EU product compliance · CRA · Machinery · CE marking
Know exactly what your product needs before it reaches the EU market
The technical file, the Declaration of Conformity, the risk assessment — explained clearly, then templated. For companies without a compliance department.
Free · about two minutes · no email needed to see your result
- CRA deadline
- 11 Dec 2027
- Machinery deadline
- 20 Jan 2027
- Products in scope
- 615,272
- Maximum penalty
- €15m
Full application. Every product with digital elements.
Regulation 2023/1230 replaces the old Directive. No grandfathering.
Of which 99.58% are small and medium enterprises.
Or 2.5% of worldwide turnover, whichever is higher.
Start where you are
Cyber Resilience Act
Any product with digital elements sold in the EU needs an Annex VII technical file by 11 December 2027. Most self-assess — no notified body required.
Read the guide → Regulation (EU) 2023/1230Machinery Regulation
Replaces the Machinery Directive on 20 January 2027. If you modify machines substantially, you may now count as a manufacturer.
Read the guide → Cross-regulationWhat is a technical file?
The single document nearly every EU product rule demands — under a different annex number each time. One explanation that covers them all.
Read the guide →Why this exists
The European Commission's own impact assessment estimates that self-assessing a single product against the Cyber Resilience Act costs about €18,400. Most of that is someone working out what the regulation actually asks for.
The regulations themselves enumerate what a technical file must contain — Annex VII for the CRA, Annex IV for machinery — but they never provide a template. That is deliberate: no single form fits both a smart doorbell and a CNC machine.
So every manufacturer builds the same document from scratch. We publish the explanation for free, and sell the structure so you do not start from a blank page.
What is not true
A great deal written about the CRA is wrong, and some of it is designed to frighten you. Three corrections worth having early:
You probably do not need a notified body
Default-category products — most business and consumer software, mobile apps, ordinary connected devices — use Module A self-assessment. You assess your own product and declare conformity. A notified body is only required for the Important Class II and Critical categories: operating systems, firewalls, antivirus, routers, smart cards.
No official template exists, and none is coming
The Commission published its first CRA guidance on 27 July 2026 — 67 practical examples and a set of flowcharts, but no fill-in forms. That matches twenty years of practice across the Machinery Directive, RED, LVD, EMC and the MDR: what that guidance actually says.
Nobody can make you compliant
Not us, not a consultant, not a piece of software. Compliance is a statement the manufacturer makes about its own product. What anyone else can do is tell you what is required, and give you a structure to work in.
Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.