[{"data":1,"prerenderedAt":10},["ShallowReactive",2],{"article:en:does-software-need-a-ce-mark-under-the-cra":3},{"locale":4,"slug":5,"title":6,"description":7,"published":8,"body":9},"en","does-software-need-a-ce-mark-under-the-cra","Does software need a CE mark under the CRA? Yes, and Article 30 says where it goes","From 11 December 2027, a CE marking is required on every product with digital elements placed on the EU market, software included. For software the mark goes on the EU declaration of conformity or on the website accompanying the product, before it is placed on the market. What the mark asserts, who can affix it, when a notified body's number joins it, and what the declaration behind it must contain.","2026-09-11","\nYes. The Cyber Resilience Act, Regulation (EU) 2024\u002F2847, brings products with digital elements into the CE marking regime that has covered machinery, toys and radio equipment for decades. From 11 December 2027 a product in scope, hardware or software, is placed on the EU market with a CE marking, and the marking asserts that the manufacturer has demonstrated conformity with the [essential requirements of Annex I](\u002Farticles\u002Fcra-annex-i-the-22-essential-requirements-as-a-checklist).\n\nFor software companies this is new, and the obvious question is where a mark goes on something with no surface. Article 30 answers it directly.\n\n## Where the mark goes\n\nArticle 30(1): the CE marking is affixed visibly, legibly and indelibly to the product. Where that is not possible or not warranted by the nature of the product, it goes on the packaging and on the EU declaration of conformity that accompanies the product. Then, specifically for software: \"for products with digital elements which are in the form of software, the CE marking shall be affixed either to the EU declaration of conformity referred to in Article 28 or on the website accompanying the software product. In the latter case, the relevant section of the website shall be easily and directly accessible to consumers.\"\n\nSo a software manufacturer has two options: the mark on the declaration of conformity, or the mark on a section of the product's website that a consumer can reach directly. Either is enough. Most will do both, because the declaration has to exist anyway and a website section is the one a buyer sees.\n\nArticle 30(2) lets the mark be smaller than 5 mm on account of the product's nature, provided it stays visible and legible. Article 30(3): it is affixed **before** the product is placed on the market.\n\n## What the mark asserts, and who affixes it\n\nThe CE marking is the manufacturer's statement, on its own responsibility, that the product meets the applicable requirements and that the conformity assessment has been carried out. For a default product that assessment is the manufacturer's own [internal control](\u002Farticles\u002Fis-your-product-important-or-critical-under-the-cyber-resilience-act); for important and critical products a notified body is involved. Article 30(4): where a notified body was involved under the full quality assurance procedure (module H), its identification number follows the CE marking, affixed by the body or under its instructions.\n\nUnder Article 30(5), where the product is also subject to other Union harmonisation legislation that provides for CE marking, the one mark indicates conformity with all of it. A connected device already CE-marked under the Radio Equipment Directive does not get a second mark; the existing mark now also asserts CRA conformity, which means the technical file behind it now has to support that assertion.\n\n## The declaration behind it: Article 28 and Annex V\n\nThe mark is only as good as the EU declaration of conformity it stands on. Article 28: the declaration is drawn up by the manufacturer, states that fulfilment of the applicable essential requirements in Annex I has been demonstrated, follows the model structure in Annex V, contains the elements the relevant conformity assessment procedure in Annex VIII specifies, is kept updated, and is made available in the languages required by the member state where the product is placed on the market. A simplified declaration, with the model in Annex VI, may accompany the product, pointing to the full one.\n\nThe declaration and the [technical documentation](\u002Farticles\u002Fwhat-goes-in-the-cra-technical-file-annex-vii-point-by-point) are kept at the disposal of the national authorities for ten years after the product is placed on the market or for the support period, whichever is longer. [The declaration itself, Annex V point by point with a worked example](\u002Farticles\u002Fthe-eu-declaration-of-conformity-under-the-cra-annex-v-point-by-point-the-simplified-form-and-a-worked-example), is its own article.\n\n## What it means for a software release process\n\nThree things change at the point of release.\n\n**A gate before \"placed on the market\".** The declaration must be signed and the mark affixed before the version that first triggers the requirements is made available. A product first released after 11 December 2027 needs it at launch; a product already on the market needs it at the first [substantial modification](\u002Farticles\u002Fis-your-product-in-scope-of-the-cyber-resilience-act) after that date.\n\n**A place on the website.** A section reachable directly by consumers, carrying the CE marking and, sensibly, the declaration itself and the user information Annex II requires: the vulnerability contact, the support period, how updates are installed.\n\n**A file that matches the shipped version.** The mark on version 4 asserts that the technical file describes version 4. A release process that updates the declaration and the file with the product is the difference between a mark and a decoration.\n\n## What it does not mean\n\nThe CE marking is not a certificate and no authority issues it. It is not evidence of security; it is evidence that the manufacturer has claimed conformity and can be held to the claim by [the market surveillance authority of its member state](\u002Farticles\u002Fwho-enforces-the-cyber-resilience-act-in-your-member-state). Affixing it without the file behind it is the infringement Article 64 prices in its second tier.\n\nThe procedure that ends in the mark, module A of Annex VIII, with the Commission's list of activities, the two forms of the declaration of conformity and the harmonised-standards timeline, is [its own article](\u002Farticles\u002Fself-assessment-under-the-cra-what-module-a-actually-requires).\n\n## Sources\n\n- Regulation (EU) 2024\u002F2847, Article 30(1) to (5) (quoted for software), Article 28 and Annexes V and VI (the declaration), Annex VIII Part I point 4 (marking and declaration under internal control), Article 64, Article 69 and Article 71(2) for the dates. Read from the Official Journal text on EUR-Lex on 11 September 2026.\n\nThis is not legal advice. Article 30 is nine sentences; read it before you decide where your mark goes.\n",1789383985290]