Consumer drone
On top of the radio, battery and cyber rules, drones carry the EU class marking under the unmanned aircraft rules and a toy classification question for the smallest ones. The sheet does not model the aviation rules; it lists them here so nobody thinks the CE file is the whole story.
Regimes engaged, per market
Standing when pasted with its name: mapped
What the file has to hold
- Technical file (11 of the 18 regimes, including GPSR, CRA, RED)
The technical documentation: design, drawings, bill of materials, the standards applied, the conformity assessment route, and the evidence that the requirements are met. Kept for the retention period the regime sets, typically ten years from the last unit placed on the market. - Declaration of conformity (8 of the 18 regimes, including CRA, RED, RoHS)
The EU or UK declaration of conformity (or the food-contact declaration of compliance), signed by the manufacturer, naming the product, the legislation and the standards, and the notified or approved body where one was involved. - Risk assessment (5 of the 18 regimes, including GPSR, CRA, CPSC)
The documented hazard identification and risk assessment for the product across its lifecycle, updated when the design, the use or the field data changes. - Test reports (10 of the 18 regimes, including GPSR, CRA, CPSC)
Test reports from an accredited or accepted laboratory against the standards the technical file names, tied to the exact model and revision tested. - Labelling and instructions (14 of the 18 regimes, including GPSR, CRA, CPSC)
Markings on the product and packaging (conformity mark, identification, warnings, manufacturer and importer details) and the instructions and safety information in the language of the market. - Traceability records (GPSR, CPSC, Toy Safety, UK GPSR)
Batch, lot or serial identification on the product, the records that tie a unit to its production and supply chain, and UDI where the device rules require it. - Third-party certificate (UL/NRTL)
A type-examination certificate, notified or approved body certificate, or listing from a recognised laboratory, with the scope and the expiry. - FCC authorisation (FCC Part 15)
The FCC Supplier's Declaration of Conformity, or the grant of certification with the FCC ID, and the compliance statement in the manual. - Substance declarations (5 of the 18 regimes, including RoHS, REACH, UK RoHS)
Safety data sheets for mixtures and supplier material declarations for articles: the trail that shows what is in the product against the restricted lists. - Registrations (WEEE, UK WEEE)
Producer, establishment, device or product registrations in the databases the regime names (EUDAMED, EPREL, CPNP, the WEEE and battery registers, FDA registration and listing). - Cybersecurity documentation (CRA, RED, UK PSTI)
The software bill of materials, the vulnerability handling and disclosure policy, the stated support period, and the secure update mechanism, as the connected-product rules expect.
Duties that continue after sale
- Market surveillance cooperation (GPSR, CPSC, UK GPSR)
Answer an authority's request for the technical file, the declaration and the supply chain within the time it sets, in a language it accepts, and cooperate with any corrective measure it requires.
Licensed controls: GPSR Art.14, 15, 17 · GPSR Art.23, 24 · CPSC PM.4 · CPSC PM.3 - Incident reporting (5 of the 18 regimes, including GPSR, CRA, CPSC)
Notify the authority when a product has caused, or could cause, an accident, injury or serious incident, through the channel the regime names (the Safety Business Gateway, the MHRA, the FDA, SaferProducts.gov) and within its clock.
Licensed controls: GPSR Art.20 · GPSR Art.25, 26, 27 · CRA Art.14, 16 · CPSC USCPSC 1 · CPSC PM.1 - Recall readiness (GPSR, CPSC, Toy Safety, UK GPSR)
Be able to identify affected units, reach the customers who hold them, issue a notice in the required form, offer the remedy the rules require, and show the authority the effectiveness of the action.
Licensed controls: GPSR Art.35 · GPSR Art.36, 37 · CPSC USCPSC 3 · CPSC PM.2 - Traceability records (GPSR, CRA, Toy Safety, UK GPSR)
Keep the records that identify which batch went to which customer, and the identification on the product that lets a unit be traced back, for the retention period the regime sets.
Licensed controls: GPSR Art.18 · GPSR Art.9 · CRA Art.23 - Security updates and vulnerability handling (CRA, CPSC, RED, UK PSTI)
Provide security updates for the stated support period, run a coordinated vulnerability disclosure process, and report actively exploited vulnerabilities and severe incidents within the reporting clock.
Licensed controls: CRA Art.13, Annex I · CRA Art.54, 55 · CPSC CS.4 · CPSC SW.3 - Producer responsibility for take-back (WEEE, UK WEEE)
Keep producer registrations current in each market, report the quantities placed, and finance collection and treatment of the product and its batteries at end of life. - Substance list watching (5 of the 18 regimes, including RoHS, REACH, UK RoHS)
Track additions to the restricted and candidate substance lists, re-check supplier declarations against them, and update customer communication and labels when a substance in the product is added.
This week
Find out which EU drone class the product is marked as, and whether that class identification label was issued by a notified body.
What holding one is evidence for
Requirement text and evidence artefacts from a human-verified corpus. Data licensed to Conformity Sheet by The Art of Service Pty Ltd, revocable, non-transferable.
GPSR: EU General Product Safety Regulation (Regulation (EU) 2023/988)
GPSR Art.9 Obligations of manufacturers (Article 9)Article 9 imposes the central manufacturer obligations: (a) carry out internal risk analysis and draw up technical documentation containing the analysis + identification of relevant European standards or risk-assessment elements (kept for 10 years); (b) place safe products on the market that comply with Article 5 + Art...
