Industrial control panel or drive
Electrical equipment under the LVD and EMC directives with the industrial control panel and switchgear standards, listing for the US, and the CRA where the controller is networked.
Regimes engaged, per market
Standing when pasted with its name: mapped
What the file has to hold
- Technical file (10 of the 15 regimes, including CRA, LVD, EMC)
The technical documentation: design, drawings, bill of materials, the standards applied, the conformity assessment route, and the evidence that the requirements are met. Kept for the retention period the regime sets, typically ten years from the last unit placed on the market. - Declaration of conformity (8 of the 15 regimes, including CRA, LVD, EMC)
The EU or UK declaration of conformity (or the food-contact declaration of compliance), signed by the manufacturer, naming the product, the legislation and the standards, and the notified or approved body where one was involved. - Risk assessment (CRA, LVD, UK Electrical Safety, OSHA/ANSI)
The documented hazard identification and risk assessment for the product across its lifecycle, updated when the design, the use or the field data changes. - Test reports (8 of the 15 regimes, including CRA, LVD, EMC)
Test reports from an accredited or accepted laboratory against the standards the technical file names, tied to the exact model and revision tested. - Labelling and instructions (11 of the 15 regimes, including CRA, LVD, EMC)
Markings on the product and packaging (conformity mark, identification, warnings, manufacturer and importer details) and the instructions and safety information in the language of the market. - Third-party certificate (OSHA/ANSI, UL/NRTL)
A type-examination certificate, notified or approved body certificate, or listing from a recognised laboratory, with the scope and the expiry. - FCC authorisation (FCC Part 15)
The FCC Supplier's Declaration of Conformity, or the grant of certification with the FCC ID, and the compliance statement in the manual. - Substance declarations (RoHS, REACH, UK RoHS, UK REACH)
Safety data sheets for mixtures and supplier material declarations for articles: the trail that shows what is in the product against the restricted lists. - Registrations (WEEE, UK WEEE)
Producer, establishment, device or product registrations in the databases the regime names (EUDAMED, EPREL, CPNP, the WEEE and battery registers, FDA registration and listing). - Cybersecurity documentation (CRA)
The software bill of materials, the vulnerability handling and disclosure policy, the stated support period, and the secure update mechanism, as the connected-product rules expect.
Duties that continue after sale
- Incident reporting (CRA)
Notify the authority when a product has caused, or could cause, an accident, injury or serious incident, through the channel the regime names (the Safety Business Gateway, the MHRA, the FDA, SaferProducts.gov) and within its clock.
Licensed controls: CRA Art.14, 16 - Traceability records (CRA)
Keep the records that identify which batch went to which customer, and the identification on the product that lets a unit be traced back, for the retention period the regime sets.
Licensed controls: CRA Art.23 - Security updates and vulnerability handling (CRA)
Provide security updates for the stated support period, run a coordinated vulnerability disclosure process, and report actively exploited vulnerabilities and severe incidents within the reporting clock.
Licensed controls: CRA Art.13, Annex I · CRA Art.54, 55 - Producer responsibility for take-back (WEEE, UK WEEE)
Keep producer registrations current in each market, report the quantities placed, and finance collection and treatment of the product and its batteries at end of life. - Substance list watching (RoHS, REACH, UK RoHS, UK REACH)
Track additions to the restricted and candidate substance lists, re-check supplier declarations against them, and update customer communication and labels when a substance in the product is added.
This week
Check the short-circuit rating on the nameplate matches the test, because that is what the inspector reads first.
What holding one is evidence for
Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable.
CRA: EU Cyber Resilience Act
CRA Art.2 Scope - Products with Digital Elements (Article 2)Article 2 sets the scope: the Regulation applies to PDEs whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Carve-outs include: products covered by sector-specific Union law (medical devices under MDR/IVDR, motor vehicles under ...
Common gap: Applying CRA to a medical-device PDE that is in fact governed by MDR cybersecurity requirements (sectoral carve-out applies)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.13, Annex I Manufacturer obligations and essential requirements (Article 13 + Annex I)Article 13 imposes the central manufacturer obligations: (1) design, develop and produce the PDE to ensure an appropriate level of cybersecurity based on the cybersecurity risk assessment in Article 13(2); (2) Article 13(6) due diligence on third-party components integrated in the PDE including FOSS dependencies; (3) A...
Common gap: No documented support period or support-period shorter than the product's reasonably expected lifecycle
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.31 Technical documentation (Article 31 + Annex VII)Article 31 requires the manufacturer to draw up the technical documentation for the PDE before it is placed on the market and to keep it up to date during the support period. The technical documentation contains the items in Annex VII: general description, design and manufacturing of the product including risk assessme...
Common gap: Technical documentation lacking Annex VII items (e.g. no SBOM, no risk assessment)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.27, 28 Presumption of conformity and EU declaration of conformity (Articles 27-28)Article 27 establishes a presumption of conformity for PDEs that conform with: (a) harmonised standards or parts thereof published in the Official Journal; (b) European cybersecurity certification schemes adopted under (EU) 2019/881 designating the schemes as offering presumption of conformity with all or part of the e...
Common gap: EU declaration of conformity missing Annex V required content
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.32 Conformity assessment procedures (Article 32)Article 32 sets the conformity assessment routes: (1) Default PDE - Module A (internal production control - self-assessment by the manufacturer); (2) Important PDE Class I (Annex III Class I) - Module A if the manufacturer applies harmonised standards or European cybersecurity certification, otherwise Module B+C (EU ty...
Common gap: Self-assessment (Module A) for an Important Class II or Critical PDE
EU Cyber Resilience Act on compliance.theartofservice.com
Do this for every product you sell
Paste the list and get this classification for every product at once, per market, with the documents held and missing, the after-sale duties and the findings. Five products free, no account.
Build my conformity sheet