The EU Declaration of Conformity Under the Cyber Resilience Act
Essential Guidance for Software Publishers and Manufacturers on CRA Requirements

The EU Declaration of Conformity under the CRA is a mandatory legal document issued by manufacturers of products with digital elements. It formally declares that their product adheres to all relevant provisions of the Cyber Resilience Act (EU Regulation 2024/2847). This declaration serves as a crucial assertion of compliance with the essential cybersecurity requirements outlined in the Act, granting market access within the EU.
Understanding Your CRA Compliance Obligations
The Cyber Resilience Act (CRA) introduces stringent cybersecurity requirements for hardware and software products across their entire lifecycle. For software makers, meticulously preparing and maintaining an accurate EU Declaration of Conformity is fundamental to demonstrating compliance. This document is far more than a mere formality; it is a critical statement of your unwavering commitment to robust cybersecurity and an indispensable prerequisite for placing your products on the European market.
Who is Responsible for Declaring Conformity?
Manufacturers, encompassing SaaS vendors, independent developers, small tech companies, and connected-product manufacturers, bear the primary responsibility for drawing up the EU Declaration of Conformity. This obligation applies to any product with digital elements made available on the EU market, unless specifically exempted by the Act.
Mandatory Elements of Your EU Declaration
The EU Declaration of Conformity, precisely specified in Annex V of the CRA, demands meticulous attention to detail and an ongoing commitment to cybersecurity.
Formal Compliance Statement
Formally declare that your software product meets all essential requirements of the CRA, encompassing cybersecurity and data protection.
Clear Product Identification
Clearly identify the product, including its type, batch, serial number, and any other relevant identifiers for complete traceability.
Manufacturer & Representative Information
Provide comprehensive details about the manufacturer or their authorized representative, ensuring full accountability and contactability.
Referenced Harmonised Standards
Reference the harmonised standards or common specifications applied, or other technical specifications where relevant, to demonstrate compliance.
Availability of Technical Documentation
Confirm that the technical documentation, as detailed in Annex VII of the CRA, has been meticulously drawn up and is readily available for inspection.
Sole Responsibility Statement
A clear and unequivocal statement from the manufacturer taking full responsibility for the product's conformity with the CRA.
Simplifying Your Path to CRA Declaration
Preparing the EU Declaration of Conformity can be a complex and time-consuming undertaking, demanding a thorough understanding of the CRA's intricate requirements and access to comprehensive technical documentation. For software makers, gathering all necessary information, accurately assessing compliance, and ensuring precision can divert valuable resources from core development activities.
- Automate SBOM generation for your software components.
- Assess your current cybersecurity posture against CRA requirements.
- Generate pre-filled EU Declaration of Conformity documents.
- Stay informed on vulnerabilities affecting your software supply chain.

Contents and Structure of the EU Declaration
The EU Declaration of Conformity is a formal, legally binding statement, signed by the manufacturer or their authorized representative, attesting that a product with digital elements complies with the essential requirements set out in the CRA. According to Annex V of the Act, this declaration must contain specific, mandatory elements to be valid and legally enforceable.
Mandatory Information
The declaration must include:
- Specific product identification (type, batch, serial number, software version, etc.).
- Name and full address of the manufacturer and, if applicable, their authorized representative.
- A clear statement that the declaration is issued under the sole responsibility of the manufacturer.
- A statement of conformity with the relevant Union harmonization legislation (specifically, the Cyber Resilience Act).
- References to the applied harmonized standards, common specifications, or other technical specifications used for conformity assessment.
- The name and identification number of the Notified Body, where applicable (for products requiring third-party conformity assessment).
- Place and date of issue of the declaration.
- Identity and signature of the person authorized to draw up the declaration on behalf of the manufacturer.
The Indispensable Role of Technical Documentation
The EU Declaration of Conformity must always be accompanied by the comprehensive technical documentation specified in Annex VII of the CRA. This documentation provides the detailed evidence necessary to demonstrate that the product fully complies with the Act's stringent requirements. It encompasses critical information on the design, manufacturing processes, and operational aspects of the product, alongside robust risk assessment and vulnerability handling procedures. Without meticulously prepared technical documentation, your Declaration of Conformity holds little legal weight or credibility.
Streamline Your CRA Documentation Process
From SBOMs to pre-filled Declarations, CRAcheck provides the tools you need.
Key Steps to Ensure a Compliant EU Declaration
- 1
Thoroughly Understand CRA Requirements
Familiarise yourself comprehensively with the Cyber Resilience Act, paying particular attention to its essential cybersecurity requirements and specific provisions for your product class (default, important, critical).
