CE marking
Also known as: Conformité Européenne, EU Marking
This is a certification mark that indicates a product complies with all applicable European Union (EU) health, safety, and environmental protection requirements. It serves as a "passport" allowing products to be legally sold within the European Economic Area (EEA). It is a mandatory regulatory requirement for specific categories of goods rather than a voluntary quality seal.
Why it matters
Absence or falsification of this mark can lead to immediate customs seizures, forced product recalls, and heavy administrative fines across EU member states. An auditor concludes that such a failure constitutes a critical breach of statutory law, creating an unmitigated legal risk for the company. These failures often cost organisations millions in lost revenue and logistics costs associated with withdrawing non-compliant stock from shelves. The Chief Operating Officer (COO) or the Head of Product Compliance is typically held accountable for these lapses.
In practice
A compliance auditor verifies this during the Technical File Review phase of an engagement. They request the EU Declaration of Conformity (DoC) and the supporting technical documentation, such as test reports for Electromagnetic Compatibility (EMC). This process ensures that a Notified Body was involved if required by specific legislation, such as the Radio Equipment Directive (2014/53/EU). The output is usually a compliance report or a gap analysis identifying missing certifications. In first-year audits, the practitioner validates the entire evidence chain from design to label; in repeat engagements, they sample only new product versions or component changes.
Worked example
SecureNet Hardware, a fictional router manufacturer, underwent a 2023 regulatory audit for its X100 model. The auditor requested the Technical File and specific safety test reports required for the EEA market. They discovered that while the physical label was on the device, the DoC had not been updated to include a mandatory 2022 safety standard amendment. This resulted in a "Major Non-Conformance" finding because the product was legally non-compliant despite having the mark. SecureNet had to halt shipments to France and Germany until October 2023 when the documentation was rectified.
Common mistakes
- Confusing this regulatory requirement with voluntary quality certifications like ISO 9001, leading to missing legal safety files.
- Applying the logo to products not covered by any EU directive, which is an illegal act of misleading marketing.
- Failing to retain the Technical File for the required ten years after the last unit was placed on the market.
- Using "China Export" logos that visually mimic the mark but lack legal validity in Europe.
Frequently asked questions
What is the difference between CE marking and UKCA?
The CE mark applies to the European Economic Area, while UKCA (UK Conformity Assessed) is the specific requirement for products sold in Great Britain following Brexit. While similar in purpose, they are governed by different legal jurisdictions and separate sets of regulations.
Is a CE mark an ISO certification?
No, it is not. An ISO certification proves that a company follows certain management processes, whereas this mark certifies that the specific physical product meets EU safety and health laws.
How do I verify if a supplier's marking is legitimate during a vendor audit?
Request the signed Declaration of Conformity (DoC) and cross-reference any listed Notified Body numbers with the NANDO database. You should also ask for the specific test reports that prove the product passed the required directives.
What documents must be present in an audit trail to support this mark?
The auditor will look for the Technical File, the EU Declaration of Conformity, and the user manual provided in the local language of the destination market. If a Notified Body was involved, the certificate issued by that body is also required.
When should compliance assessment occur in the product development lifecycle?
It must happen during the design and prototyping phase, well before mass production begins. Assessing it after the product is finished often reveals fundamental design flaws that require expensive hardware re-engineering to meet EU standards.
More terms
Control mapping · Data Protection Impact Assessment · Common controls framework · Subprocessor · Significant deficiency · Three lines of defense · SOC 2 Type II · Risk assessment