Every product with digital elements needs an EU Declaration of Conformity before it can legally carry the CE marking. The DoC is your formal statement that the product meets CRA requirements. You are legally responsible for its accuracy.
This guide provides a complete template and explains each required element.
Summary
- The EU Declaration of Conformity (DoC) is mandatory for every CRA product and must be in place before market placement.
- The manufacturer is legally responsible for the declaration. Where an authorised representative is appointed and the mandate covers it, the representative may draw up and sign the DoC on the manufacturer's behalf and under its responsibility, but responsibility for conformity stays with the manufacturer.
- The required elements are fixed in the CRA declaration template.
- It must be made available in the language(s) required by each Member State where the product is sold.
- Retain it for at least 10 years after market placement, or for the length of the support period if longer.
- A substantial modification requires a new DoC. A third party that carries out the modification and makes the product available becomes the manufacturer and issues it.
- A template is provided below. Adapt it for your product.
Important: Do not sign a DoC before conformity assessment is complete. An incomplete or inaccurate declaration can create serious fine exposure and undermine the CE marking.
Tip: Include the product support period and a vulnerability contact point in your DoC. They are practical transparency fields even when the minimum declaration template does not force them.
What is the EU Declaration of Conformity?
The EU Declaration of Conformity is a formal legal document in which the manufacturer declares that a product complies with applicable EU legislation. It is mandatory for all products with digital elements before they can bear the CE marking. For CRA products, it must state:
- The product meets the essential cybersecurity requirements.
- Conformity assessment has been completed.
- The manufacturer takes legal responsibility.
Without a signed DoC, your product cannot bear the CE marking and cannot be legally placed on the EU market.
What does the CRA require in the DoC?
The DoC must be drawn up before market placement, kept current as the product or its compliance status changes, translated into the language(s) required by each Member State where the product is sold, and retained alongside the technical file for at least ten years.
Note: When a product falls under several EU acts that each require a declaration of conformity, you must draw up a single combined declaration covering all of them, and it must identify each act including its publication reference. See the "Multiple regulations" variation later in this guide.
Required elements
| # | Element | What to include |
|---|---|---|
| 1 | Product name and type | Name, type, and any additional information enabling unique identification of the product with digital elements. |
| 2 | Manufacturer identification | Name and address of the manufacturer or its authorised representative. |
| 3 | Sole responsibility statement | A statement that the declaration is issued under the sole responsibility of the provider. Suggested wording: "This declaration of conformity is issued under the sole responsibility of the provider." The CRA text uses the term "provider". |
| 4 | Object of the declaration | Identification of the product allowing traceability, which may include a photograph where appropriate. |
| 5 | Conformity statement | A statement that the object is in conformity with the relevant Union harmonisation legislation, including Regulation (EU) 2024/2847 and any other applicable EU act. |
| 6 | Standards and certifications applied | Harmonised standards, common specifications, or cybersecurity certifications relied on. |
| 7 | Notified Body details | Name, number, conformity assessment procedure performed, certificate reference. Required only when a third-party assessment module was used. |
| 8 | Additional information + signature | Place and date of issue; signatory name, function, and signature (for example handwritten or a qualified electronic signature). Other additional information as needed. |
Each row maps to the correspondingly numbered element of the EU declaration template.
Note: A declaration number is not mandatory, but is strongly recommended for version control and internal tracking.
Complete DoC template
Use this as a starting point. Customise the bracketed fields for your product.
Note: Section 3 must state that the declaration is issued under the sole responsibility of the provider. The CRA requires a statement to that effect and uses the word "provider". The wording below satisfies it.