- 2
Perform a Comprehensive Risk Assessment
Conduct a detailed cybersecurity risk assessment for your software product, meticulously identifying and mitigating potential vulnerabilities throughout its lifecycle, as explicitly required by Annex III of the CRA.
- 3
Compile Essential Technical Documentation
Assemble all necessary technical documentation as meticulously outlined in Annex VII of the CRA, including design specifications, implemented security measures, vulnerability management processes, and comprehensive test reports.
- 4
Generate a Comprehensive SBOM
Create a Software Bill of Materials (SBOM) for your product to list all components, including open-source libraries, ensuring full transparency and significantly aiding vulnerability monitoring.
- 5
Draft the Official EU Declaration of Conformity
Based on your robust technical documentation and thorough compliance assessment, draft the EU Declaration of Conformity, ensuring all mandatory elements from Annex V are precisely included.
- 6
Continuous Maintenance and Monitoring
Post-declaration, continuously monitor your product for new vulnerabilities, update documentation as necessary, and be prepared to revise your declaration if significant changes occur or new risks emerge, ensuring ongoing compliance.
How CRAcheck Empowers Your EU Declaration Process
CRAcheck is meticulously designed to be your indispensable self-assessment support tool, simplifying the often daunting task of preparing for the Cyber Resilience Act and generating your EU Declaration of Conformity. We provide a structured, efficient approach to compliance, ensuring you meet your obligations effectively and confidently.
Automated Document Generation
One of CRAcheck's core strengths is its ability to automatically generate pre-filled documents, including your EU Declaration of Conformity and comprehensive technical documentation (Annex VII). By seamlessly connecting your GitHub repository, CRAcheck intelligently leverages your project data to populate these crucial documents, saving you significant time and drastically reducing the risk of manual errors. This provides a robust and reliable foundation for your legal statement of conformity.
Comprehensive Compliance Assessment
CRAcheck goes far beyond mere document generation. Our advanced platform helps you compute a precise compliance score out of 100, offering a clear and actionable indication of your readiness. We generate a detailed Software Bill of Materials (SBOM) across 9 ecosystems (npm, PyPI, Go, Rust, .NET, PHP, Ruby, Java, CycloneDX), and provide proactive vulnerability monitoring with email alerts, ensuring your technical documentation is always up-to-date and your declaration remains accurate and valid.
Stay Ahead of Critical Deadlines
With vulnerability reporting due on 11 September 2026 and full obligations on 11 December 2027, time is of the essence. CRAcheck empowers you to prepare proactively, effectively mitigating the risk of potential penalties up to EUR 15M or 2.5% of worldwide turnover.
Frequently Asked Questions About the CRA Declaration
What is the primary purpose of the EU Declaration of Conformity under the CRA?+
The EU Declaration of Conformity is a legal statement by the manufacturer that their product with digital elements complies with all essential cybersecurity requirements of the Cyber Resilience Act. It is mandatory for placing products on the EU market.
Which products are required to have an EU Declaration of Conformity under the CRA?+
All products with digital elements made available on the EU market, unless specifically exempted, require an EU Declaration of Conformity. This encompasses a wide range of hardware and software, from IoT devices to operating systems and SaaS solutions.
Does CRAcheck guarantee full compliance with the Cyber Resilience Act?+
CRAcheck is a self-assessment support tool meticulously designed to help you prepare for and manage your CRA obligations. While it significantly assists in generating necessary documentation and assessing your posture, it does not provide official certification or guarantee full compliance. Manufacturers remain ultimately responsible for their products' conformity.
What are the consequences of not having a proper EU Declaration of Conformity?+
Non-compliance with the CRA, including failing to provide an accurate EU Declaration of Conformity, can lead to significant penalties. These can be as high as EUR 15 million or 2.5% of the manufacturer's total worldwide annual turnover for the preceding financial year, whichever is higher.
How frequently should the EU Declaration of Conformity be updated?+
Your EU Declaration of Conformity must accurately reflect your product's current compliance status. It requires updating whenever significant changes are made to the product that affect its conformity with the CRA, or when new risks or vulnerabilities are identified that necessitate changes in your technical documentation or security measures.
Ensure Your Software is CRA-Ready
Take the first step towards securing your market access in the EU.
Same topic — Obligations CRA
New to the Cyber Resilience Act? Start with the complete guide.
The CRA guideFrom the blog
Check your CRA compliance in 1 minute
Free, no sign-up. Scan your repo and get your compliance score + pre-filled documents.