Cenitia Library
Practical guides to EU regulatory compliance.
Engineering-grade explainers of the regulations every hardware product entering the EU market has to meet. No legal-pad jargon, no AI filler — written by the same team that built Cenitia.
62 guides across 12 topics
CE Marking & Conformity
4How CE marking actually works — the conformity-assessment routes, when a Notified Body is mandatory, and the mistakes that get products stopped at the border.
- referenceCRA, RED, LVD, EMC, MDR
Conformity assessment — selected routes under CRA, RED, machinery and MDR
Selected conformity-assessment routes and category checks under CRA, RED, machinery and MDR, with the evidence needed to justify the route for a product.
- referenceCRA, RED, LVD, EMC, RoHS
Common CE marking errors — scope, assessment and evidence
Common pitfalls in CE marking, representative mandates, assessment routes and regulatory penalties, with primary references and product-evidence checks.
- guideCRA, RED, MDR
When you need a Notified Body — the EU CE marking decision guide
Selected RED, CRA, machinery and MDR route conditions that can require a notified body, with classification and evidence checks for the actual product.
- guideCRA, RED, LVD, EMC, RoHS, MDR
CE Marking 101 — essential requirements and conformity evidence
A concise overview of RED marking and declaration rules, CRA declaration requirements, and the product evidence needed to support a manufacturer’s CE claim.
Declaration of Conformity
5What an EU Declaration of Conformity must contain, how to translate it, when to re-issue it, and how to sign it electronically.
- referenceeIDAS
eIDAS and Declarations of Conformity — signature claims and evidence
A concise overview of Cenitia’s signature record and its limits: issuance evidence does not establish a qualified eIDAS signature or product conformity.
- referenceCRA, RED, MDR
Declaration of Conformity translation requirements — every EU language explained
Separate declaration language, accompanying user information and authority requests; verify the applicable act and target Member State before translating.
- tutorialRED, RoHS, CRA
Sample Declaration of Conformity — annotated walkthrough with template
An unsigned RED and RoHS declaration worksheet for a fictional radio product, with fields that require actual configuration and assessment evidence.
- guideCRA, RED
Updating a Declaration of Conformity after a regulation amendment
When a cited EU regulation or harmonised standard is amended, the Declaration of Conformity may need to be reissued. This guide explains when, how, and what to retain.
- guideCRA, RED, LVD, EMC, RoHS
Declaration of Conformity 101 — what it is, who needs it, how it's signed
How to identify applicable EU declaration requirements, confirm product evidence, choose language and signatory, and retain an issued declaration.
Technical File & Risk Assessment
4The documentation behind the CE mark — what goes in the technical file, how long to keep it, and how to run a defensible risk assessment.
- referenceCRA, RED, MDR, LVD, EMC
Technical File retention requirements per EU directive
Selected documentation-retention and availability duties under CRA, MDR, RED and machinery legislation, with product-specific evidence and source references.
- guideCRA, MDR
Risk assessment for CE compliance — methodology overview and standards reference
How to document product-specific safety and cybersecurity risks, choose methods within their verified scope, and connect risk controls to conformity evidence.
- tutorialCRA, RED
Technical File for IoT devices — concrete template aligned with CRA and RED
An illustrative eight-part evidence folder for connected IoT products, with separate checks against applicable RED documentation and future CRA Annex VII duties.
- guideCRA, RED, MDR, LVD, EMC
Technical File 101 — documentation scope and evidence overview
A concise overview of technical documentation, selected CRA, RED and machinery duties, retention and the product evidence needed to support conformity.
Cyber Resilience Act (CRA)
10The EU Cyber Resilience Act end to end — Annex I requirements, product classes, the reporting clock, overlap with NIS2, and the 2026–2027 deadlines.
- tutorialCRA
Coordinated Vulnerability Disclosure Policy for Hardware Manufacturers
Build a usable hardware vulnerability disclosure policy with intake owners, safe testing boundaries and a security.txt example.
- referenceCRA
CRA for existing products already on the EU market: the Article 69 transitional rules
CRA Article 69 explained: grandfathering for products placed on the EU market before 11 December 2027, substantial modification test, Article 14 reporting carve-back.
