Skip to main content
🎓 Claude Code Masterclass Learn AI-assisted development on Udemy — plus the companion book on Leanpub & Amazon. Start Learning
CE Marking for Software: How to Achieve CRA Conformity
DevOps

CE Marking for Software: How to Achieve CRA Conformity

The CRA requires CE marking on software products. How to perform conformity assessment, prepare technical documentation, and achieve CE compliance.

LB
Luca Berton
· 1 min read

CE Marking: Your Market Access Ticket

CE marking has traditionally been for physical products — machinery, electronics, toys. The CRA extends it to software. Without CE marking, your software product cannot legally be sold in the EU after December 2027.

What CE Marking Requires

1. Conformity Assessment

Depending on your product classification:

ClassificationAssessment Type
DefaultSelf-assessment (Module A)
Important Class ISelf-assessment with harmonized standards, or third-party (Module B+C)
Important Class IIThird-party assessment preferred (Module B+C or Module H)
CriticalMandatory third-party (EU-type examination)

2. Technical Documentation

You must maintain:

  • Product description and intended use
  • Design and manufacturing documentation
  • Security risk assessment (threat model)
  • List of harmonized standards applied
  • Test reports and results
  • SBOM
  • Vulnerability handling procedures
  • Security update policy

3. EU Declaration of Conformity

EU DECLARATION OF CONFORMITY

Product: [Product Name] v[Version]
Manufacturer: [Company Name]
Address: [Registered Address]

This declaration of conformity is issued under the sole responsibility
of the manufacturer.

The product described above is in conformity with the relevant Union
harmonisation legislation:
- Regulation (EU) 2024/2847 (Cyber Resilience Act)

Standards applied:
- EN 304 [XXX] (as applicable)

Signed:
[Name, Function]
[Date]

4. CE Mark Application

Once conformity is established:

  • Apply CE marking to product documentation/packaging
  • CE mark must be visible, legible, and permanent
  • For software: displayed in the “About” section, website, and documentation

The Self-Assessment Path (Default Products)

Most software products qualify for self-assessment:

Step 1: Identify applicable essential requirements
Step 2: Apply harmonized standards (when available)
Step 3: Conduct internal testing against requirements
Step 4: Prepare technical documentation
Step 5: Draft EU Declaration of Conformity
Step 6: Apply CE marking
Step 7: Maintain ongoing compliance (updates, monitoring)

Common Mistakes

  1. Treating CE marking as a one-time event — it requires ongoing compliance
  2. Incomplete SBOM — missing transitive dependencies
  3. No vulnerability handling process — mandatory even for default products
  4. Missing security update commitment — you must specify the support period
  5. Forgetting the Declaration of Conformity — a legal document, not just a checkbox

Need help with CRA conformity assessment and CE marking? I help organizations navigate the compliance process. Get in touch.

#cra #ce-marking #conformity #compliance #eu-regulation
Share:
Automation Strategy Consulting

Need help with Automation Strategy Consulting?

Streamline workflows and build automation strategies that scale.

Learn more about Automation Strategy Consulting

Want to operate this yourself, in production?

Take the free AI Platform Engineer Readiness Scorecard to see which skills transfer — then build a production-shaped AI platform in the 4-week Bootcamp.

Take the Scorecard →
Luca Berton — AI & Cloud Advisor, Docker Captain

Luca Berton

AI & Cloud Advisor · Docker Captain · KubeCon Speaker

15+ years in enterprise infrastructure. Author of 8 technical books, creator of Ansible Pilot (1M+ YouTube views, 648K site users). Former Red Hat engineer. Speaker at KubeCon EU 2026 and Red Hat Summit 2026.

Free 30-min AI & Cloud consultation

Book Now