Essential requirements, standards, and presumptions

Lesson 1 of 5 in Conformity Assessment, Standards, CE Marking, and Post-Market Duties.

You know the Articles 8–15 rulebook. Now comes the question every provider actually loses sleep over: how do you prove you meet it? The Act’s answer is fifty years old and borrowed wholesale from EU product-safety law — the New Legislative Framework chain: the law states essential requirements in deliberately open language, technical committees write harmonized standards that make them concrete, and a provider who applies those standards earns a presumption of conformity — regulators must presume the covered requirements are met unless they can show otherwise. Prove the whole package through conformity assessment, sign a declaration, affix the CE mark, and the product circulates in all 27 Member States.

This chain is why the standards work matters as much as the statute. Article 9 tells you to run a “risk management system”; it does not tell you what documents, what review cadence, or what acceptance criteria satisfy a market-surveillance inspector. A harmonized standard does. Whoever writes the standards writes the practical meaning of the law.

Read the trigger carefully: the presumption attaches only when a standard’s reference is cited in the Official Journal (OJEU) — not when CEN publishes it, not when your consultant recommends it. The Commission issued a standardisation request to CEN/CENELEC, whose joint technical committee JTC 21 is drafting the deliverables: standards on risk management, data quality and governance, transparency, human oversight, accuracy, robustness, cybersecurity, and quality management — one work item per limb of Articles 9–15, plus an overarching “trustworthiness framework” designed to let ISO/IEC 42001-style management systems carry much of the load.

Two fallbacks exist for when standards are missing or inadequate. Under Article 41, the Commission may adopt common specifications by implementing act — Commission-written technical rules that grant the same presumption; a provider may still use alternative technical solutions if it can justify equivalence. And Article 42 adds two ready-made presumptions: systems trained and tested on data reflecting the specific geographical, behavioural, contextual or functional setting of intended use are presumed to meet Article 10(4)’s representativeness demand; and cybersecurity certification under an EU cybersecurity scheme — the route the Cyber Resilience Act ecosystem plugs into — presumes conformity with Article 15’s cybersecurity requirements, to the extent covered.

Four ways to earn a presumption of conformity
InstrumentWho creates itWhat it presumesThe catch

Harmonized standard (Art 40)

CEN/CENELEC JTC 21, on a Commission standardisation request

Conformity with the Arts 9–15 requirements (or GPAI obligations) the standard covers

Presumption starts only at OJEU citation — publication by the standards body is not enough

Common specification (Art 41)

The European Commission, by implementing act

Same presumption, for the requirements the specification covers

A fallback for gaps or inadequate standards; providers may justify equivalent alternative solutions instead

Local-data presumption (Art 42(1))

Earned by the provider’s own training/testing choices

The Art 10(4) requirement that data reflect the specific setting of use

Only that one requirement — the rest of Art 10 still needs its own evidence

Cybersecurity certification (Art 42(2))

Certification under an EU cybersecurity scheme

Art 15’s cybersecurity requirements, insofar as the certificate covers them

Covers cybersecurity only — accuracy and robustness under Art 15 still need separate evidence

Key terms: harmonized standard, presumption of conformity, New Legislative Framework, common specifications, CE marking

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.