Document identification
| Declaration No. | [DoC-PRODUCT-YYYY-NNN] |
|---|---|
| Date of issue | [DD Month YYYY] |
Manufacturer
| Name | [Company Legal Name] |
|---|---|
| Address | [Street Address, Postal Code, City, Country] |
| Contact | [Email / Phone] |
| Website | [URL] |
Product identification
| Product name | [Product Name] |
|---|---|
| Model / type | [Model Number / Type Designation] |
| Hardware version | [Hardware Version, if applicable] |
| Software version | [Software / Firmware Version] |
| Batch / serial | [Batch range or serial number format] |
| Photograph | [Optional, where appropriate for traceability] |
| Description | [Brief description of the product and its intended purpose, sufficient to identify the product unambiguously] |
Declaration
"This declaration of conformity is issued under the sole responsibility of the provider." (This wording satisfies the sole-responsibility requirement. The CRA text uses the term "provider".)
The object of the declaration described above is in conformity with the relevant Union harmonisation legislation:
- Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act).
- [Additional applicable EU legislation, where relevant.]
Conformity assessment
Conformity assessment procedure applied (select one):
Module A. Internal Production Control.
| Notified Body | Not required for Module A |
|---|
Module B + C. EU-Type Examination + Conformity to Type.
| Notified Body | [Name], No. [XXXX] |
|---|---|
| Certificate | [Number], dated [DD Month YYYY] |
Module H. Full Quality Assurance.
| Notified Body | [Name], No. [XXXX] |
|---|---|
| QA Certificate | [Number], dated [DD Month YYYY] |
European cybersecurity certification under an EU cybersecurity certification scheme (Regulation (EU) 2019/881).
| Scheme | [Name] |
|---|---|
| Certificate | [Number] |
| Assurance level | [Substantial / High] |
Standards and specifications applied
| Harmonised standards | EN [XXXXX]:20XX, [Standard Title] |
|---|---|
| Other technical specs | ISO/IEC [XXXXX]:20XX, [Standard Title] |
| Cybersecurity certifications | [Scheme name, certificate reference, if applicable] |
Additional information (CRA-specific)
| Support period | Security updates until [DD Month YYYY] |
|---|---|
| First EU market placement | [DD Month YYYY] |
| Vulnerability contact | [security@company.com] / [https://company.com/.well-known/security.txt] |
| Technical documentation | Available upon request to competent authorities at the address above. |
Signature
Signed for and on behalf of [Company Legal Name]:
Place: [City, Country] · Date: [DD Month YYYY]
Section-by-section guidance
1. Document identification
Declaration number. Not mandatory, but strongly recommended for version control. A practical format is DoC-[ProductCode]-[Year]-[Sequence], for example DoC-SSP3000-2027-001.
Date of issue. The date you sign the declaration. Must be after conformity assessment is complete.
2. Manufacturer identification
The signatory is a person authorised to legally commit the manufacturer. The CRA does not by itself require appointing an authorised representative. Where one is appointed and its mandate specifies these tasks, the authorised representative may draw up and sign the EU Declaration of Conformity and affix the CE marking on the manufacturer's behalf and under its responsibility. The manufacturer stays legally responsible for the product's conformity. If an authorised representative acts, add a line such as:
Authorised Representative: [Name, Address]
acting on behalf of: [Manufacturer Name, Address]
3. Product identification
Be specific enough for traceability: include model numbers, separate hardware and software versions, and the batch or serial number scope.
Example:
Product Name: SmartSense Pro Industrial Sensor
Model/Type: SSP-3000
Hardware Ver: Rev C (PCB v3.2)
Software Ver: Firmware 2.4.1
Batch/Serial: Serial numbers SSP3K-2027-XXXXXX
4. Conformity assessment
Which module you must use depends on your product's classification. Use this table to orient yourself:
| Module | When it applies | Notified Body? |
|---|---|---|
| Module A (Internal Production Control) | Default products; Important Class I when the relevant standards, specifications, or scheme fully apply | No |
| Module B+C (EU-Type Examination) | Available to all products; required option for Important Class I when they do not fully apply; one route for Important Class II and Critical fallback | Yes |
| Module H (Full Quality Assurance) | All products; alternative to B+C for Important Class I and II | Yes |
| EUCC / cybersecurity scheme | Where an applicable EU cybersecurity certification scheme is available, a certificate at assurance level ≥ Substantial | Removes the third-party assessment obligation, but only for the requirements the certificate covers |
| Free and open-source | Qualifying free and open-source products in the Important classes | May use any Module A/B+C/H route, including Module A, if the technical documentation is public at market placement |
Note: Critical products have a stricter conformity-assessment path. Use the conformity assessment decision guide for the full routing logic.
