Skip to content

Product Safety

EU Cyber Resilience Act (CRA) Guide

Here's a problem you might not have thought about: before the Cyber Resilience Act, most hardware and software products had no mandatory cybersecurity requirements at all. A smart camera, a connected thermostat, a SaaS platform — none of them needed to meet any baseline security standard to be sold in the EU. The CRA (Regulation 2024/2847) changes that, and it's going to affect every company that makes or sells products with digital elements.

The Act entered into force in 2024, with obligations phasing in through 2027. If you make connected devices, operating systems, or even mobile apps sold in the EU, you're in scope.

GPSR Software: Meet EU Product Safety Requirements

The EU General Product Safety Regulation (GPSR, Regulation 2023/988) has been in effect since December 2024, replacing the old GPS Directive. It requires every product sold in the EU to have an accountable EU Responsible Person, accessible safety documentation, and a traceability system — regardless of whether the product is covered by sector-specific legislation like CE marking.

GPSR compliance software automates responsible person appointment, safety document management, incident reporting, and marketplace compliance — keeping your products selling on Amazon, eBay, and other EU marketplaces.

Toy Safety: EU vs. US Requirements

Toys are one of the most heavily regulated consumer product categories in the world — and for good reason. A defective toy can cause choking, lacerations, chemical poisoning, or strangulation in a matter of seconds. Because the end-user is a child, regulators apply a zero-tolerance approach to non-compliance.

If you manufacture, import, or sell toys in the European Union or the United States, you must navigate two distinct but equally demanding regulatory regimes: the EU Toy Safety Directive (2009/48/EC) and the US Consumer Product Safety Act (CPSIA), which mandates a Children's Product Certificate (CPC). Understanding the differences — and producing compliant documentation for both markets — is essential for uninterrupted market access.

EU AI Act Compliance for Product Manufacturers

If your products contain software that makes decisions, recognizes patterns, generates outputs, or interacts with users — even basic features like predictive text, smart sensors, or automated quality grading — you are now regulated under the EU Artificial Intelligence Act (Regulation [EU] 2024/1689).

This is not a law for Silicon Valley alone. The EU AI Act applies to every manufacturer, importer, and distributor placing AI-enabled products on the European market. And because the Act is integrated with the New Legislative Framework (NLF), AI compliance is now directly tied to your CE Mark. If your AI system does not meet the Act's requirements, your product cannot legally carry the CE Mark — and cannot be sold in the European Union.

How to Build a RoHS Compliance System

Manufacturing electronic and electrical equipment (EEE) involves complex global supply chains, often requiring thousands of individual components to build a single finished product. If just one of those components—down to the smallest resistor, capacitor, or plastic casing—contains a restricted hazardous substance above the legal threshold, your entire product is barred from entering the European Union.

This is the reality of the Restriction of Hazardous Substances (RoHS) Directive (2011/65/EU), commonly referred to as RoHS 2 (and updated by RoHS 3). Ensuring that your products are compliant is not a one-time event; it requires a continuous, dynamic RoHS Compliance Management System (CMS).

In this guide, we will break down the exact technical steps required to build a system that satisfies market surveillance authorities and ensures uninterrupted market access.

RoHS vs. REACH: Supplier Requirements

One of the most common causes of supply chain friction in European manufacturing is the conflation of REACH and RoHS.

It happens every day: A procurement manager emails a supplier asking for a "REACH/RoHS Certificate." The supplier, based outside the EU and confused by the acronyms, replies with a generic letter stating their product is "safe and compliant." The procurement manager files it away. A year later, a market surveillance authority audits the manufacturer, deems the generic letter invalid, and forces a product recall.

While both REACH and RoHS are European regulations designed to protect human health and the environment from hazardous chemicals, their scopes, thresholds, and reporting mechanics are completely different. To secure your supply chain, you must know exactly what to ask for.

Preparing for the EU CRA: SBOM Requirements

If you manufacture hardware, connected consumer electronics, IoT devices, or develop commercial software sold in the European Union, a massive regulatory wave is about to hit your engineering team.

The EU Cyber Resilience Act (CRA) represents the most sweeping cybersecurity law for physical and digital products in the world.

Under the CRA, cybersecurity is no longer treated as a post-launch software update or a marketing feature. It has become a mandatory condition for CE Marking.

If your "product with digital elements" does not meet the CRA's strict security-by-design standards, you cannot legally affix the CE Mark, and your product is banned from entering the European market. Penalties for non-compliance are severe, reaching up to €15 million or 2.5% of global turnover.

To maintain EU market access, software and hardware product teams must master the CRA's core technical requirement: the Software Bill of Materials (SBOM).

PFAS-Free Declarations for Retail Buyers

If you supply consumer goods, apparel, cosmetics, or electronics to major retailers or online marketplaces, you have likely received a sudden, urgent request for a PFAS-Free Declaration.

Per- and polyfluoroalkyl substances (PFAS)—commonly dubbed "forever chemicals" due to their extreme persistence in the human body and environment—are facing an unprecedented wave of global regulation. In the United States, several states (including California, Maine, and Vermont) have enacted strict bans on intentionally added PFAS in consumer products.

Meanwhile, the European Union is evaluating a blanket restriction under REACH.

To protect themselves from immense liability and potential class-action lawsuits, retail giants (such as Amazon, Target, and Costco) are enforcing strict "flow-down" policies. If you cannot provide a valid, verifiable chemical compliance statement proving your products contain no intentionally added PFAS, your inventory will be immediately rejected and your vendor status terminated.

Here is how to audit your supply chain and draft a legally compliant PFAS-free declaration.

California Proposition 65 Compliance

If your business ships physical products to California, list items on Amazon US, or sells through major retail distributors, you are subject to one of the most litigious consumer laws in the United States: California Proposition 65 (Prop 65).

Officially known as the Safe Drinking Water and Toxic Enforcement Act of 1986, Prop 65 requires businesses to provide a "clear and reasonable" warning to California consumers before exposing them to any of over 900 naturally occurring or synthetic chemicals known to cause cancer, birth defects, or other reproductive harm.

What makes Prop 65 uniquely dangerous is its enforcement mechanism. Unlike most laws enforced by government agencies, Prop 65 allows private citizens and advocacy groups to sue businesses on behalf of the public—creating a lucrative industry for plaintiff attorneys operating on contingency fees.

In 2024 alone, businesses paid over $30 million in settlements to resolve private Prop 65 lawsuits. To protect your business from these "bounty-hunter" lawsuits, you must understand how to audit your products and apply compliant safe harbor warnings.

How to Create a CE Declaration of Conformity

If you are importing physical products into the European Economic Area (EEA), you cannot legally sell them without a CE Mark. However, many importers mistakenly believe that the CE Mark is simply a sticker you buy and slap onto a product box.

In reality, the CE Mark is a visible declaration of a much deeper legal process. The cornerstone of this process is the EU Declaration of Conformity (DoC).

The DoC is a legally binding document drafted and signed by the manufacturer (or the importer assuming the manufacturer's liability) stating that the product meets all essential health, safety, and environmental protection requirements of the applicable European directives. If a customs officer at an EU border, a distributor, or an online marketplace like Amazon requests this document and you cannot provide a valid, properly formatted copy, your shipments will be seized, and your listings will be suspended.

Here is the definitive, step-by-step guide to creating a legally compliant CE Declaration of Conformity.