CRA Articles 29-30From 11 December 2027

CE marking under the Cyber Resilience Act

From 11 December 2027, the CE mark on a product with digital elements also declares conformity with the CRA cybersecurity requirements. Here is what the mark stands for, how to affix it, and what has to be in place first.

What the CE mark declares under the CRA

By affixing the CE marking, the manufacturer takes sole responsibility for the product meeting Regulation (EU) 2024/2847 and all other applicable Union legislation. For a product with digital elements, that means the Annex I Part I essential cybersecurity requirements are met and the Annex I Part II vulnerability handling process is in place.

The mark is the visible outcome of a conformity assessment. It is affixed only after the risk assessment, the technical file, and the EU Declaration of Conformity are done.

How to affix the CE marking

Art. 30(2)Affix the CE marking visibly, legibly and indelibly to the product.
Art. 30(3)-(4)Where the product does not allow it, affix the CE marking to the packaging and the accompanying documents, including the EU Declaration of Conformity.
Art. 30(5)Affix the CE marking before the product is placed on the market.
Art. 29Follow the general principles of the CE marking set out in Regulation (EC) No 765/2008.
Art. 30(6)On a third-party route, follow the CE marking with the four-digit identification number of the notified body involved in the production-control phase.

When a notified body number follows the mark

Most products use internal control (Module A), where the manufacturer self-assesses and the CE marking carries no notified body number. A third-party route, EU-type examination (Module B and C) or full quality assurance (Module H), applies to important products in Class II, critical products under Annex IV, and Class I products where the manufacturer does not fully apply the relevant harmonised standards. On those routes the CE marking is followed by the notified body's four-digit number.

See the CRA notified bodies directory

Six steps before you can affix the mark

Step 1

Classify the product

Work out whether the product is default, important Class I or II, or critical. The class decides the conformity assessment route.

Step 2

Run the risk assessment

Carry out and document the cybersecurity risk assessment that drives which Annex I requirements apply.

Step 3

Meet the Annex I requirements

Design and build the product to the Annex I Part I essential requirements and run the Part II vulnerability handling process.

Step 4

Compile the technical file

Assemble the Annex VII technical documentation that evidences conformity.

Step 5

Draw up the Declaration of Conformity

Complete the Annex V EU Declaration of Conformity stating the product meets Regulation (EU) 2024/2847.

Step 6

Affix the CE marking

Affix the CE marking under Article 30, adding a notified body number where a third-party route applies.

Market surveillance and penalties

National market surveillance authorities can require a non-compliant product to be brought into conformity, withdrawn, or recalled. Breaching the essential requirements or the manufacturer obligations can draw administrative fines of up to 15 million euro or 2.5 percent of worldwide annual turnover, whichever is higher.

CE marking questions

Does software need a CE mark under the CRA?

Yes. The CRA covers products with digital elements, which includes standalone software. Where the software cannot carry a physical mark, the CE marking goes on the packaging and the accompanying documents, including the EU Declaration of Conformity.

When does CE marking under the CRA start?

The main obligations, including CE marking against the CRA essential requirements, apply from 11 December 2027. The reporting obligations under Article 14 apply earlier, from 11 September 2026.

Do I need a notified body number next to the CE mark?

Only on a third-party conformity route. Then the CE marking is followed by the four-digit identification number of the notified body involved in the production-control phase. On the internal control route (Module A) there is no notified body and no number.

What happens if I affix the CE mark without meeting the requirements?

It is a non-compliance that market surveillance authorities can act on. The CRA sets administrative fines of up to 15 million euro or 2.5 percent of worldwide annual turnover for breaches of the essential requirements.

Get to the CE mark, step by step

Work through classification, risk assessment, Annex I, and the technical file in one workspace, then export the Declaration of Conformity.

Explore the CRA workspace