The EU declaration of conformity under the CRA
Short answer. The declaration of conformity is a one-page document with eight required items, and Annex V tells you exactly what they are. It is the easiest of the five documents to produce.
It is also the one with teeth. It is signed under sole responsibility, by a named person, asserting that the product meets the essential requirements. Everything else in your file exists to make that signature defensible.
Manufacturers coming from other CE-marking regimes will find this familiar — the shape is the same as the declaration you already sign for EMC or radio equipment. Manufacturers whose products have never been CE-marked before often expect something more elaborate, and are surprised that the legally decisive document is a single page they write themselves.
- The eight items in Annex V
- What “sole responsibility” actually commits you to
- Point 6, and the problem with citing standards that do not exist yet
- The simplified declaration in Article 28
- When it has to be redrawn, and why the old ones matter
- Five ways this document goes wrong
- One word worth checking with the Official Journal open
The eight items in Annex V
Annex V is the content list for the declaration referred to in Article 28. It requires all of the following.
| # | What it requires | What that means in practice |
|---|---|---|
| 1 | Name, type and any additional information enabling unique identification of the product | Model name, type designation, and whatever identifier pins down exactly which product this is — part number, SKU, or the software version range |
| 2 | Name and address of the manufacturer or its authorised representative | Legal entity name and postal address. A non-EU manufacturer with an authorised representative names it here |
| 3 | A statement that the declaration is issued under sole responsibility | One sentence, and the most important one in the document. See below |
| 4 | Object of the declaration — identification allowing traceability, which may include a photograph where appropriate | Distinct from point 1: point 1 names the product, point 4 identifies the specific object being declared so it can be traced back |
| 5 | A statement that the object is in conformity with the relevant Union harmonisation legislation | Name the legislation. For most products that is more than just the CRA — a connected device is often also under radio equipment, EMC or machinery rules |
| 6 | References to any relevant harmonised standards used, or any other common specification or cybersecurity certification in relation to which conformity is declared | The interesting one, because of what does not exist yet. See below |
| 7 | Where applicable, the notified body's name and number, a description of the conformity assessment procedure performed, and identification of the certificate issued | Blank if you self-assess. If you went through EU-type examination, this is where the certificate is cited |
| 8 | Additional information, then a signature block: signed for and on behalf of, place and date of issue, name and function, signature | A named human with a stated role. Not an anonymous corporate seal |
Note what is not in the list. No requirement for a lawyer, an auditor, a consultant, a notarisation, a filing with any authority, or a fee. For a product in the default category, nobody outside your company is involved in this document at all.
What “sole responsibility” actually commits you to
Point 3 is one sentence long and it is the whole reason the rest of your file exists.
By signing, you are asserting — on your own responsibility, with nobody to share it with — that the identified product conforms to the relevant Union harmonisation legislation. For the CRA that means it meets the essential cybersecurity requirements in Annex I: Part I's properties of the product, and Part II's vulnerability-handling process.
Which produces the honest framing of the whole compliance exercise:
The declaration is not the work. The declaration is the claim. The technical documentation is the evidence for the claim, and the risk assessment is the reasoning behind it. If the file cannot support the sentence, the sentence is the problem — not the file.
Two things follow that are worth being blunt about.
A declaration is easy to produce and easy to produce falsely. Nothing stops you from signing one today for a product that has had no risk assessment. The document will look correct. It will also be a false statement in a signed instrument, and non-compliance with the Annex I requirements sits in the top penalty tier alongside the Article 13 and 14 duties. Producing the document without the work behind it is worse than not producing it, because it converts an omission into an assertion.
The named individual matters. Point 8 requires a name and a function, not just a company. For a one-person business that is you. That is not a reason for alarm — it is the same commitment a director already makes across a range of regulatory filings — but it is a reason to read the sentence you are signing rather than treating it as boilerplate.
Point 6, and the problem with citing standards that do not exist yet
Point 6 asks for references to the harmonised standards, common specifications or cybersecurity certifications in relation to which conformity is declared.
In a mature CE-marking regime this is the easy part: you cite the standard, and citing it gives you a presumption of conformity. For the CRA today it is the awkward part, because the harmonised standards are still being developed under the Commission's standardisation request, and their published schedules have already moved.