Common gap: Product placed on market without Article 9(2) risk analysis + technical documentation
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
GPSR Art.5, 6, 7, 8 General safety requirement and assessment criteria (Articles 5-8)Article 5 establishes the general safety requirement: economic operators shall place or make available on the market only safe products. Article 6 sets the criteria for assessing safety: the characteristics of the product including its composition, packaging, instructions for assembly and, where applicable, installatio...
Common gap: Placing on market without an Article 6 assessment file
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
GPSR Art.10, 11, 12 Authorised representatives, importers and distributors (Articles 10-12)Article 10 governs authorised representatives (written mandate; tasks include keeping the EU declaration / technical documentation available for 10 years + cooperation with market surveillance). Article 11 sets importer obligations: place safe products + verify Article 9 manufacturer compliance + place importer identit...
Common gap: Non-EU manufacturer placing products without an authorised representative + responsible person in the Union (Article 16)
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
GPSR Art.13, 16 Cases where manufacturer obligations apply to other persons + responsible person in the Union (Articles 13 and 16)Article 13 provides that an importer, distributor or other economic operator is considered to be a manufacturer + subject to Article 9 obligations where the operator places on the market under its own name or trademark, modifies the product in a way that may affect compliance with Article 5, or carries out other Articl...
Common gap: Non-EU manufacturer placing products on the Union market without an Article 16 responsible person
EU General Product Safety Regulation (GPSR, Regulation 2023/988) on compliance.theartofservice.com
CRA: EU Cyber Resilience Act
CRA Art.2 Scope - Products with Digital Elements (Article 2)Article 2 sets the scope: the Regulation applies to PDEs whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. Carve-outs include: products covered by sector-specific Union law (medical devices under MDR/IVDR, motor vehicles under ...
Common gap: Applying CRA to a medical-device PDE that is in fact governed by MDR cybersecurity requirements (sectoral carve-out applies)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.13, Annex I Manufacturer obligations and essential requirements (Article 13 + Annex I)Article 13 imposes the central manufacturer obligations: (1) design, develop and produce the PDE to ensure an appropriate level of cybersecurity based on the cybersecurity risk assessment in Article 13(2); (2) Article 13(6) due diligence on third-party components integrated in the PDE including FOSS dependencies; (3) A...
Common gap: No documented support period or support-period shorter than the product's reasonably expected lifecycle
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.31 Technical documentation (Article 31 + Annex VII)Article 31 requires the manufacturer to draw up the technical documentation for the PDE before it is placed on the market and to keep it up to date during the support period. The technical documentation contains the items in Annex VII: general description, design and manufacturing of the product including risk assessme...
Common gap: Technical documentation lacking Annex VII items (e.g. no SBOM, no risk assessment)
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.27, 28 Presumption of conformity and EU declaration of conformity (Articles 27-28)Article 27 establishes a presumption of conformity for PDEs that conform with: (a) harmonised standards or parts thereof published in the Official Journal; (b) European cybersecurity certification schemes adopted under (EU) 2019/881 designating the schemes as offering presumption of conformity with all or part of the e...
Common gap: EU declaration of conformity missing Annex V required content
EU Cyber Resilience Act on compliance.theartofservice.com
CRA Art.32 Conformity assessment procedures (Article 32)Article 32 sets the conformity assessment routes: (1) Default PDE - Module A (internal production control - self-assessment by the manufacturer); (2) Important PDE Class I (Annex III Class I) - Module A if the manufacturer applies harmonised standards or European cybersecurity certification, otherwise Module B+C (EU ty...
Common gap: Self-assessment (Module A) for an Important Class II or Critical PDE
EU Cyber Resilience Act on compliance.theartofservice.com
CPSC: US Consumer Product Safety Commission (CPSC) requirements, including connected product safety
CPSC RA.3 Lifecycle Risk AssessmentRisk analysis must cover every stage of the product lifecycle including software updates and end-of-life scenarios.
Common gap: OTA update integrity controls insufficient
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC STD.3 Voluntary Standards ParticipationManufacturers should participate in development of voluntary safety standards with UL, ASTM, and other bodies.
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 1 Section 15(b) Substantial Product Hazard ReportingPer US Consumer Product Safety Act Section 15(b): Substantial Product Hazard Reporting to CPSC within 24 hours of obtaining information including cybersecurity hazards.
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 3 Recall, Corrective Action, SaferProducts.govPer CPSC: Voluntary Recall Notice + Corrective Action Plan + SaferProducts.gov Complaint Monitoring.
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.1 Network Security for Connected ProductsConnected products must implement security measures to prevent network-based attacks that could cause physical harm.
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC CS.4 Vulnerability DisclosureManufacturers should establish vulnerability disclosure programmes for security issues affecting product safety.
Common gap: Section 15(b) report triage not aligned to connected hazards
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC SW.3 Remote Update SecurityRemote software update mechanisms must ensure integrity and authenticity of updates per UL 5500 guidance.
Common gap: Vulnerability disclosure programme absent
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
CPSC USCPSC 2 Connected Product Cybersecurity Hazard IdentificationPer CPSC + NIST IR 8425: Connected Product Cybersecurity Hazard Identification + risk assessment + alignment with NIST + secure default configuration.
Common gap: Sec 15(b) + connected product partial
US Consumer Product Safety Commission (CPSC) - Connected Product Safety on compliance.theartofservice.com
Do this for every product you sell
Paste the list and get this classification for every product at once, per market, with the documents held and missing, the after-sale duties and the findings. Five products free, no account.
Build my conformity sheet