Conformity Sheet
Every category · Consumer electronics · connected product

Speaker, soundbar or headphones

Bluetooth makes it radio equipment, and a rechargeable cell makes it a battery product too. Headphones that connect to an app are in scope of the CRA as products with digital elements.

Regimes

Regimes engaged, per market

Standing when pasted with its name: mapped

EUGPSRCRAREDRoHSREACHWEEE
UKUK GPSRUKCAUK PSTIUK RadioUK RoHSUK REACHUK WEEE
USCPSCFCC Part 15UL/NRTLProp 65
Documents

What the file has to hold

After sale

Duties that continue after sale

This week

This week

Check whether the battery cell has a UN 38.3 test summary and whether the Bluetooth module's certification is in the vendor's name or yours.

Licensed text

What holding one is evidence for

Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable.

GPSR: EU General Product Safety Regulation (Regulation (EU) 2023/988)
GPSR Art.9 Obligations of manufacturers (Article 9)

Article 9 imposes the central manufacturer obligations: (a) carry out internal risk analysis and draw up technical documentation containing the analysis + identification of relevant European standards or risk-assessment elements (kept for 10 years); (b) place safe products on the market that comply with Article 5 + Art...

Evidence an inspector accepts: Risk analysis + technical documentation per Article 9(2) retained for 10 years; Traceability markings (type/batch/serial) on each product; Single point of contact for safety queries published
Common gap: Product placed on market without Article 9(2) risk analysis + technical documentation
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
GPSR Art.5, 6, 7, 8 General safety requirement and assessment criteria (Articles 5-8)

Article 5 establishes the general safety requirement: economic operators shall place or make available on the market only safe products. Article 6 sets the criteria for assessing safety: the characteristics of the product including its composition, packaging, instructions for assembly and, where applicable, installatio...

Evidence an inspector accepts: Article 6 product-safety assessment file covering all enumerated criteria; Vulnerable-consumer impact assessment (children + older + disabled); Article 6(h) cybersecurity-as-safety analysis where the product's cybersecurity has a bearing on safety (separate from CRA - CRA covers cybersecurity per se, GPSR covers safety dimension)
Common gap: Placing on market without an Article 6 assessment file
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
GPSR Art.10, 11, 12 Authorised representatives, importers and distributors (Articles 10-12)

Article 10 governs authorised representatives (written mandate; tasks include keeping the EU declaration / technical documentation available for 10 years + cooperation with market surveillance). Article 11 sets importer obligations: place safe products + verify Article 9 manufacturer compliance + place importer identit...

Evidence an inspector accepts: Authorised-representative written mandates where the entity acts for a non-EU manufacturer; Importer pre-placing verification checklist; Distributor due-care procedure
Common gap: Non-EU manufacturer placing products without an authorised representative + responsible person in the Union (Article 16)
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
GPSR Art.13, 16 Cases where manufacturer obligations apply to other persons + responsible person in the Union (Articles 13 and 16)

Article 13 provides that an importer, distributor or other economic operator is considered to be a manufacturer + subject to Article 9 obligations where the operator places on the market under its own name or trademark, modifies the product in a way that may affect compliance with Article 5, or carries out other Articl...

Evidence an inspector accepts: Substantial-modification policy aligned with Article 13(2); Article 16 responsible-person designation evidence for each non-EU manufacturer the entity represents + identification on the product / packaging; Fulfilment service provider as Article 16 responsible person where applicable
Common gap: Non-EU manufacturer placing products on the Union market without an Article 16 responsible person
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
CRA: EU Cyber Resilience Act
CRA Art.2 Scope - Products with Digital Elements (Article 2)

Article 2 sets the scope: the Regulation applies to PDEs whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Carve-outs include: products covered by sector-specific Union law (medical devices under MDR/IVDR, motor vehicles under ...

Evidence an inspector accepts: Scope-determination matrix for each product (PDE category, applicable sectoral carve-out if any, FOSS-steward boundary); CRA-vs-sector-Regulation precedence analysis
Common gap: Applying CRA to a medical-device PDE that is in fact governed by MDR cybersecurity requirements (sectoral carve-out applies)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.13, Annex I Manufacturer obligations and essential requirements (Article 13 + Annex I)

Article 13 imposes the central manufacturer obligations: (1) design, develop and produce the PDE to ensure an appropriate level of cybersecurity based on the cybersecurity risk assessment in Article 13(2); (2) Article 13(6) due diligence on third-party components integrated in the PDE including FOSS dependencies; (3) A...