Use this flowchart to identify your path:
flowchart TD
A["What is your product class?"] --> B["Default
(not listed)"]
A --> C["Important Class I
(listed class)"]
A --> D["Important Class II
(listed class)"]
A --> E["Critical
(critical list)"]
B --> F["Module A, B+C, or H
your choice"]
C --> G{"Standards, specs, or
scheme fully applied?"}
G -->|Yes| H["Module A available
or B+C / H"]
G -->|No| I["Module B+C or H
Notified Body required"]
D --> J["Module B+C, H, or a substantial-level certification scheme"]
E --> K["Certification route if applicable
otherwise third-party routes"]
5. Standards applied
Harmonised standards are standards published in the Official Journal of the EU. They create a presumption of conformity for the requirements they cover. Include the full reference: number, year, title.
Format:
EN 303 645:2020, Cyber Security for Consumer Internet of Things: Baseline Requirements
If no harmonised standards exist, state: "No harmonised standards applied. Conformity demonstrated through [describe approach]."
If a European cybersecurity certificate was relied on during conformity assessment, list it with the scheme name and certificate reference number (this covers the certification field in the declaration).
6. CRA-specific additional information
This section is not part of the minimum declaration template, but including it improves regulatory transparency:
- Support period. State when security updates end. Must be at least 5 years from market placement, or the expected in-use period if shorter.
- Vulnerability contact. Where reports should be sent, including a reference to your
security.txtfile.
Note: The support period end date must also appear at the point of purchase. Including it in the DoC is best practice, but it does not substitute for point-of-purchase communication.
7. Signature
Anyone authorised to legally commit the manufacturer can sign. Typically that is the CEO, a director, the quality manager, or the regulatory affairs lead. The DoC must carry the signatory's full name and title, place and date (date must follow assessment completion), and a signature, typically handwritten or a qualified electronic signature.
When must CE marking be applied relative to the Declaration of Conformity?
For physical products, affix the CE marking visibly, legibly, and indelibly to the product before placing it on the market. Where that is not possible or not warranted by the nature of the product, affix it to the packaging and to the EU Declaration of Conformity instead.
For software-only products, the CE marking is placed either directly on the EU Declaration of Conformity, or on the product's website in a section that is easily and directly accessible to consumers.
Where a Notified Body is involved under Module H, the CE marking must be followed by that body's identification number.
Note: The CE marking must be affixed before placing the product on the market, not after. For software products, ensure the DoC or website section is live before any distribution begins.
Does the DoC need to be translated?
Yes. The DoC must be made available in the language(s) required by each Member State in which the product is placed on the market.
In practice:
- Selling only in Germany → a German DoC is required.
- Selling across the EU → you will need multiple language versions.
- Keep all language versions in the technical file.
The simplified DoC and the URL pointing to the full DoC must also be in the required language(s). Keeping the URL stable and accessible is best practice.
Does each product model or version need its own Declaration of Conformity?
One DoC per product type
Each distinct product model or type generally needs its own DoC.
A single DoC can cover several variants when they are variants of the same type, the same conformity assessment applies to all of them, and the same standards were applied.
Example:
Product Name: SmartSense Pro Industrial Sensor
Model/Type: SSP-3000 (all variants)
- SSP-3000-WiFi
- SSP-3000-LoRa
- SSP-3000-Cellular
When does a modification require a new DoC?
