CRA guide

EU Declaration of Conformity for software — a worked example

CRA Annex V lists, field by field, what the EU Declaration of Conformity must contain. Below is that list, followed by an illustrative (fictional) worked example.

What Annex V requires

  • Name, type and any additional information uniquely identifying the product.
  • Name and address of the manufacturer or its authorised representative.
  • A statement that the declaration is issued under the sole responsibility of the provider.
  • The object of the declaration (identification allowing traceability — may include a photograph).
  • A statement that the product is in conformity with the relevant Union harmonisation legislation.
  • References to any harmonised standards, common specifications, or cybersecurity certification applied.
  • Where applicable, the notified body's name and number, the assessment procedure used, and the certificate identification.
  • Place and date of issue, and the signatory's name, function and signature.

A worked example

This is an illustrative example for a fictional small manufacturer — not a real filing. It shows the fields above filled in for a default-category product using internal control (no notified body, so item 7 is left blank, as the regulation allows for that route).

1. Product: Acme Sensors GmbH TempTrack Gateway, model TT-200, firmware v2.4.1

2. Manufacturer: Acme Sensors GmbH, Musterstraße 12, 10115 Berlin, Germany

3. This declaration is issued under the sole responsibility of the manufacturer.

4. Object of the declaration: TempTrack Gateway TT-200 (see product photograph, Annex VII §1)

5. The product described above is in conformity with Regulation (EU) 2024/2847 (Cyber Resilience Act).

6. Standards applied: [harmonised standard reference, or “no harmonised standard applied — see Annex VII §5 for the alternative solution adopted”]

7. Notified body: not applicable (default-category product, conformity assessment by internal control, Annex VIII Module A)

8. Signed for and on behalf of: Acme Sensors GmbH — Berlin, Germany, 14 March 2027 — J. Author, Head of Product Compliance

What backs it up

The declaration is the visible top of a larger evidence stack — Annex VII technical documentation, an SBOM, and a vulnerability-handling record. Normproof's dossier generator collects exactly the manufacturer address, signatory name, signatory function, and place/date shown above, and assembles the rest of the declaration from your product's actual recorded evidence rather than a generic template.

Key points

  • Defined by CRA Annex V — 8 required fields.
  • Issued under the manufacturer's sole responsibility; a precondition for CE marking.
  • The notified-body field only applies where third-party assessment was used (see “Do you need a notified body?”).
  • Should reference the same product, standards and route documented in your Annex VII technical documentation.

Frequently asked questions

Who signs the EU Declaration of Conformity?
The manufacturer, or its authorised representative, signs it under sole responsibility. The declaration records the signatory's name, function and the place and date of signing.
Do I need a notified body's details on the declaration?
Only if your conformity route involved one. Default-category products using internal control (Module A) leave that field not applicable.

Related

General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.

See exactly what the CRA requires for your product.

Run the free readiness check — your category, obligations, and deadlines in 60 seconds.