Essential requirements, standards, and presumptions
Lesson 1 of 5 in Conformity Assessment, Standards, CE Marking, and Post-Market Duties.
You know the Articles 8–15 rulebook. Now comes the question every provider actually loses sleep over: how do you prove you meet it? The Act’s answer is fifty years old and borrowed wholesale from EU product-safety law — the New Legislative Framework chain: the law states essential requirements in deliberately open language, technical committees write harmonized standards that make them concrete, and a provider who applies those standards earns a presumption of conformity — regulators must presume the covered requirements are met unless they can show otherwise. Prove the whole package through conformity assessment, sign a declaration, affix the CE mark, and the product circulates in all 27 Member States.
This chain is why the standards work matters as much as the statute. Article 9 tells you to run a “risk management system”; it does not tell you what documents, what review cadence, or what acceptance criteria satisfy a market-surveillance inspector. A harmonized standard does. Whoever writes the standards writes the practical meaning of the law.
Read the trigger carefully: the presumption attaches only when a standard’s reference is cited in the Official Journal (OJEU) — not when CEN publishes it, not when your consultant recommends it. The Commission issued a standardisation request to CEN/CENELEC, whose joint technical committee JTC 21 is drafting the deliverables: standards on risk management, data quality and governance, transparency, human oversight, accuracy, robustness, cybersecurity, and quality management — one work item per limb of Articles 9–15, plus an overarching “trustworthiness framework” designed to let ISO/IEC 42001-style management systems carry much of the load.
Two fallbacks exist for when standards are missing or inadequate. Under Article 41, the Commission may adopt common specifications by implementing act — Commission-written technical rules that grant the same presumption; a provider may still use alternative technical solutions if it can justify equivalence. And Article 42 adds two ready-made presumptions: systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting of intended use are presumed to meet Article 10(4)’s representativeness demand; and cybersecurity certification under an EU cybersecurity scheme — the route the Cyber Resilience Act ecosystem plugs into — presumes conformity with Article 15’s cybersecurity requirements, to the extent covered.
| Instrument | Who creates it | What it presumes | The catch |
|---|---|---|---|
Harmonized standard (Art 40) | CEN/CENELEC JTC 21, on a Commission standardisation request | Conformity with the Arts 9–15 requirements (or GPAI obligations) the standard covers | Presumption starts only at OJEU citation — publication by the standards body is not enough |
Common specification (Art 41) | The European Commission, by implementing act | Same presumption, for the requirements the specification covers | A fallback for gaps or inadequate standards; providers may justify equivalent alternative solutions instead |
Local-data presumption (Art 42(1)) | Earned by the provider’s own training/testing choices | The Art 10(4) requirement that data reflect the specific setting of use | Only that one requirement — the rest of Art 10 still needs its own evidence |
Cybersecurity certification (Art 42(2)) | Certification under an EU cybersecurity scheme | Art 15’s cybersecurity requirements, insofar as the certificate covers them | Covers cybersecurity only — accuracy and robustness under Art 15 still need separate evidence |
Key terms: harmonized standard, presumption of conformity, New Legislative Framework, common specifications, CE marking
Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.