Module 7 of 8 · 40 min
Conformity assessment, technical documentation, and CE marking
The Annex VIII modules, which routes each product tier may use, presumption of conformity, Annex VII technical documentation, the EU Declaration of Conformity, and CE marking rules.
Learning objectives
- Match each product tier to its permitted conformity assessment routes
- Describe Modules A, B plus C, and H from Annex VIII
- Explain presumption of conformity through harmonised standards, common specifications, and EUCC certificates
- List the Annex VII technical documentation and Annex V Declaration of Conformity content
- Apply the Article 30 CE marking rules, including where the mark goes and the notified body number
The routes
Annex VIII provides the procedures: Module A, internal control, where the manufacturer alone verifies conformity, compiles the documentation and declares conformity; Module B, EU-type examination by a notified body, followed by Module C, conformity to type based on internal production control; and Module H, conformity based on full quality assurance, where a notified body approves and surveils the manufacturer's quality system. Default products may use Module A. Important Class I products may only self-assess under Module A if they fully apply relevant harmonised standards, common specifications or European cybersecurity certification schemes; otherwise they need B plus C or H. Class II products always involve a notified body. Critical products can additionally be required to obtain a European cybersecurity certificate.
Route questions resolve on two facts: the product's tier, and whether harmonised standards were applied in full. Fix both before choosing.
Presumption of conformity
Products in conformity with harmonised standards, or parts of them, whose references are published in the Official Journal are presumed to conform with the essential requirements those standards cover. The same presumption attaches to common specifications the Commission adopts where standards are missing, and to EU statements of conformity or certificates issued under a European cybersecurity certification scheme such as EUCC, to the extent they cover the requirements. Presumption narrows what an assessment must prove; it never removes the obligations themselves. ENISA's recorded EUCC-CRA interplay webinars walk through how Common Criteria certification maps onto CRA requirements.
Technical documentation and the Declaration of Conformity
Annex VII documentation must contain at least: a general description of the product including its intended purpose; software versions affecting compliance; design, development and production documentation including the vulnerability-handling processes; the cybersecurity risk assessment; the support period; a list of the harmonised standards or other specifications applied; test reports from verifying conformity; and a copy of the EU Declaration of Conformity — with the SBOM available on a reasoned request from an authority. The Declaration of Conformity follows Annex V, states that fulfilment of the essential requirements has been demonstrated, identifies the product, the manufacturer, the assessment procedure and any notified body, and must be kept up to date. By drawing it up, the manufacturer assumes responsibility for compliance.
CE marking
The CE marking is affixed visibly, legibly and indelibly to the product; where that is not possible or not warranted by the product's nature, it goes on the packaging and on the EU Declaration of Conformity, and for software either on the Declaration of Conformity or on an easily accessible website. Where a notified body is involved under Module H, its identification number follows the CE marking, affixed by the notified body itself or under its instructions by the manufacturer. The mark is the only marking that attests conformity with the CRA's requirements, and misleading markings are prohibited. Member States build on existing CE enforcement mechanisms to act against misuse.
Official sources for this module
- Regulation (EU) 2024/2847 — full official text (EUR-Lex)Official text
- The Cyber Resilience Act — summary of the legislative text (European Commission)Official text
- ENISA webinar — EUCC and CRA interplay (morning session, recorded)Recorded session
- ENISA webinar — EUCC and CRA interplay (afternoon session, recorded)Recorded session
Module 7 quiz
10 questions, pass mark 70%, 3 attempts. Starting an attempt consumes it.
Enroll and confirm your email to take the quiz.