Warning: A substantial modification is a change made after the product is placed on the market that affects its compliance with the essential cybersecurity requirements, or that changes the intended purpose it was assessed for. It triggers a mandatory new DoC. A third party that both carries out the substantial modification and makes the product available on the market becomes the manufacturer and must issue the new DoC.
The table below shows typical outcomes. Apply the statutory test above rather than treating any single trigger as automatic.
| Scenario | New DoC required? |
|---|---|
| New hardware version that affects its compliance with the essential requirements | Yes, substantial modification |
| Firmware update that broadens the attack surface or raises the cybersecurity risk | Yes, substantial modification |
| Firmware update that changes the product's intended purpose | Yes, substantial modification |
| Security patch (same architecture, no new risk, reduces CVEs) | Case by case |
| Change to applied harmonised standards or conformity assessment certificate | Case by case, only if it reflects a change affecting the essential requirements or the assessed intended purpose |
| Cosmetic, documentation-only, or localisation change | No |
| Third party substantially modifies the product and places it on the market | Yes, the third party issues the new DoC as the new manufacturer |
For iterative software releases that are not substantial modifications, the existing DoC remains valid. You must be able to demonstrate this to market surveillance authorities, and the risk-assessment update is how you do it.
DoC distribution
The DoC must travel with the product. You can choose between:
- the full DoC, or
- a simplified DoC carrying the exact internet address where the full DoC is published.
Either form must also be provided on request to market surveillance authorities, and should be available to customers on request.
Simplified EU Declaration of Conformity
The simplified form is two sentences: the manufacturer's declaration and a URL where the full document can be found. It is particularly useful for software distributions, packaging-constrained hardware, and any product whose full DoC is published online.
Hereby, [name of manufacturer] declares that the product with digital elements type [designation] is in compliance with Regulation (EU) 2024/2847.
The full text of the EU declaration of conformity is available at the following internet address: [URL]
The URL: the CRA requires only that the simplified DoC carries the exact internet address where the full DoC can be accessed. As practical best practice, keep the URL stable (do not change it after products are distributed), accessible without registration or login, and downloadable or printable. The full DoC must still exist in the technical file and be available to authorities on request.
Common mistakes
| Mistake | Why it matters | Fix |
|---|---|---|
| Missing required elements (e.g., no conformity statement, or missing Notified Body details where a Notified Body was involved) | DoC is non-compliant | Use the checklist before signing; verify every required declaration item |
| Wrong entity signs (importer or distributor signs instead of manufacturer) | DoC is legally invalid | A person authorised to commit the manufacturer, or a mandated authorised representative, signs it. An importer or distributor cannot, unless they became the manufacturer |
| Outdated standards references (withdrawn or superseded standards listed) | Presumption of conformity is lost | Review applied standards regularly; update the DoC when standards change |
| No version control (multiple DoC versions exist with no clear current version) | Audit and enforcement risk | Assign declaration numbers; archive superseded versions |
| Signing before assessment is complete (DoC dated before conformity activities finished) | The DoC pre-dates the evidence it relies on | Complete all assessment activities first; DoC date must follow assessment |
| Wrong language (DoC only in English when selling in a non-English-speaking Member State) | Non-compliant for that market | Translate the DoC into each required Member State language |
| No update after substantial modification (original DoC still in use after a material change) | DoC covers a version it was never assessed for | Issue a new DoC whenever a substantial modification occurs |
DoC preparation checklist
- Conformity assessment complete
- Test reports available
- Technical file prepared
- Standards list finalised
- Support period determined
- Language requirements confirmed for all target Member States
- Unique declaration number assigned
- Manufacturer name and address correct
- Product fully identified (model, version, batch/serial)
- CRA referenced correctly: "Regulation (EU) 2024/2847"
- Other applicable legislation listed (if any)
- Conformity assessment module stated
- Notified Body details included (if applicable)
- All applied standards listed with full references
- Support period end date included
- Security contact information included
- Signatory is authorised to commit the manufacturer
- Full name and title/function stated
- Place and date stated (date after assessment completion)
- Signature present (e.g. handwritten or qualified electronic)
- Copy accompanies the product (physical or digital link)
- Copy in technical file
- Available for authority requests
- Versions tracked and archived
- Language versions prepared for all target Member States
- CE marking applied before distribution
DoC template variations
For Module A (self-assessment)
Module A. Internal Production Control.
