CE marking under the Cyber Resilience Act is the sign with which the manufacturer declares that its product with digital elements meets the essential cybersecurity requirements of Regulation (EU) 2024/2847. Before affixing it, the manufacturer needs a conformity assessment, technical documentation and an EU declaration of conformity signed under its own responsibility. It applies to products placed on the EU market from 11 December 2027. The regulation offers four assessment procedures, from self-assessment through internal control to European certification, and the product’s category decides which are available. The pieces that will allow many manufacturers to self-assess, the harmonised standards, are still being drafted, and notified bodies can only be notified from 11 June 2026.
If you need a lawyer to help you comply with the Cyber Resilience Act, request a free initial assessment.
CE marking shows that the product meets the essential cybersecurity requirements of Annex I and that the manufacturer has followed the assessment procedure that applies to it. By drawing up the EU declaration of conformity, the manufacturer assumes responsibility for that conformity, under Article 28(4). It is not third-party certification, even though in some cases a third party is involved.
It is the same CE marking that many products already bear for electrical safety, electromagnetic compatibility or radio equipment. When a product is subject to several laws requiring CE marking, a single marking indicates that it complies with all of them, and Article 28(3) requires a single EU declaration of conformity referring to each applicable law.
The marking is required for products placed on the market from 11 December 2027. Those placed on the market earlier are outside the essential requirements unless they are substantially modified after that date, under Article 69(2), although they are already subject to the obligation to report exploited vulnerabilities.
Article 32 of the Cyber Resilience Act provides four procedures for demonstrating conformity. They are based on the classic modules of EU product legislation and are described in Annex VIII.
| Procedure | Who assesses | What it involves |
|---|---|---|
| Internal control, module A | The manufacturer | Technical documentation, control of its processes and an EU declaration of conformity under its sole responsibility |
| EU-type examination and conformity to type, modules B and C | A notified body examines the design and the manufacturer ensures that production matches the approved type | EU-type examination certificate issued by the body |
| Full quality assurance, module H | A notified body approves and monitors the manufacturer’s quality system | Periodic audits of the quality system covering design, development, production and vulnerability handling |
| European cybersecurity certification scheme | A conformity assessment body under Regulation (EU) 2019/881 | European certificate, where a scheme applicable to the product exists |
The product’s category limits the procedures the manufacturer can use. Classification into default products, important products of class I and II and critical products is explained in our guide to product classification under the Cyber Resilience Act.
| Category | Procedures available |
|---|---|
| Default | Any of the four, including internal control |
| Important, class I | Internal control if harmonised standards, common specifications or a European certification scheme at assurance level at least substantial are applied in full. Otherwise, modules B and C or module H |
| Important, class II | Modules B and C, module H or a European certification scheme at assurance level at least substantial |
| Critical | European certification if a delegated act requires it. Until it does, the same routes as class II |
Free and open-source software has a rule of its own. Article 32(5) allows its manufacturer to use internal control even if the product is listed in Annex III, provided it makes the technical documentation public when placing it on the market. Article 32(6) also requires assessment fees to be reduced proportionately for microenterprises, SMEs and start-ups.
The technical documentation is the file that shows how the product complies, and it is drawn up before the product is placed on the market. Article 31 requires it to be kept up to date at least during the support period. Article 13 requires it to be kept at the disposal of the authorities for at least ten years, or for the whole support period if longer. Annex VII sets its minimum content.
The software bill of materials, known as the SBOM, is the new element that creates the most work for manufacturers that have never kept one. Microenterprises and small enterprises will be able to submit the documentation in a simplified format, which the Commission must specify through an implementing act, under Article 33(5).
The EU declaration of conformity is the signed document in which the manufacturer states that the product meets the applicable essential requirements. It follows the structure of Annex V, is kept up to date and must be available in the language or languages required by each Member State where the product is sold. The regulation also allows a simplified declaration, following the model in Annex VI, which refers to the internet address where the full text can be found.
If other EU laws requiring a declaration apply to the product, such as the radio equipment directive for a wireless device, a single declaration is drawn up citing all of them, with their publication references.
CE marking is affixed visibly, legibly and indelibly to the product before it is placed on the market, under Article 30. Where the nature of the product does not allow this, it goes on the packaging and on the EU declaration of conformity. It may be smaller than 5 millimetres provided it remains visible and legible.