- comparisonISO27001, CRA
ISO/IEC 27001 vs CRA — when to certify both
ISO/IEC 27001:2022 is an organisational ISMS standard; the EU Cyber Resilience Act is a product-level regulation. Where they overlap, where they don't, and why you need both.
- tutorialCRA
CRA December 2027 readiness — scope, assessment and evidence checks
Key checks before CRA main product obligations apply: legacy products and modifications, support and retention, assessment route, declaration and technical evidence.
- tutorialCRA
CRA ENISA reporting — early warnings, notifications and final-report triggers
A concise overview of CRA Article 14 reporting paths, 24-hour and 72-hour stages, different final-report triggers and evidence for an operational workflow.
- tutorialCRA
CRA reporting since September 2026 — workflow and evidence checks
Checks for CRA reporting now in force: platform access, accountable staff, escalation, legacy-product scope and the separate final-report triggers.
- referenceCRA
CRA Annex III important products — Class I and Class II explained
An overview of CRA Class I and Class II assessment routes and scope checks. Classify the actual product using Annex III and the applicable technical descriptions.
- comparisonCRA
CRA vs NIS2 — when both apply and how to handle the overlap
A concise overview of separate product-security, entity-security and personal-data reporting duties. Check CRA, NIS2 and GDPR applicability and national implementation.
- referenceCRA
CRA Annex I — cybersecurity requirements and evidence overview
An overview of CRA product security and vulnerability handling, linked manufacturer duties, reporting paths, retention and evidence for a product-specific assessment.
- guideCRA
CRA timeline and reporting obligations — September 2026, December 2027, and the 24-hour rule
CRA reporting has applied since 11 September 2026; main product obligations start 11 December 2027. Review the reporting stages, legacy transition and evidence.
Radio Equipment & EN 18031
6The RED cybersecurity delegated act and the EN 18031 harmonised standards — what the three parts cover, the radio conformity path, and where RED meets the CRA.
- tutorialCEMark, RED, EMC, RoHS
How to Verify CE Documents from an Electronics Supplier
Check product identity, declarations, test reports and supplier gaps before accepting CE evidence for an electronics order.
- referenceEN303645
ETSI EN 303 645 — the 13 consumer IoT controls explained
The 13 high-level provisions of ETSI EN 303 645 v2.1.1 (June 2020) and v3.1.3 (September 2024) explained, with the TS 103 701 conformance assessment mapping.
- referenceRED
RED Annex IV path: when radio equipment needs a Notified Body
RED Annex IV path — when radio equipment requires Notified Body full quality assurance (Module H), versus Module A self-assessment under Article 17(2).
- comparisonRED, CRA
RED and CRA overlap for connected radio products: 2025-2027 transition
RED cybersecurity and CRA scope for connected radio products: OJ coverage, assessment conditions, legacy transitions and the 2027 delegated-act repeal.
- referenceRED
EN 18031-1 vs -2 vs -3: which parts apply to your radio product
EN 18031-1, -2 and -3 compared: product scope, mechanism families, OJEU restrictions, notified body routes and the transition to CRA on 11 December 2027.
- guideRED, CRA
RED cybersecurity and EN 18031 — scope and assessment overview
An overview of RED cybersecurity scope, EN 18031 OJ restrictions, available assessment routes and evidence. Check the licensed standard for the actual test method.
SBOM & Software Supply Chain
4Software Bills of Materials for hardware — CycloneDX vs SPDX, tooling for embedded builds, how often to regenerate, and recovering an SBOM from legacy firmware.
- referenceCRA
SBOM for legacy embedded firmware: building one from binaries when source is gone
Build an SBOM for legacy embedded firmware from binaries — Binwalk extraction, Syft + Trivy scan, EMBA triage, and an honest residual-risk template for CRA Annex I Part II.
- referenceCRA
SBOM tooling for embedded systems: Syft, Trivy, Yocto SPDX and CycloneDX-generators compared
SBOM tools for embedded development compared — Syft, Trivy, Yocto create-spdx, CycloneDX-generators, EMBA — with a decision matrix and CRA Annex I Part II mapping.