So what do you put in point 6 before they arrive?
- If a relevant harmonised standard exists and you applied it, cite it, with its reference and version, and say whether you applied it in full or in part. Point 6 is also cross-referenced by Annex VII point 5, which requires the same list in your technical documentation.
- If none exists for your product type, you have not failed the point. Point 6 asks for references to what you used. If you used none, there is nothing to reference — but the burden then moves entirely onto your own documented reasoning about how the product meets Annex I, because you are not relying on a presumption.
- Do not invent a citation, and do not cite a draft as though it were cited in the Official Journal. A standard confers a presumption of conformity only once it has been cited there. A reference to a draft in a signed declaration is a misleading statement in the exact document an authority reads first.
The simplified declaration in Article 28
Article 28 provides that a simplified EU declaration of conformity may be provided with the product. This is a practical accommodation, and it is widely misunderstood as a lighter obligation. It is not.
- The full declaration still has to be drawn up. The simplification is about what physically accompanies the product.
- The simplified version typically carries an internet address where the full declaration can be obtained — which is also what Annex II point 6 requires you to give users anyway.
- That URL is a commitment. If you cite an address, it has to resolve, and the underlying retention duty runs for at least ten years from placing the product on the market. A link that dies in a site rebuild in 2031 is a compliance failure with no error message.
When it has to be redrawn, and why the old ones matter
The declaration is a statement about a specific identified product. So when the product changes in a way that matters, the statement has to be remade. The clearest trigger is a substantial modification, which requires the product to be reassessed — and a reassessed product needs a declaration that reflects the reassessment.
Other triggers worth watching: a change in the standards you cite in point 6; a change of legal entity name or address; a move from self-assessment to a notified-body route, or the reverse; and a change to the support period, which flows into the user information the file has to contain.
And never overwrite the previous one. This is the mistake that is invisible for years. The declaration you signed in 2027 was the instrument that governed the units placed on the market in 2027. If a question arises about those units in 2033, the 2027 declaration is the relevant document, and the current one is not a substitute. The retention duty is at least ten years from placing on the market, or the support period, whichever is longer — and that applies to each version, for the units it covered.
Five ways this document goes wrong
- Signing before the evidence exists. The most serious one. The document is trivial to produce and the assertion is not trivial to support.
- Identifying the product too loosely. “Our firmware” is not unique identification. Points 1 and 4 exist so that a specific unit can be traced to a specific declaration.
- Naming only the CRA in point 5. Most connected products sit under several instruments at once. Point 5 asks about the relevant Union harmonisation legislation, plural.
- Citing a draft standard in point 6. Or citing a standard you applied only partly without saying so.
- Keeping one live file called
doc.pdf. Overwriting destroys the version that governed earlier units, and there is no way to reconstruct it.
One word worth checking with the Official Journal open
A note in the interests of being straight with you, because this page is about a document you will sign.
In the reproduction of Annex V used in preparing this page, point 3 reads that the declaration is issued under the sole responsibility of the “provider” — where every comparable EU declaration-of-conformity annex says “manufacturer”, and where Annex V's own point 2 says “manufacturer”.
There are two possibilities. It is a genuine drafting quirk in the published text — those exist, and the CRA has already been corrected twice by corrigendum. Or the reproduction is wrong and the official text says “manufacturer”.
We have not resolved it, and we are not going to guess, because it is a single word in the most-read sentence of the most-checked document in the set. If you are drafting your own declaration, take the wording of point 3 from the Official Journal text rather than from any secondary source, including this page. It is one line to check with the file open, and it is the highest-value five minutes available on this subject.
An honest note on confidence: the Annex V list on this page comes from a single reproduction of the annex and has not been second-sourced, which is weaker than most pages on this site and is the reason for the section immediately above. Annex VII's cross-references were confirmed against two independent reproductions. The account of Article 28's simplified declaration is a summary, not a quotation. Nothing here is legal advice.
The declaration is one page. Getting to the point where you can sign it is the work
Conformance House produces the declaration alongside the technical documentation and the risk assessment that has to support it — and keeps every signed version dated, so the declaration that governed a 2027 unit still exists in 2037.
Need to know whether you self-assess or need a notified body first? That is decided by two short lists.