This document is under active development and has not been finalised.
Skip to content

Chapter 9: Product Compliance Publication

Overview

The CRA requires manufacturers to make extensive compliance information publicly accessible. The EU Declaration of Conformity, user information, the support period, and the Vulnerability Disclosure Policy must be available to customers, authorities, and the public.

This chapter describes how each software product publishes its CRA compliance artefacts as a consolidated public compliance statement — and how this process is standardised and automated across all products.

LEGAL BASIS

Art. 13 CRA: "The manufacturer shall ensure that the product is accompanied by the information set out in Annex II."

Art. 28(3) CRA: "The manufacturer may include with the product a simplified EU declaration of conformity as set out in Annex VI, provided that the full version is made available online."

Art. 29 CRA: The CE marking shall be affixed to the product or its accompanying documents before the product is placed on the market.

Why a Public Compliance Page?

ReasonExplanation
Regulatory obligationArt. 13 and Art. 28 CRA require public access to the Declaration of Conformity and user information
Market surveillanceAuthorities must be able to inspect compliance information (Art. 52–58 CRA)
Customer trustB2B customers expect demonstrable compliance documentation
Market advantageProactive compliance signals maturity and professionalism
StandardisationA uniform format across all products simplifies maintenance and auditing

Distinction from Chapter 7

AspectChapter 7: Conformity AssessmentChapter 9: Compliance Publication
FocusHow is conformity assessed?How is it publicly presented?
OutputEU Declaration of Conformity (Annex V)Public product compliance page
AudienceManufacturer, notified bodiesCustomers, authorities, public
TimingBefore placing on the marketThroughout entire product lifecycle

Additional Regulatory Notes

NOTE FOR AI PRODUCTS

Products containing AI components are additionally subject to the EU AI Act (Regulation (EU) 2024/1689). AI Act compliance is covered in separate documentation. The CRA Compliance Statement (→ 9.1) covers CRA requirements only.

Chapter Structure

SectionTopicDescription
9.1CRA Compliance StatementRequired content, structure, and example of a product-specific compliance statement
9.2Publication StrategyDual concept: repository as source of truth, website as public presentation
9.3Machine-Readable FormatJSON schema for cra-statement.json and CI/CD validation
9.4Maintenance & UpdatesUpdate triggers, review cycle, responsibilities

→ Fillable template: A.9 CRA Compliance Statement

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT