials (SBOM).
- A signed EU Declaration of Conformity.
- Certification reports issued by a notified body (for Critical Class I and II products).
- Validation records proving the essential requirements were tested, such as penetration test results or vulnerability scan logs.
Common pitfalls
- Misclassifying a "Critical" product as "Default" to avoid third-party assessment costs, which leads to immediate non-compliance upon audit.
- Treating CE marking as a one-time certification rather than updating the technical file and assessment for every significant software version or hardware revision.
- Failing to maintain an accurate SBOM within the technical documentation, making it impossible to prove how vulnerabilities in third-party components are managed.