It is a legal act, not a form
The eight elements
- The name, type and any additional information uniquely identifying the product. A product name alone is not enough — you need a version, model or article number.
- The name and address of the manufacturer, or of the authorised representative. A registered legal name and a postal address, not a trading name and a web form.
- A statement that the declaration is issued under the sole responsibility of the provider.
- The object of the declaration: a description sufficient to allow traceability, and where applicable a colour photograph.
- A statement that the object is in conformity with the relevant Union harmonisation legislation.
- References to the harmonised standards, certification schemes or common specifications relied on, if any.
- Where applicable, the name and number of the notified body, the conformity assessment procedure performed, and the certificate issued.
- Additional information: signed for and on behalf of, place and date of issue, name, function and signature.
If you need a notified body, the declaration is not valid without it
Annex III Class II products — hypervisors, container runtimes, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and microcontrollers — cannot be self-assessed at all. Neither can Annex IV critical products.
Annex III Class I products can be self-assessed only where the relevant harmonised standards, European cybersecurity certification schemes or common specifications are applied in full. Those standards are still being developed, so in practice many Class I manufacturers will need a third-party route for the time being.
Retention
Keep the declaration and the technical documentation at the disposal of market surveillance authorities for ten years after the product has been placed on the market, or for the support period, whichever is longer. For a product with a ten-year support period, that is twenty years of retention.
A note on templates
Any competent template will get the eight elements right — they are prescribed, and there is no scope for creativity. What a template cannot do is tell you whether the statement in element 5 is true.
Before you sign, the honest questions are: is there a documented risk assessment? Is every applicable Annex I requirement implemented and recorded? Does the shipped artefact contain a known exploitable vulnerability? If any answer is no, the declaration says something untrue and the template has not helped you.