Most manufacturers assume a CE mark means an EU authority tested their product and found it safe. It does not. Under the CRA, the mark is a declaration you sign yourself: a statement that your product, and the way you build and maintain it, meet the CRA's cybersecurity requirements. For most products, nobody from the EU ever looks at the device. You assess it, you document it, and you put your name on it.

That matters, because the responsibility stays with you. There is no authority standing behind you who "approved" anything. If the declaration turns out to be wrong, and the product does not actually meet the requirements, you face fines of up to €15 million or 2.5 percent of worldwide turnover, whichever is higher, and your product can be pulled off the market. Problems with the paperwork alone, a missing or faulty declaration, or a mark applied incorrectly, sit one tier lower at €10 million or 2 percent.

For the full regulation, see our complete guide to the EU Cyber Resilience Act.


What the mark certifies

CE marking indicates that a product, and the manufacturer's processes behind it, conform to the essential cybersecurity requirements of the CRA and to any other EU harmonisation legislation that applies to it. It goes on only after two things have happened: you have completed a conformity assessment, and you have signed the EU Declaration of Conformity. The mark comes last, not first.

For roughly 90 percent of products, the ones in the Default category, that assessment is something you do yourself. You check your product against the requirements and sign the declaration. Nobody outside your company is involved. Important and Critical products face a stricter path, which we cover in our guide to CRA product classification. Right now that stricter path catches more products than the category names suggest: no harmonised standard exists yet for any product type, so everything above Default has to go through an external assessor, not just Class II and Critical.

One detail people skip: not every product needs a CE mark. Only products covered by EU harmonisation legislation carry one, and the CRA and RED are two examples. Putting the mark on a product that nothing covers is not a harmless decision. It is a false declaration. The mark makes a specific legal claim, and it is not decorative.


The RED question

This is where the "CE marking is for radio devices, CRA is for everything else" assumption comes from. If your device has Bluetooth, Wi-Fi, or cellular, you probably already deal with CE marking under the Radio Equipment Directive, and RED has had cybersecurity requirements since 1 August 2025.

The natural next thought is that RED covers radio devices and the CRA covers everything else, so you end up with two marks. That is not how it works. There is one CE mark. The CRA's own definition says the mark covers its requirements plus any other EU legislation that applies to the product. So if your device has a radio and digital elements, both sets of rules apply to the same physical device, one mark has to be backed by both, and you write one Declaration of Conformity covering both.

The CRA expects this overlap to get tidied up eventually. Its recitals note that the CRA's requirements already include everything RED asks for on cybersecurity, and that the RED rules were expected to be narrowed or dropped for products the CRA covers. That has not happened yet. Until it does, a connected device with a radio has to satisfy both at once.

RED is further along: its standards already exist. EN 18031-1, -2 and -3 are published, and they work on a simple principle. Meet the standard, and you are treated as having met the law. That is what "presumption of conformity" means, and it is worth real money: you prove nothing further, you assess the product yourself, and no external body is involved.

The Commission attached three exceptions when it published them:

  • you let the user skip setting a password;
  • you have a toy or a childcare device with no parental access control (this one applies to EN 18031-2);
  • you need the secure update criteria from EN 18031-3, which the Commission struck out completely, so they work for nobody.

Fall into any of those three and the rule stops applying to you. You have to demonstrate conformity on your own, and that means a notified body: money and months.

The CRA does not even have that yet. No standards at all. The earliest are not due until August 2026.


When it becomes mandatory

The CRA entered into force on 10 December 2024, and it is tempting to read that as the start date for everything in it. It is not. The dates are staggered:

  • 11 June 2026 - the rules for appointing the bodies that will carry out external assessments.
  • 11 September 2026 - Article 14, the vulnerability and incident reporting obligation.
  • 11 December 2027 - everything else, including the security requirements themselves and the CE marking obligation.

Until December 2027 you are not legally required to have done a conformity assessment or to be carrying a CRA CE mark. The one obligation that bites earlier is reporting, and it reaches further than people expect: it applies to products you sold before that date, not just new ones.

