Skip to content
Inovasense

CE Marking

CE marking is required only for products covered by EU legislation that specifically mandates it.

Author:
Inovasense Team
Updated:
Definition
CE marking is required only for products covered by EU legislation that specifically mandates it.

Scope of CE marking

CE marking is required only for products covered by EU legislation that specifically mandates it. It is the manufacturer’s declaration of conformity, not a general quality approval. A product outside those regimes must not carry CE merely because it is sold in Europe. The assessment route, declaration, marking placement and retention rules depend on the applicable product law.

Available assessment procedures

The framework in Decision 768/2008/EC does not make every module available under every directive. LVD uses internal production control (A). EMC offers A or B+C. RED offers A, B+C in Annex III or full quality assurance (H) in Annex IV, subject to Article 17. MDR uses its own sector-specific procedures. Always check the law and product category before selecting a route.

Radio equipment and other legislation

For radio equipment within RED, the safety objectives of LVD and the EMC requirements are incorporated through RED Article 3(1); the radio equipment does not automatically require separate LVD and EMC declarations. A separately supplied power supply may have its own assessment. Delegated Regulation 2022/30 activates different scopes for network protection, privacy and fraud protection; not every radio meets all three scope tests.

CRA scope and application dates

The CRA entered into force on 10 December 2024. Article 14 reporting has applied since 11 September 2026; the main product requirements apply from 11 December 2027. Article 69 contains transitional rules for previously placed products. Products subject to MDR or IVDR are excluded under Article 2(2); other exclusions and non-commercial free/open-source scope must also be checked.

CRA: requirements and engineering choices

CRA requirements are outcome-oriented and technology-neutral, based on the product’s cybersecurity risk assessment and applicability. Secure boot, a hardware root of trust, TPM, TrustZone and wireless OTA can be appropriate engineering controls; they are not universal legal mandates for every product. Document why the chosen controls satisfy the applicable requirements rather than equating one architecture with compliance.

Support, updates and SBOM

CRA Annex I requires applicable secure vulnerability-handling and update mechanisms. Automatic security updates have conditions and exceptions; automatic does not mean wireless. The support period is determined under Article 13(8), normally at least five years; where expected use is shorter, it corresponds to that use, while longer-use factors can require longer support. An SBOM must be machine-readable and cover at least top-level dependencies.

Practical checklist

  1. Identify the product, intended use, market and applicable legal scope.
  2. Record the exact legal provisions, dates and applicable standard editions, including restrictions.
  3. Select the permitted assessment route and document the evidence needed.
  4. Link risk assessment, tests, product versions and declarations in the technical documentation.
  5. Assign responsibility for changes, support and responses to authorities.

This checklist supports planning; the applicable legal requirements determine the final assessment.

Primary sources

Related Terms