- guideCRA
SBOM update frequency under CRA: release-based maintenance and historic retention
How often the SBOM must be updated under CRA Annex I Part II item (1) and Annex VII — release-based maintenance, historic version retention, and vulnerability monitoring cadence.
- guideCRA
SBOM for hardware manufacturers — CycloneDX vs SPDX practical guide
Practical SBOM guide for hardware manufacturers in 2026: CycloneDX vs SPDX format comparison, generation tooling, maintenance lifecycle, and CRA Annex I compliance.
EU Authorised Representative
4When a non-EU manufacturer needs an EU Authorised Representative (EC REP), what it costs, how it differs from an importer, and the software-product specifics.
- guideCRA, RED, MDR
EC REP cost guide 2026: what you pay, what you get, what to avoid
Cost guide for EU Authorised Representative services in 2026 by directive — CRA Article 18, RED Article 11, MDR Article 11 — what drives premium and how to verify a quote.
- guideCRA
EC REP for software products — CRA scope and representative mandates
CRA Article 18 permits a representative by written mandate. Check software and remote-data-processing scope, responsible operators and separate sector obligations.
- comparisonCRA, RED, MDR
EC REP vs Importer: Responsibilities Under CRA, RED, and MDR
EC REP vs Importer — the two distinct EU economic operator roles, their obligations under CRA, RED, MDR, and Regulation 2019/1020, and when one entity can be both.
- guideCRA, RED, MDR
EU Authorised Representative — scope and mandate overview
An overview of optional CRA representative mandates, the distinct MDR non-EU manufacturer rule, responsible-operator scope and documentation evidence.
Directives & Standards
8Per-directive and per-standard deep dives — EMC, Low Voltage, RoHS, Machinery, GPSR, and the harmonised standards that demonstrate conformity.
- referenceLVD
EN 62368-1 — safety for audio/video and ICT equipment
EN IEC 62368-1 (3rd ed., 2018) is the hazard-based safety standard replacing EN 60950-1 and EN 60065 — energy classes, safeguards, LVD presumption of conformity.
- referenceIEC62443, CRA, RED
IEC 62443 family overview for product manufacturers
Practical map of the IEC 62443 industrial cybersecurity standards — what -1-1, -2-1, -2-4, -3-2, -3-3, -4-1 and -4-2 cover, and which parts hardware manufacturers actually need.
- referenceEMC
EN 55032 and EMC — scope and conformity-evidence checks
A scope and evidence overview for EMC assessment: radio exclusion, assessment alternatives and checking the exact standard citation. No licensed limit tables are reproduced.
- referenceGPSR
General Product Safety Regulation 2023/988 — when it applies
Regulation (EU) 2023/988 GPSR applies from 13 December 2024, replacing Directive 2001/95/EC. Scope, traceability, online marketplaces, Safety Gate, recalls.
- referenceMachineryReg
Machinery Regulation 2023/1230 — transition from the Machinery Directive
The 20 January 2027 machinery transition: current Directive routes, replacement Regulation categories, documentation and evidence checks for affected products.
- guideEMC
EMC Directive 2014/30/EU — the complete guide
EMC Directive 2014/30/EU explained: scope, Annex I essentials, Modules A and B+C, technical file, EU DoC, CE marking, harmonised standards.
- referenceLVD
Low Voltage Directive 2014/35/EU — what it covers
Plain-English walk-through of the EU Low Voltage Directive 2014/35/EU: scope, voltage limits, safety objectives, Module A, technical file, DoC, harmonised standards.
- referenceRoHS
RoHS Directive 2011/65/EU — Annex II restricted substances
Annex II of RoHS 2 lists 10 restricted substances with maximum concentration values. The 2015 phthalate amendment, exemptions, and CE marking explained.
Product-Type Playbooks
4CE-marking playbooks for specific product categories — consumer IoT, industrial sensors, medical wearables, and AI-enabled hardware.
- guideAIAct, CRA, CEMark
CE marking AI-enabled hardware — CRA + AI Act overlap
A scope overview for AI-enabled hardware: updated high-risk application dates, category-specific assessment, and evidence needed alongside product legislation.
- guideCEMark, EMC, CRA, ATEX, LVD, RED, RoHS
CE marking for industrial sensors and gateways
Product-specific scope and evidence checks for industrial sensors and gateways: EMC, RED, RoHS, voltage limits, ATEX, machinery transition and CRA classification.
