Cyber Resilience Act
CE marking
Legal definition Art. 3(31) CRA
“a marking by which a manufacturer indicates that a product with digital elements and the processes put in place by the manufacturer are in conformity with the essential cybersecurity requirements set out in Annex I and other applicable Union harmonisation legislation providing for its affixing”
CE marking is not a quality seal and not a test mark. It is a declaration, and one the manufacturer makes itself. By affixing it, the manufacturer says: this product and the processes I have put in place meet the essential cybersecurity requirements in Annex I and all other applicable Union harmonisation legislation providing for its affixing.
The second half is notable. The declaration expressly covers not only the product but the manufacturer’s processes. Vulnerability handling is therefore part of what the marking asserts, not just the state of the shipped code.
What has to come first
The marking sits at the end of a chain, not the start:
- Conformity assessment verifies that the Annex I requirements are met.
- The technical documentation records what that verification rests on.
- The EU declaration of conformity formally states the result.
- Only then is the CE marking affixed.
Treating the marking as a formality at the end reverses the order and usually leaves nothing to back it up.
Affixing it
As a rule the marking is affixed visibly, legibly and indelibly to the product. Where the nature of the product does not allow or does not warrant that, the marking goes on the packaging and on the EU declaration of conformity accompanying the product.
For software there is the special rule already mentioned: the declaration of conformity, or the accompanying website, in the latter case easily and directly accessible. The Cyber Resilience Act (CRA) also allows the height of the mark to be lower than the usual five millimetres where the nature of the product warrants it, provided the marking remains visible and legible.
What hangs on it
With the marking, the manufacturer takes responsibility for the accuracy of its declaration. Market surveillance authorities can request the underlying documentation; where the declaration turns out to be wrong, measures up to recall and withdrawal from the market are on the table.
That is the real reason marking without solid documentation is a risk: it is a commitment that must remain verifiable at any time. That holds for at least ten years, or for the duration of the support period, whichever is longer.
Practical questions
-
No, and this is the most common misunderstanding. It is a self-declaration by the manufacturer. Nobody grants it and nobody approves it. The manufacturer affixes it and carries responsibility for the declaration being true. Only for certain product categories must a notified body be involved beforehand. Even then, the marking remains the manufacturer’s own declaration.
-
The CRA explicitly provides two routes: the CE marking is affixed either to the EU declaration of conformity or to the website accompanying the software product. In the second case the relevant section must be easily and directly accessible to consumers; a link buried in the legal notice is not enough.
-
The marking is the same, but what it asserts becomes broader. It will also declare conformity with the CRA’s cybersecurity requirements. Anyone already marking under other harmonisation legislation does not need a second mark, but does need to extend the underlying assessment and documentation to cover the CRA part.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.