None of this is a reason to wait. The standards that will eventually let you claim presumption of conformity do not exist yet. The Commission has given the European standards bodies until August 2026 for the two main general standards, October 2026 for all 26 product-specific ones, and October 2027 for the remaining 13 general ones. Those are deadlines to finish writing the standards, not to publish them, and presumption of conformity only starts once the Commission publishes the reference. External assessors are in the same state. They could not be appointed at all before June 2026, and the CRA only asks Member States to have enough of them in place by December 2026, so that capacity is still being built. Building now, without a finished standard to tick off against, tends to produce a better product than waiting for the paperwork and then scrambling.


Getting there

Worked from the start, the path to a CE mark looks like this.

  1. Risk assessment first. Everything the CRA asks for downstream is scaled to what your risk assessment finds, so this is not something you write up at the end.
  2. Design and build against the requirements. Secure by design, secure by default, with the specific controls chosen based on what your risk assessment says is appropriate for your product. It is not a fixed checklist.
  3. Work out your category, then do the matching assessment. Default: assess it yourself. Important Class I: assess it yourself against a harmonised standard, or use an external assessor where no standard exists. Important Class II: external assessment, mandatory. Critical: in principle an EU cybersecurity certificate, but only once the Commission has required one and a scheme exists to issue it. Neither exists yet, so Critical products currently take the same route as Class II.
  4. Compile the technical documentation. Product description, risk assessment, standards applied, test results, and the SBOM where relevant.
  5. Sign the EU Declaration of Conformity. You sign it yourself. Nothing is filed with any authority. You keep it, ship a copy or a short version with a link, and produce the full one if a market surveillance authority asks.
  6. Affix the CE mark. On the product. If that is not possible, on the packaging and on the declaration. Visible, legible, and permanent.

What this means for a smaller manufacturer

None of the CRA's obligations shrink because you are small. The requirements, the documentation, the reporting deadlines are the same whatever your headcount. What changes is mostly procedural. Micro and small companies will be able to use a simplified documentation format once the Commission issues one, and they are not fined for missing the 24-hour early warning deadline, though they are still expected to report promptly. Fees for external assessment also have to be scaled to smaller companies.

For most manufacturers we talk to, the hard part is not the marking step. It is not having the security architecture, documentation, or risk assessment that the mark is supposed to attest to. That is engineering time, not paperwork time. If you want a read on where your product sits today, our CRA Readiness Check is a place to start.


FAQ

Does a CE mark mean the EU tested my product? No. For roughly 90 percent of products, the mark rests entirely on your own assessment, and nobody from the EU looks at the product first. Only products above the Default category need an external assessor, and since no harmonised standard exists yet, that currently means all of them.

My device already has a CE mark under RED. Do I need a second one for the CRA? No. It is the same mark. What changes is what stands behind it: one Declaration of Conformity now has to cover both RED and the CRA.

Can I get CE marking under the CRA right now? You can prepare, but there is no harmonised standard to assess against yet, and the marking obligation does not apply until 11 December 2027. What you can do now is build the risk assessment, architecture, and documentation the assessment will eventually need.

What if I put a CE mark on a product that does not need one? It counts as a false declaration of conformity, not a harmless label. Only products covered by EU harmonisation legislation carry the mark, and the CRA and RED are two examples.


Sources: CRA Regulation (EU) 2024/2847 - Annex I, Articles 14, 28, 30, 32, 64 and 71; delegated regulation (EU) 2022/30 supplementing the Radio Equipment Directive; Commission Implementing Decision (EU) 2025/138 on EN 18031; CONFIRMATE Project - CRA Compliance Guide for SMEs, Section 5.3


Valentyna Shulga is the co-founder and CEO of Platanor Technologies. Platanor designs and implements the security architecture and documentation IoT and hardware manufacturers need to work toward CRA and RED requirements. platanor.com/contact