← Back to CRA Insights
Conformity assessment

Writing Your EU Declaration of Conformity: CRA Annex V Field by Field (and the Simplified Version Most Teams Miss)

The EU Declaration of Conformity is the shortest legally binding document you will produce under the Cyber Resilience Act, and the one most teams leave until last. It is one page. It has eight mandatory elements, set out in Annex V. There is also a shorter version in Annex VI that a surprising number of manufacturers do not know exists. This is a field-by-field guide to what actually goes in each box.

This article provides general guidance, not legal advice. The worked examples below are illustrations to adapt, not approved templates. Have your declaration reviewed before you sign it.

Key points

  • Annex V sets eight mandatory elements for the full EU Declaration of Conformity (DoC). Annex VI sets a shorter, simplified declaration, referenced by Article 13(20).
  • The simplified version supplements the full one. It does not replace it, and it must point to an internet address where the full declaration can be obtained.
  • Article 28(2) requires the declaration in the languages required by each Member State where you place or make the product available. Plan for translation.
  • Article 28(3): if your product is covered by several EU acts requiring a DoC, you draw up one single declaration covering all of them. This is where most of the time saving is.
  • Field 6 - references to harmonised standards - will look thin or empty in 2026. No CRA harmonised standard has been cited in the Official Journal yet. That is expected, not a defect.
  • The DoC, CE marking and technical documentation are enforceable from 11 December 2027, not from the September 2026 reporting date. Drafting it now is still worth doing.

What the declaration is, and is not

The DoC is the document by which you state that your product meets the applicable essential cybersecurity requirements in Annex I, and take responsibility for that statement. Article 28(4) puts it plainly: by drawing up the declaration, the manufacturer assumes responsibility for the compliance of the product[1].

It is not your technical file. The technical documentation under Annex VII is the body of evidence sitting behind the declaration - risk assessment, SBOM, test records, design documents - and it is kept for ten years, not shipped with the product. We cover that separately in CRA Technical Documentation: What Annex VII Requires.

Think of the DoC as the signature page on a much thicker file. Short, public, and load-bearing.

Annex V, field by field

Annex V lists eight elements. Here is what each one means, an illustrative example, and the mistake we see most often.

1. Name, type and identifying information

The product identity at type level: what it is called and what model or family it belongs to.

Illustration: "NorthVale ThermaLink Smart Radiator Controller, model TL-200."

Common mistake: listing a marketing name with no model designation, so the declaration cannot be tied to a specific product line.

2. Name and address of the manufacturer or authorised representative

Legal entity name and a postal address. If you have appointed an authorised representative under Article 18, they can appear here.

Common mistake: a trading name rather than the registered legal entity, or a PO box with no street address.

3. A statement that the declaration is issued under the sole responsibility of the provider

Standard New Legislative Framework wording, used across EU product law.

Illustration: "This declaration of conformity is issued under the sole responsibility of the manufacturer."

Common mistake: softening it. Do not add "to the best of our knowledge". That is not what the regulation asks you to say.

4. Object of the declaration

This is where fields 1 and 4 stop looking duplicative. Field 1 identifies the product type. Field 4 identifies the specific object in a way that allows traceability - which is where serial ranges, hardware revisions and, critically for software, firmware or software version belong. Annex V notes that a photograph may be included where appropriate.

Illustration: "NorthVale ThermaLink TL-200, hardware revision C, firmware version 4.2.x and later."

Common mistake: omitting version information entirely, which makes it impossible to tell which builds the declaration actually covers.

5. A statement of conformity with the relevant Union harmonisation legislation

The declaration proper.

Illustration: "The object of the declaration described above is in conformity with the relevant Union harmonisation legislation: Regulation (EU) 2024/2847."

Common mistake: naming the regulation without its publication reference when other acts are also in play. See Article 28(3) below.

6. References to harmonised standards, common specifications or cybersecurity certification

Where you list what you applied to demonstrate conformity.

This is the field that will look thin in 2026, and that is fine. No CRA harmonised standard has yet been cited in the Official Journal, so for most manufacturers there is little or nothing to put here today. You may reference other standards you have applied, but be careful not to imply a presumption of conformity that does not yet exist. We track the state of play in CRA Harmonised Standards and the Presumption of Conformity.

Common mistake: listing a standard you partially applied as though you applied it in full. Presumption of conformity, once available, depends on full application.

7. Notified body details, where applicable

Name and number of the notified body, a description of the conformity assessment procedure performed, and identification of the certificate issued.

For the default class - roughly nine in ten products - this field is empty. Default products self-assess through internal control, with no notified body involved. It becomes relevant for Important Class II and critical products, and for Important Class I where you cannot fully apply a harmonised standard.

Common mistake: assuming a notified body is always required, and stalling the whole declaration waiting for one you do not need. Check your class first with the scope checker.

8. Additional information, and the signature block

Annex V closes with an "Additional information" field, followed by:

  • Signed for and on behalf of:
  • (place and date of issue):
  • (name, function) (signature):

Common mistake: an unnamed signature, or a date that predates the completion of the technical file. The date should be the date you were actually in a position to declare.

The simplified declaration most teams miss

Article 13(20) provides for a simplified EU declaration of conformity, with its model structure set out in Annex VI. Its wording begins:

"Hereby, ... [name of manufacturer] declares that the product with digital elements type ... [designation of type of product with digital element] is in compliance with Regulation (EU) 2024/2847."

It is accompanied by the internet address at which the full declaration can be obtained.

This is useful where space is genuinely constrained - small packaging, a compact quick-start leaflet, a product with no room for a full page of legal text. Two things to be clear about:

  • The simplified form does not replace the full Annex V declaration. You still draw that up, and you still make it available.
  • The address you publish must actually resolve, and must keep resolving. A dead link on a declaration is a formal non-compliance waiting to be found.

Article 28(2) applies the same language requirement to the simplified declaration as to the full one.

Languages

Article 28(2) requires the declaration to be made available in the languages required by the Member State in which the product is placed on the market or made available on the market.

The practical consequence for anyone selling across the EU is that this is a translation project, not a copy-and-paste. Which languages you need depends on where you sell and on each Member State's own requirements - a company shipping to seven countries may need seven versions, each of which has to be kept in step when the declaration is updated.

Two planning points that save pain later:

  • Keep the declaration short and factual so translation is cheap and low-risk. Everything discursive belongs in the technical file, not here.
  • Version the translations together. A declaration updated in English but not in the other six is worse than no update at all.

One declaration, several regulations

This is the section that saves most teams the most work.

Article 28(3): where a product is subject to more than one Union legal act requiring an EU declaration of conformity, a single EU declaration of conformity shall be drawn up in respect of all such acts[1], identifying the Union legal acts concerned including their publication references.

So if your connected product already carries a declaration under, say, the Radio Equipment Directive and the EMC Directive, you do not issue a second, separate CRA declaration. You extend the one you have: add Regulation (EU) 2024/2847 to the list of acts, with its publication reference, and add the CRA-relevant entries to fields 6 and 7.

For machine builders, the same logic applies across the Machinery Regulation and the CRA - worth reading alongside The Machinery Regulation Lands 11 Months Before the CRA.

Practically: find out who currently owns your DoC template. It is usually a quality or regulatory affairs function, not engineering. Get the CRA onto their roadmap rather than starting a parallel document.

Keeping it current

Article 28(2) says the declaration "shall be updated as appropriate". In practice the triggers are:

  • A substantial modification that re-opens conformity assessment. Where that line sits is covered in CRA Substantial Modification.
  • A change of legal entity name, address, or authorised representative.
  • Newly applied standards or specifications - which for most manufacturers means the first time a CRA harmonised standard is cited in the Official Journal and you adopt it.
  • A new or amended notified body certificate.
  • Adding a Member State with a different language requirement.

Build the check into an existing process. A release checklist item asking "does this change the DoC?" costs nothing and catches almost everything.

When this actually bites

The declaration, CE marking and technical documentation become enforceable on 11 December 2027[3]. The 11 September 2026 date that has dominated the last year concerns Article 14 reporting only. So no, you are not late.

But drafting it now is a genuinely useful exercise, because the declaration is a short document that can only be completed honestly if the work behind it exists. Try to fill in field 4 and you will discover whether you can actually pin your declaration to specific firmware versions. Try to fill in field 6 and you will find out where your standards position really is. Try to fill in the signature block and you will find out who is willing to sign.

That is the point. The DoC is a forcing function disguised as a form.

How to draft yours this week

  1. Find the existing template. Ask whoever owns your current CE declarations. Do not start a new document.
  2. Confirm your product class - default, Important Class I or II, or critical - so you know whether field 7 applies. Use the scope checker.
  3. Fill fields 1 to 5. These are facts you already have.
  4. Draft field 4 properly, including version or revision ranges. This is the field that takes real thought.
  5. Leave field 6 honest. Write what you have actually applied in full, and nothing more.
  6. List every EU act requiring a declaration for this product, with publication references, and consolidate under Article 28(3).
  7. Decide whether you need the Annex VI simplified form, and if so, publish the URL it will point to.
  8. Map your language requirements against the Member States you sell into.
  9. Identify the signatory by name and function - and tell them, before December 2027, that they will be signing.

Where to go next

{{component:callout|level=tip}} Annex V may grow. Under Article 28(5) the Commission can adopt delegated acts adding elements to the minimum content of the declaration to take account of technological developments. Subscribe to The CRA Brief and we will tell you if and when that happens. {{/component}}