CE Marking: Your Market Access Ticket
CE marking has traditionally been for physical products โ machinery, electronics, toys. The CRA extends it to software. Without CE marking, your software product cannot legally be sold in the EU after December 2027.
What CE Marking Requires
1. Conformity Assessment
Depending on your product classification:
| Classification | Assessment Type |
|---|---|
| Default | Self-assessment (Module A) |
| Important Class I | Self-assessment with harmonized standards, or third-party (Module B+C) |
| Important Class II | Third-party assessment preferred (Module B+C or Module H) |
| Critical | Mandatory third-party (EU-type examination) |
2. Technical Documentation
You must maintain:
- Product description and intended use
- Design and manufacturing documentation
- Security risk assessment (threat model)
- List of harmonized standards applied
- Test reports and results
- SBOM
- Vulnerability handling procedures
- Security update policy
3. EU Declaration of Conformity
EU DECLARATION OF CONFORMITY
Product: [Product Name] v[Version]
Manufacturer: [Company Name]
Address: [Registered Address]
This declaration of conformity is issued under the sole responsibility
of the manufacturer.
The product described above is in conformity with the relevant Union
harmonisation legislation:
- Regulation (EU) 2024/2847 (Cyber Resilience Act)
Standards applied:
- EN 304 [XXX] (as applicable)
Signed:
[Name, Function]
[Date]4. CE Mark Application
Once conformity is established:
- Apply CE marking to product documentation/packaging
- CE mark must be visible, legible, and permanent
- For software: displayed in the โAboutโ section, website, and documentation
The Self-Assessment Path (Default Products)
Most software products qualify for self-assessment:
Step 1: Identify applicable essential requirements
Step 2: Apply harmonized standards (when available)
Step 3: Conduct internal testing against requirements
Step 4: Prepare technical documentation
Step 5: Draft EU Declaration of Conformity
Step 6: Apply CE marking
Step 7: Maintain ongoing compliance (updates, monitoring)Common Mistakes
- Treating CE marking as a one-time event โ it requires ongoing compliance
- Incomplete SBOM โ missing transitive dependencies
- No vulnerability handling process โ mandatory even for default products
- Missing security update commitment โ you must specify the support period
- Forgetting the Declaration of Conformity โ a legal document, not just a checkbox
Need help with CRA conformity assessment and CE marking? I help organizations navigate the compliance process. Get in touch.