- guideMDR, CRA, RED
CE marking medical wearables — MDR scope, CRA exclusion and radio requirements
A concise overview of medical-device classification, non-EU representation, documentation and the MDR exclusion from CRA for in-scope medical wearables.
- guideCEMark, CRA, RED, EMC, LVD, RoHS, GPSR
CE marking for IoT consumer products — end-to-end
End-to-end CE marking process for consumer IoT — RED, EMC, LVD, RoHS, CRA (from 11 December 2027), and GPSR — sequenced from scope to vulnerability handling.
Country Guides
5National specifics that sit on top of the EU framework — Germany, France, Spain, Italy, and the UK’s post-Brexit UKCA mark.
- guideCEMark, GPSR
Italy — CE marking and Codice del Consumo
How CE marking works in Italy: MIMIT as competent authority, Italian-language requirements under Codice del Consumo, and Ministero della Salute's role.
- guideCEMark, LVD, EMC, RED
Spain — CE marking, language and MITECO requirements
Spanish CE marking rules — the key Reales Decretos that transpose LVD, EMC and RED, the castellano labelling requirement, MITECO environmental duties, and the legacy DIE regime.
- guideCEMark
France — CE marking and additional national obligations
France-specific add-ons to CE marking: DGCCRF market surveillance, Loi Toubon French-language documentation, Triman waste-sorting logo, AGEC law and REP eco-organisme registration.
- comparisonUKCA, CEMark
UKCA mark vs CE mark — post-Brexit clarity 2025-2026
How UKCA and CE marking actually work in Great Britain after the 2024 indefinite recognition decision — plus Northern Ireland UK(NI), construction, and medical device carve-outs.
- guideProdSG, GPSR, MarketSurveillance
Germany ProdSG and CE marking — what changes for the German market
How Germany's Produktsicherheitsgesetz (ProdSG 2021) interacts with CE marking: GS mark, BAuA, Länder market surveillance, and German-language obligations.
Research Tools
4How to read the primary sources yourself — CELEX numbers, EUR-Lex, the NANDO Notified Body database, and harmonised standards in the Official Journal.
- tutorialCEMark, CRA, RED, MDR
How to check NANDO for Notified Bodies
Step-by-step guide to NANDO — the Commission's public database of Notified Bodies. Search by Directive, by 4-digit ID, by country, and verify a quoted NB number on a DoC.
- tutorialCEMark, RED
How to find harmonised standards in the Official Journal
Tutorial: locate the current list of harmonised standards giving presumption of conformity in the OJEU, verify references, and read excluded clauses.
- tutorialEURLex
How to navigate EUR-Lex — find the consolidated version
Tutorial on EUR-Lex search, ELI URIs, CELEX numbers, and how to find the current consolidated version of an EU regulation plus subscribe to updates.
- tutorialEURLex, RED
How to read CELEX numbers — EUR-Lex navigation
Decode CELEX numbers like 32014L0053 (RED): sector code, year, document type, and number. Includes consolidated text identifiers and worked examples from EUR-Lex.
Trackers & Deadlines
4Living trackers we keep current — CRA enforcement countdown, harmonised-standards status, EN 18031 progress, and the quarterly Official Journal digest.
- referenceRED
EN 18031 — OJ citation, restrictions and assessment checks
An overview of RED cybersecurity scope, EN 18031 citation and restriction checks, assessment routes and the 2027 delegated-act transition.
- referenceCEMark, CRA, RED, EMC, LVD
Official Journal monitoring for hardware compliance — a quarterly review workflow
A practical workflow for tracking EU product legislation, OJ standards citations, restrictions and transition dates, with a review record for each affected product.
- guideCRA
CRA readiness countdown — scope, reporting, assessment and release checkpoints
Planning checkpoints before CRA main product obligations apply on 11 December 2027, with reporting already in force, class-specific routes and release evidence.
- referenceCRA
CRA harmonised standards — citation and assessment checks
How to check the role of harmonised standards in CRA assessment: exact citation, requirement coverage, route conditions and evidence. This is not a live OJ ledger.