CRA guide
EU Declaration of Conformity for software — a worked example
CRA Annex V lists, field by field, what the EU Declaration of Conformity must contain. Below is that list, followed by an illustrative (fictional) worked example.
What Annex V requires
- Name, type and any additional information uniquely identifying the product.
- Name and address of the manufacturer or its authorised representative.
- A statement that the declaration is issued under the sole responsibility of the provider.
- The object of the declaration (identification allowing traceability — may include a photograph).
- A statement that the product is in conformity with the relevant Union harmonisation legislation.
- References to any harmonised standards, common specifications, or cybersecurity certification applied.
- Where applicable, the notified body's name and number, the assessment procedure used, and the certificate identification.
- Place and date of issue, and the signatory's name, function and signature.
A worked example
This is an illustrative example for a fictional small manufacturer — not a real filing. It shows the fields above filled in for a default-category product using internal control (no notified body, so item 7 is left blank, as the regulation allows for that route).
1. Product: Acme Sensors GmbH TempTrack Gateway, model TT-200, firmware v2.4.1
2. Manufacturer: Acme Sensors GmbH, Musterstraße 12, 10115 Berlin, Germany
3. This declaration is issued under the sole responsibility of the manufacturer.
4. Object of the declaration: TempTrack Gateway TT-200 (see product photograph, Annex VII §1)
5. The product described above is in conformity with Regulation (EU) 2024/2847 (Cyber Resilience Act).
6. Standards applied: [harmonised standard reference, or “no harmonised standard applied — see Annex VII §5 for the alternative solution adopted”]
7. Notified body: not applicable (default-category product, conformity assessment by internal control, Annex VIII Module A)
8. Signed for and on behalf of: Acme Sensors GmbH — Berlin, Germany, 14 March 2027 — J. Author, Head of Product Compliance
What backs it up
The declaration is the visible top of a larger evidence stack — Annex VII technical documentation, an SBOM, and a vulnerability-handling record. Normproof's dossier generator collects exactly the manufacturer address, signatory name, signatory function, and place/date shown above, and assembles the rest of the declaration from your product's actual recorded evidence rather than a generic template.
Key points
- Defined by CRA Annex V — 8 required fields.
- Issued under the manufacturer's sole responsibility; a precondition for CE marking.
- The notified-body field only applies where third-party assessment was used (see “Do you need a notified body?”).
- Should reference the same product, standards and route documented in your Annex VII technical documentation.
Frequently asked questions
- Who signs the EU Declaration of Conformity?
- The manufacturer, or its authorised representative, signs it under sole responsibility. The declaration records the signatory's name, function and the place and date of signing.
- Do I need a notified body's details on the declaration?
- Only if your conformity route involved one. Default-category products using internal control (Module A) leave that field not applicable.
Related
General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.