Skip to content
Inovasense

Conformity Assessment

Conformity assessment is the process of demonstrating that a product meets applicable requirements.

Author:
Inovasense Team
Updated:
Definition
Conformity assessment is the process of demonstrating that a product meets applicable requirements.

Conformity assessment is the process of demonstrating that a product meets applicable requirements. The permitted procedure depends on the legislation and product category; a laboratory report is one form of evidence, not a substitute for the complete procedure.

Available assessment procedures

The framework in Decision 768/2008/EC does not make every module available under every directive. LVD uses internal production control (A). EMC offers A or B+C. RED offers A, B+C in Annex III or full quality assurance (H) in Annex IV, subject to Article 17. MDR uses its own sector-specific procedures. Always check the law and product category before selecting a route.

Standards and their limits

Harmonised standards are generally voluntary. Applying an OJ-cited standard can provide a presumption of conformity only for the requirements it covers and subject to published restrictions. Under RED Article 17, missing or partly applied relevant standards for Article 3(2)/(3) require B+C or H for those requirements. Standards, accredited test laboratories and notified bodies have different roles.

The declaration and responsibility

The EU declaration of conformity is issued under the manufacturer’s responsibility, including when a notified body participates. Use the applicable legal model, identify the product and manufacturer, cite applicable legislation and specifications, and include the authorised signatory and any required notified-body reference. An authorised representative acts within a written mandate. Language and provision to users are law- and market-specific.

CRA product classification

CRA classification follows core functionality, Annexes III/IV and the technical descriptions in Regulation 2025/2392. Operating systems are important Class I; Class II includes firewalls/IDS/IPS, specified hypervisors/container runtimes and tamper-resistant microprocessors/microcontrollers. Smartcards and similar devices, including secure elements, are critical categories. Integrating such a component does not automatically give the complete product its category. Article 32 defines the applicable assessment routes.

Practical checklist

  1. Identify the product, intended use, market and applicable legal scope.
  2. Record the exact legal provisions, dates and applicable standard editions, including restrictions.
  3. Select the permitted assessment route and document the evidence needed.
  4. Link risk assessment, tests, product versions and declarations in the technical documentation.
  5. Assign responsibility for changes, support and responses to authorities.

This checklist supports planning; the applicable legal requirements determine the final assessment.

Primary sources