CRA File / guide, updated 2026-10-05
EU declaration of conformity template for the Cyber Resilience Act
The EU declaration of conformity is the document in which you, as manufacturer, state that your product meets the requirements of the Cyber Resilience Act (Regulation (EU) 2024/2847). Article 28 requires it, Annex V gives the content, and Annex VI gives a simplified version. It is one of the documents in the technical file (Annex VII) and must exist before you place the product on the market with the CE marking. The obligations apply from 11 December 2027.
What the declaration contains (Annex V, in short)
- The product with digital elements: name, type and any additional information that identifies it uniquely.
- Name and address of the manufacturer or of the authorised representative.
- A statement that the declaration is issued under the sole responsibility of the manufacturer.
- The object of the declaration, identified so that the product can be traced (version, serial or batch where relevant).
- A statement that the product conforms to the Regulation and to any other relevant Union harmonisation legislation.
- References to harmonised standards, common specifications or a European cybersecurity certification scheme that were applied, where relevant.
- Where applicable, the name and number of the notified body, a description of the conformity assessment procedure performed and identification of the certificate issued.
- Additional information, and the signature block: place and date, name and function of the signatory.
Check Annex V of the Regulation for the exact text. The list above is a summary to prepare the facts.
Fill-in template
EU declaration of conformity
1. Product: <name, type, version, other identification>
2. Manufacturer: <legal name and postal address>
Authorised representative (if any): <name and address>
3. This declaration of conformity is issued under the sole responsibility
of the manufacturer.
4. Object of the declaration: <identification allowing traceability>
5. The object of the declaration described above is in conformity with
Regulation (EU) 2024/2847 and with <other Union harmonisation legislation,
if any>.
6. Standards, specifications or certification scheme applied:
<references, or "none">
7. Notified body (if applicable): <name, number, procedure performed, certificate>
8. Additional information: <...>
Signed for and on behalf of: <manufacturer>
Place and date of issue: <...>
Name, function, signature: <...>
Simplified declaration (Annex VI)
The manufacturer may provide the simplified declaration (Annex VI). In essence it reads: "Hereby, [manufacturer] declares that the product with digital elements type [designation of type] is in compliance with Regulation (EU) 2024/2847. The full text of the EU declaration of conformity is available at the following internet address: ...". Keep the full declaration available at that address, and keep the technical documentation and the declaration for at least 10 years after the product was placed on the market or for the support period, whichever is longer (Article 13).
Where this fits
The declaration is only as good as the file behind it: the risk assessment, the vulnerability handling process, the SBOM and the test reports. Start with what you can generate today: classify your product, check your SBOM and publish a disclosure policy.
This page is general information, not legal advice; check the Regulation and, for important and critical products, the conformity assessment route in Article 32.
Free tools
- Product classifier: Is your product in scope, and in which category?
- SBOM checker: Check a CycloneDX or SPDX file in your browser.
- security.txt and disclosure policy: The contact file and policy the Regulation expects.
- Repository check: what a GitHub repository already shows.
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.