Conformity Sheet
Every category · Industrial equipment · connected product

CNC machine or machine tool

Machine tools have dedicated safety standards, guarding and control system requirements, and networked controllers that bring the CRA in; presses sit on the EU high-risk list.

Regimes

Regimes engaged, per market

Standing when pasted with its name: mapped

EUMachinery RegEMCRoHSREACHWEEECRA
UKUK MachineryUKCAUK EMCUK RoHSUK REACHUK WEEE
USOSHA/ANSIUL/NRTLFCC Part 15
Documents

What the file has to hold

After sale

Duties that continue after sale

This week

This week

Check the control system performance level claimed in the file against the standard the risk assessment names.

Licensed text

What holding one is evidence for

Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable.

Machinery Reg: EU Machinery Regulation (Regulation (EU) 2023/1230)
Machinery Reg Art.10 Obligations of manufacturers of machinery and related products (Article 10)

Article 10 imposes the central manufacturer obligations: (a) ensure the EHSR Annex III compliance + carry out risk assessment per Annex III 1; (b) draw up the technical documentation per Annex IV + retain for 10 years; (c) carry out the applicable conformity assessment procedure (Article 25); (d) draw up the EU declara...

Evidence an inspector accepts: Annex IV technical documentation per machine retained 10 years; Risk assessment + design + commissioning file aligned with Annex III; Article 21 EU DoC + Article 23-24 CE marking artwork
Common gap: Machine placed without Annex IV technical documentation
EU Machinery Regulation (Regulation (EU) 2023/1230) on compliance.theartofservice.com
Machinery Reg Art.8, 9 Essential health and safety requirements and sectoral coordination (Articles 8-9 + Annex III)

Article 8 imposes the central requirement: machinery and related products placed on the market or put into service shall comply with the essential health and safety requirements (EHSR) set out in Annex III. Annex III covers: 1.1 general principles of safety integration (eliminate / reduce / inform), 1.1.9 protection ag...

Evidence an inspector accepts: Annex III EHSR compliance file per product (risk assessment + design measures + residual-risk warnings); Annex III 1.1.9 cybersecurity-as-safety analysis (protection against unauthorised connections / software modifications); Annex III 1.2.6 AI / autonomous-behaviour safety analysis for AI-integrating machinery
Common gap: Product placed without Annex III EHSR compliance file
EU Machinery Regulation (Regulation (EU) 2023/1230) on compliance.theartofservice.com
Machinery Reg Art.21, 22 EU declaration of conformity and EU declaration of incorporation (Articles 21-22)

Article 21 requires the manufacturer to draw up the EU declaration of conformity per Annex V before placing on the market or putting into service. By drawing up the EU DoC the manufacturer assumes responsibility for compliance. The EU DoC is kept for 10 years. Article 22 sets the EU declaration of incorporation for par...

Evidence an inspector accepts: EU DoC per machine aligned with Annex V; EU DoI per partly completed machinery aligned with Annex XI; 10-year retention plan
Common gap: Machine placed without EU DoC
EU Machinery Regulation (Regulation (EU) 2023/1230) on compliance.theartofservice.com
Machinery Reg Art.23, 24 CE marking principles and affixing rules (Articles 23-24)

Article 23 applies the general principles of the CE marking per Regulation (EC) 765/2008 to machinery. Article 24 sets the affixing rules: CE marking visible, legible, indelible, affixed before placing on the market; for high-risk products subject to Annex I requiring notified-body assessment, the NB identification num...

Evidence an inspector accepts: CE marking artwork + placement evidence; NB identification number alongside CE marking for high-risk Annex I products; Partly completed machinery NOT marked with CE
Common gap: CE marking on partly completed machinery
EU Machinery Regulation (Regulation (EU) 2023/1230) on compliance.theartofservice.com
Machinery Reg Art.25 Conformity assessment procedures (Article 25)

Article 25 sets the conformity assessment routes. (1) Default (non-Annex-I): manufacturer self-assessment via Annex VIII (internal production control) + Annex IV technical documentation. (2) Annex I high-risk products: mandatory third-party involvement. The manufacturer chooses among Annex IX (EU type-examination + pro...

