CE marking under the Cyber Resilience Act
From 11 December 2027, the CE mark on a product with digital elements also declares conformity with the CRA cybersecurity requirements. Here is what the mark stands for, how to affix it, and what has to be in place first.
What the CE mark declares under the CRA
By affixing the CE marking, the manufacturer takes sole responsibility for the product meeting Regulation (EU) 2024/2847 and all other applicable Union legislation. For a product with digital elements, that means the Annex I Part I essential cybersecurity requirements are met and the Annex I Part II vulnerability handling process is in place.
The mark is the visible outcome of a conformity assessment. It is affixed only after the risk assessment, the technical file, and the EU Declaration of Conformity are done.
How to affix the CE marking
When a notified body number follows the mark
Most products use internal control (Module A), where the manufacturer self-assesses and the CE marking carries no notified body number. A third-party route, EU-type examination (Module B and C) or full quality assurance (Module H), applies to important products in Class II, critical products under Annex IV, and Class I products where the manufacturer does not fully apply the relevant harmonised standards. On those routes the CE marking is followed by the notified body's four-digit number.
See the CRA notified bodies directorySix steps before you can affix the mark
Classify the product
Work out whether the product is default, important Class I or II, or critical. The class decides the conformity assessment route.
Run the risk assessment
Carry out and document the cybersecurity risk assessment that drives which Annex I requirements apply.
Meet the Annex I requirements
Design and build the product to the Annex I Part I essential requirements and run the Part II vulnerability handling process.
Compile the technical file
Assemble the Annex VII technical documentation that evidences conformity.
Draw up the Declaration of Conformity
Complete the Annex V EU Declaration of Conformity stating the product meets Regulation (EU) 2024/2847.
Affix the CE marking
Affix the CE marking under Article 30, adding a notified body number where a third-party route applies.
Market surveillance and penalties
National market surveillance authorities can require a non-compliant product to be brought into conformity, withdrawn, or recalled. Breaching the essential requirements or the manufacturer obligations can draw administrative fines of up to 15 million euro or 2.5 percent of worldwide annual turnover, whichever is higher.
CE marking questions
Does software need a CE mark under the CRA?
Yes. The CRA covers products with digital elements, which includes standalone software. Where the software cannot carry a physical mark, the CE marking goes on the packaging and the accompanying documents, including the EU Declaration of Conformity.
When does CE marking under the CRA start?
The main obligations, including CE marking against the CRA essential requirements, apply from 11 December 2027. The reporting obligations under Article 14 apply earlier, from 11 September 2026.
Do I need a notified body number next to the CE mark?
Only on a third-party conformity route. Then the CE marking is followed by the four-digit identification number of the notified body involved in the production-control phase. On the internal control route (Module A) there is no notified body and no number.
What happens if I affix the CE mark without meeting the requirements?
It is a non-compliance that market surveillance authorities can act on. The CRA sets administrative fines of up to 15 million euro or 2.5 percent of worldwide annual turnover for breaches of the essential requirements.
Get to the CE mark, step by step
Work through classification, risk assessment, Annex I, and the technical file in one workspace, then export the Declaration of Conformity.
Explore the CRA workspace