EU product compliance · CRA · Machinery · CE marking

Know exactly what your product needs before it reaches the EU market

The technical file, the Declaration of Conformity, the risk assessment — explained clearly, then templated. For companies without a compliance department.

Free · about two minutes · no email needed to see your result

An Annex VII technical file assembling Eight labelled document sections stack into a single bound technical file. Product description Risk assessment Essential requirements SBOM Test reports Vulnerability handling Support period Declaration of Conformity Technical file CRA ANNEX VII · COMPLETE
CRA deadline
11 Dec 2027

Full application. Every product with digital elements.

Machinery deadline
20 Jan 2027

Regulation 2023/1230 replaces the old Directive. No grandfathering.

Products in scope
615,272

Of which 99.58% are small and medium enterprises.

Maximum penalty
€15m

Or 2.5% of worldwide turnover, whichever is higher.

02

Why this exists

The European Commission's own impact assessment estimates that self-assessing a single product against the Cyber Resilience Act costs about €18,400. Most of that is someone working out what the regulation actually asks for.

The regulations themselves enumerate what a technical file must contain — Annex VII for the CRA, Annex IV for machinery — but they never provide a template. That is deliberate: no single form fits both a smart doorbell and a CNC machine.

So every manufacturer builds the same document from scratch. We publish the explanation for free, and sell the structure so you do not start from a blank page.

Written from primary sources. Every regulatory page here cites EUR-Lex, the European Commission or the relevant standards body directly, and carries the date it was last reviewed. Regulations move — the AI Act's high-risk deadline has already slipped once.
03

What is not true

A great deal written about the CRA is wrong, and some of it is designed to frighten you. Three corrections worth having early:

You probably do not need a notified body

Default-category products — most business and consumer software, mobile apps, ordinary connected devices — use Module A self-assessment. You assess your own product and declare conformity. A notified body is only required for the Important Class II and Critical categories: operating systems, firewalls, antivirus, routers, smart cards.

No official template exists, and none is coming

The Commission published its first CRA guidance on 27 July 2026 — 67 practical examples and a set of flowcharts, but no fill-in forms. That matches twenty years of practice across the Machinery Directive, RED, LVD, EMC and the MDR: what that guidance actually says.

Nobody can make you compliant

Not us, not a consultant, not a piece of software. Compliance is a statement the manufacturer makes about its own product. What anyone else can do is tell you what is required, and give you a structure to work in.