Evidence an inspector accepts: Route selection record per machine class; Notified-body engagement evidence for Annex I products; Annex VIII / IX / X / XI procedural records
Common gap: Annex I (Class B) product self-declared without notified-body involvement
EU Machinery Regulation (Regulation (EU) 2023/1230) on compliance.theartofservice.com
CRA: EU Cyber Resilience Act
CRA Art.2 Scope - Products with Digital Elements (Article 2)

Article 2 sets the scope: the Regulation applies to PDEs whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Carve-outs include: products covered by sector-specific Union law (medical devices under MDR/IVDR, motor vehicles under ...

Evidence an inspector accepts: Scope-determination matrix for each product (PDE category, applicable sectoral carve-out if any, FOSS-steward boundary); CRA-vs-sector-Regulation precedence analysis
Common gap: Applying CRA to a medical-device PDE that is in fact governed by MDR cybersecurity requirements (sectoral carve-out applies)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.13, Annex I Manufacturer obligations and essential requirements (Article 13 + Annex I)

Article 13 imposes the central manufacturer obligations: (1) design, develop and produce the PDE to ensure an appropriate level of cybersecurity based on the cybersecurity risk assessment in Article 13(2); (2) Article 13(6) due diligence on third-party components integrated in the PDE including FOSS dependencies; (3) A...

Evidence an inspector accepts: Cybersecurity risk assessment per Article 13(2) for each PDE; Third-party component due-diligence file per Article 13(6) including SBOM and FOSS-component analysis; Documented support period per Article 13(8) communicated to users and tracked operationally
Common gap: No documented support period or support-period shorter than the product's reasonably expected lifecycle
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.31 Technical documentation (Article 31 + Annex VII)

Article 31 requires the manufacturer to draw up the technical documentation for the PDE before it is placed on the market and to keep it up to date during the support period. The technical documentation contains the items in Annex VII: general description, design and manufacturing of the product including risk assessme...

Evidence an inspector accepts: Technical-documentation file aligned with Annex VII; 10-year retention plan; Microenterprise / SME simplified-documentation reliance where applicable (Annex VI)
Common gap: Technical documentation lacking Annex VII items (e.g. no SBOM, no risk assessment)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.27, 28 Presumption of conformity and EU declaration of conformity (Articles 27-28)

Article 27 establishes a presumption of conformity for PDEs that conform with: (a) harmonised standards or parts thereof published in the Official Journal; (b) European cybersecurity certification schemes adopted under (EU) 2019/881 designating the schemes as offering presumption of conformity with all or part of the e...

Evidence an inspector accepts: EU declaration of conformity for each PDE per Annex V; Mapping of relied-upon harmonised standards or European cybersecurity certification schemes
Common gap: EU declaration of conformity missing Annex V required content
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.32 Conformity assessment procedures (Article 32)

Article 32 sets the conformity assessment routes: (1) Default PDE - Module A (internal production control - self-assessment by the manufacturer); (2) Important PDE Class I (Annex III Class I) - Module A if the manufacturer applies harmonised standards or European cybersecurity certification, otherwise Module B+C (EU ty...

Evidence an inspector accepts: Conformity-assessment route selection record per PDE class; Module B+C / Module H notified-body engagement evidence; EUCC certification engagement evidence for Critical PDEs
Common gap: Self-assessment (Module A) for an Important Class II or Critical PDE
EU Cyber Resilience Act on compliance.theartofservice.com

Do this for every product you sell

Paste the list and get this classification for every product at once, per market, with the documents held and missing, the after-sale duties and the findings. Five products free, no account.

Build my conformity sheet

Treadmill or fitness equipment · Commercial HVAC or refrigeration unit