Evidence an inspector accepts: Cybersecurity risk assessment per Article 13(2) for each PDE; Third-party component due-diligence file per Article 13(6) including SBOM and FOSS-component analysis; Documented support period per Article 13(8) communicated to users and tracked operationally
Common gap: No documented support period or support-period shorter than the product's reasonably expected lifecycle
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.31 Technical documentation (Article 31 + Annex VII)

Article 31 requires the manufacturer to draw up the technical documentation for the PDE before it is placed on the market and to keep it up to date during the support period. The technical documentation contains the items in Annex VII: general description, design and manufacturing of the product including risk assessme...

Evidence an inspector accepts: Technical-documentation file aligned with Annex VII; 10-year retention plan; Microenterprise / SME simplified-documentation reliance where applicable (Annex VI)
Common gap: Technical documentation lacking Annex VII items (e.g. no SBOM, no risk assessment)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.27, 28 Presumption of conformity and EU declaration of conformity (Articles 27-28)

Article 27 establishes a presumption of conformity for PDEs that conform with: (a) harmonised standards or parts thereof published in the Official Journal; (b) European cybersecurity certification schemes adopted under (EU) 2019/881 designating the schemes as offering presumption of conformity with all or part of the e...

Evidence an inspector accepts: EU declaration of conformity for each PDE per Annex V; Mapping of relied-upon harmonised standards or European cybersecurity certification schemes
Common gap: EU declaration of conformity missing Annex V required content
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.32 Conformity assessment procedures (Article 32)

Article 32 sets the conformity assessment routes: (1) Default PDE - Module A (internal production control - self-assessment by the manufacturer); (2) Important PDE Class I (Annex III Class I) - Module A if the manufacturer applies harmonised standards or European cybersecurity certification, otherwise Module B+C (EU ty...

Evidence an inspector accepts: Conformity-assessment route selection record per PDE class; Module B+C / Module H notified-body engagement evidence; EUCC certification engagement evidence for Critical PDEs
Common gap: Self-assessment (Module A) for an Important Class II or Critical PDE
EU Cyber Resilience Act on compliance.theartofservice.com
CPSC: US Consumer Product Safety Commission (CPSC) requirements, including connected product safety
CPSC RA.3 Lifecycle Risk Assessment

Risk analysis must cover every stage of the product lifecycle including software updates and end-of-life scenarios.

Evidence an inspector accepts: Software update and remote update security plan; Recall plan for connected products; Section 15(b) incident reporting procedure
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.3 Voluntary Standards Participation

Manufacturers should participate in development of voluntary safety standards with UL, ASTM, and other bodies.

Evidence an inspector accepts: Recall plan for connected products; Connected product hazard analysis and FMEA; Section 15(b) incident reporting procedure
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 1 Section 15(b) Substantial Product Hazard Reporting

Per US Consumer Product Safety Act Section 15(b): Substantial Product Hazard Reporting to CPSC within 24 hours of obtaining information including cybersecurity hazards.

Evidence an inspector accepts: CPSC evidence for USCPSC-1
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 3 Recall, Corrective Action, SaferProducts.gov

Per CPSC: Voluntary Recall Notice + Corrective Action Plan + SaferProducts.gov Complaint Monitoring.

Evidence an inspector accepts: CPSC evidence for USCPSC-3
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.1 Network Security for Connected Products

Connected products must implement security measures to prevent network-based attacks that could cause physical harm.

Evidence an inspector accepts: Software update and remote update security plan; Section 15(b) incident reporting procedure; Recall plan for connected products
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.4 Vulnerability Disclosure

Manufacturers should establish vulnerability disclosure programmes for security issues affecting product safety.

Evidence an inspector accepts: End-of-life and end-of-support safety communications; Recall plan for connected products; Cybersecurity assessment against UL 2900-1
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.3 Remote Update Security

Remote software update mechanisms must ensure integrity and authenticity of updates per UL 5500 guidance.

Evidence an inspector accepts: Recall plan for connected products; Connected product hazard analysis and FMEA; Section 15(b) incident reporting procedure
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 2 Connected Product Cybersecurity Hazard Identification

Per CPSC + NIST IR 8425: Connected Product Cybersecurity Hazard Identification + risk assessment + alignment with NIST + secure default configuration.

Evidence an inspector accepts: CPSC evidence for USCPSC-2
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com

Do this for every product you sell

Paste the list and get this classification for every product at once, per market, with the documents held and missing, the after-sale duties and the findings. Five products free, no account.

Build my conformity sheet

Printer or scanner · Television or monitor