Products that are software only have no physical surface. The marking goes on the EU declaration of conformity or on the website accompanying the product, and in that case consumers must be able to reach the section where it appears easily and directly.
The notified body’s identification number accompanies the marking only when that body is involved in the full quality assurance procedure, module H. It is affixed by the body itself or by the manufacturer following its instructions.
Applying a harmonised standard whose reference has been published in the Official Journal of the European Union gives a presumption of conformity with the requirements it covers, under Article 27. For class I products it is also the key to self-assessment.
The Commission entrusted those standards to the European standardisation organisations through standardisation request M/606, which covers a set of 41 horizontal and product standards. Until the reference of each one is published in the Official Journal it gives no presumption of conformity, even if the technical text is available. If the standards do not arrive or do not meet the request, the Commission can adopt common specifications through implementing acts, with the same effect.
Notified bodies are the independent entities involved in modules B, C and H. The rules for notifying them, in Chapter IV of the regulation, have applied since 11 June 2026, eighteen months before CE marking becomes mandatory, so that the network exists in time.
The manufacturer chooses the body. The application for EU-type examination is lodged with a single notified body of its choice, with a declaration that it has not been lodged with another, and the body can be from any Member State. In Spain the notifying authority has not yet been designated. The draft royal decree on designation assigns that role to the National Cryptologic Centre (CCN) and market surveillance to the Secretary of State for Telecommunications and Digital Infrastructure.
The technical documentation and correspondence with the body are drawn up in an official language of the Member State where it is established or in a language it accepts, under Article 31(4). Choosing a body in another country may mean translating the file.
Missing CE marking, incorrectly affixed marking, an EU declaration of conformity that does not exist or is drawn up incorrectly, a missing notified body number and incomplete technical documentation are formal non-compliance under Article 58. The market surveillance authority requires them to be remedied and, if they persist, restricts or prohibits the sale or ensures that the product is withdrawn or recalled. The fines for these infringements are explained in our analysis of Cyber Resilience Act penalties.
The case is fictitious. Portalia Smart, S.L. manufactures in Santiago de Compostela a smart lock for homes that is opened from a mobile app. The lock is an important product of class I, because it falls into the category of smart home products with security functionalities. The cloud server that allows it to be opened remotely forms part of the product as a remote data processing solution, because without it the lock could not perform one of its functions.
Portalia wants to sell the second version of the lock in February 2028. If by then the applicable harmonised standards have been published in the Official Journal and it applies them in full, it will be able to self-assess through internal control. If they do not exist or it applies them only in part, it will have to choose between modules B and C or module H with a notified body. As it cannot know today which scenario it will be in, it starts in 2026 with what does not depend on the standards. That means the software bill of materials, the vulnerability disclosure policy, the support period and the risk assessment.
As the lock uses a wireless connection, Portalia will draw up a single EU declaration of conformity citing the Cyber Resilience Act and the radio equipment directive. The general framework of the regulation is in our guide to what the Cyber Resilience Act is and which companies it covers.
It depends on the product’s category. Default products can self-assess through internal control. Class I products can too, if they apply harmonised standards, common specifications or a European certification scheme in full; otherwise they need a notified body. Class II and critical products always need a notified body or European certification.
On the EU declaration of conformity or on the website accompanying the product, under Article 30(1) of the Cyber Resilience Act. If it is placed on the website, users must be able to reach the section where it appears easily and directly.
Yes, and it is mandatory. When a product is subject to several EU laws requiring a declaration, such as the Cyber Resilience Act and the radio equipment directive, Article 28(3) requires a single declaration identifying all of them and their publication references.
From 11 December 2027 for products placed on the EU market from that date. Products placed on the market earlier only become subject to the essential requirements if they are substantially modified afterwards, although the obligation to report exploited vulnerabilities has applied to them since 11 September 2026.
At least ten years from the product being placed on the market, or for the whole support period if longer. Throughout that time it must be at the disposal of the market surveillance authorities together with the EU declaration of conformity, and kept up to date at least during the support period.
CE marking under the Cyber Resilience Act is won or lost before December 2027, not in December. The technical documentation, the software bill of materials and choosing a notified body take months, and part of that work does not depend on the harmonised standards being published. At Innovatech we work with manufacturers and importers on the assessment route for each product, the EU declaration of conformity and supplier contracts, as part of our Cyber Resilience Act compliance service. Write to us and we will give you a free initial assessment.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