The manufacturer has verified that the product meets the essential requirements through internal assessment documented in the technical file.
For Module B+C (third-party)
Module B + C. EU-Type Examination + Conformity to Type.
| Notified Body | TÜV Rheinland LGA Products GmbH |
|---|---|
| NB number | 0197 |
| Certificate | EU-TYPE-2027-12345 |
| Date | 15 January 2027 |
The manufacturer ensures production conformity to the certified type (Module C) through internal production controls.
For multiple regulations
A single combined DoC is required when a product is subject to the CRA and other EU legislation that also requires a declaration of conformity. It must identify each act, including its publication reference:
The object of the declaration described above is in conformity with the relevant Union harmonisation legislation:
- Regulation (EU) 2024/2847 (Cyber Resilience Act), OJ L, 2024/2847, 20.11.2024
- Directive 2014/53/EU (Radio Equipment Directive), OJ L 153, 22.5.2014. Notified Body: [Name], No. [XXXX], Certificate: [Number]
- Directive 2014/35/EU (Low Voltage Directive), OJ L 96, 29.3.2014
Retention requirements
| What to retain | Retention period | Where |
|---|---|---|
| Signed DoC (or authenticated copy) | 10 years after market placement, or the support period if longer | Technical file; accessible to authorities on request |
| Version history and superseded DoCs | Alongside the current DoC | Technical file |
| Supporting documentation referenced in the DoC | Alongside the DoC | Technical file |
Frequently asked questions
Can one Declaration of Conformity cover products sold across all EU Member States?
Yes. The same DoC document can cover the full EU, but it must be translated into the language(s) required by each Member State where the product is placed. The core content is identical; only the language version changes. Keep all translations in the technical file.
Does the CRA Declaration of Conformity need to be notarised or officially certified?
No. The DoC is signed by a person authorised to commit the manufacturer, or by a mandated authorised representative acting on its behalf. A signature is required, for example handwritten or a qualified electronic signature. No notarisation, apostille, or third-party certification of the document itself is required, unless a specific Member State requires it for market surveillance purposes.
What happens if market surveillance finds the DoC is incomplete or inaccurate?
Penalty exposure depends on the breach. A false claim that product conformity has been demonstrated can reach the highest CRA fine tier. Standalone DoC, CE-marking, or documentation defects sit in the next tier. Incorrect, incomplete, or misleading information supplied to a notified body or market surveillance authority in reply to a request has its own lower tier.
Can a software product use the simplified EU DoC instead of the full document?
Yes. Manufacturers may ship the simplified EU Declaration of Conformity with the product. The requirement is that it carries the exact internet address where the full document can be accessed; keeping that URL stable and openly accessible is best practice. The simplified form is two sentences: the manufacturer's declaration of conformity and the URL. The full document must still exist and be available to authorities on request.
How long must the CRA Declaration of Conformity be retained?
At least 10 years after the product is placed on the market, or for the length of the support period, whichever is longer. For a product with a 15-year support period, the DoC and technical file must be retained for 15 years.
Who is authorised to sign the CRA Declaration of Conformity?
A person authorised to legally commit the manufacturer signs. Where an authorised representative is appointed and its mandate specifies these tasks, the representative may draw up and sign the DoC on the manufacturer's behalf and under its responsibility, but the manufacturer stays legally responsible for conformity. An importer or distributor cannot sign unless they have become the manufacturer through own-brand placement or a substantial modification.