The CRA Declaration of Conformity is not a rebranded CE Declaration from another directive. It must state that the product meets the essential cybersecurity requirements of Annex I of Regulation (EU) 2024/2847 — not the safety requirements of 2014/35/EU or the radio requirements of 2014/53/EU. Article 28(3) allows a single Declaration to cover the CRA and other Union legal acts, but the CRA must be cited explicitly with its publication reference. Annex V lists 8 elements that must appear. CRACheck fills every field based on your input and the conformity assessment module identified by the Product Classifier. €149 per product. 15–25 minutes. The Declaration is one of 8 PDFs in the dossier.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
Article 28(3) allows a single Declaration to cover the CRA and other Union legal acts, but the CRA must be cited explicitly. A Declaration that references 2014/35/EU (LVD) or 2014/53/EU (RED) without also citing Regulation (EU) 2024/2847 does not satisfy the CRA requirement.
Annex V element 5 requires a statement that the product is in conformity with the relevant Union harmonisation legislation. Under the CRA, this means conformity with the essential cybersecurity requirements of Annex I. A generic "complies with all applicable EU legislation" without citing Annex I of Regulation (EU) 2024/2847 is insufficient.
If your product requires Module B+C or Module H assessment under Article 32(3), Annex V element 7 requires the notified body name, number, and identification of the certificate issued. A Declaration without this reference is incomplete for any product that went through third-party assessment.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Identifies the CRA category and the conformity assessment module that the Declaration of Conformity will reference.
Annex VII file. Annex VII point (7) requires a copy of the Declaration in the technical documentation — CRACheck cross-references them.
Cybersecurity risk assessment per Article 13(2)–(3). The risk assessment underpins the conformity claim in the Declaration.
Annex II information sheet with the Declaration of Conformity link (Annex II point 6).
EU Declaration per Article 28 and Annex V. All 8 elements pre-filled from your input. Ready-to-sign PDF.
Coordinated vulnerability disclosure policy per Annex I Part II point (5).
ENISA/CSIRT notification template per Article 14. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.
Key dates including the 10-year retention obligation for the Declaration.
See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.
Generated from your data, in your browser. No data leaves your device.