Skip to main content
๐ŸŽค Speaking at KubeCon EU 2026 Lessons Learned Orchestrating Multi-Tenant GPUs on OpenShift AI View Session
๐ŸŽค Speaking at Red Hat Summit 2026 GPUs take flight: Safety-first multi-tenant Platform Engineering with NVIDIA and OpenShift AI Learn More
CE Marking for Software: How to Achieve CRA Conformity
DevOps

CE Marking for Software: How to Achieve CRA Conformity

The CRA requires CE marking on software products. How to perform conformity assessment, prepare technical documentation, and achieve CE compliance.

LB
Luca Berton
ยท 1 min read

CE Marking: Your Market Access Ticket

CE marking has traditionally been for physical products โ€” machinery, electronics, toys. The CRA extends it to software. Without CE marking, your software product cannot legally be sold in the EU after December 2027.

What CE Marking Requires

1. Conformity Assessment

Depending on your product classification:

ClassificationAssessment Type
DefaultSelf-assessment (Module A)
Important Class ISelf-assessment with harmonized standards, or third-party (Module B+C)
Important Class IIThird-party assessment preferred (Module B+C or Module H)
CriticalMandatory third-party (EU-type examination)

2. Technical Documentation

You must maintain:

  • Product description and intended use
  • Design and manufacturing documentation
  • Security risk assessment (threat model)
  • List of harmonized standards applied
  • Test reports and results
  • SBOM
  • Vulnerability handling procedures
  • Security update policy

3. EU Declaration of Conformity

EU DECLARATION OF CONFORMITY

Product: [Product Name] v[Version]
Manufacturer: [Company Name]
Address: [Registered Address]

This declaration of conformity is issued under the sole responsibility
of the manufacturer.

The product described above is in conformity with the relevant Union
harmonisation legislation:
- Regulation (EU) 2024/2847 (Cyber Resilience Act)

Standards applied:
- EN 304 [XXX] (as applicable)

Signed:
[Name, Function]
[Date]

4. CE Mark Application

Once conformity is established:

  • Apply CE marking to product documentation/packaging
  • CE mark must be visible, legible, and permanent
  • For software: displayed in the โ€œAboutโ€ section, website, and documentation

The Self-Assessment Path (Default Products)

Most software products qualify for self-assessment:

Step 1: Identify applicable essential requirements
Step 2: Apply harmonized standards (when available)
Step 3: Conduct internal testing against requirements
Step 4: Prepare technical documentation
Step 5: Draft EU Declaration of Conformity
Step 6: Apply CE marking
Step 7: Maintain ongoing compliance (updates, monitoring)

Common Mistakes

  1. Treating CE marking as a one-time event โ€” it requires ongoing compliance
  2. Incomplete SBOM โ€” missing transitive dependencies
  3. No vulnerability handling process โ€” mandatory even for default products
  4. Missing security update commitment โ€” you must specify the support period
  5. Forgetting the Declaration of Conformity โ€” a legal document, not just a checkbox

Need help with CRA conformity assessment and CE marking? I help organizations navigate the compliance process. Get in touch.

Luca Berton Ansible Pilot Ansible by Example Open Empower K8s Recipes Terraform Pilot CopyPasteLearn ProteinLens TechMeOut