A documented way to decide, at each release, whether a change triggers a new conformity assessment. The test is risk-based, not size-based — and security updates generally do not count.
Primary sources
Read it yourself.
We would rather you checked. These are the texts and the bodies behind everything claimed on this site.
The legislation
- Cyber Resilience ActOpens on an external siteThe full text, including Annex I requirements and the Article 14 reporting duty.Regulation (EU) 2024/2847
- NIS2 DirectiveOpens on an external siteRisk management and reporting duties for essential and important entities.Directive (EU) 2022/2555
- Radio Equipment Directive, Art. 3(3)Opens on an external siteThe delegated regulation that activated the network, privacy and fraud requirements.Delegated Reg. (EU) 2022/30
- Battery RegulationOpens on an external siteArticle 77 sets the first legally fixed Digital Product Passport deadline.Regulation (EU) 2023/1542
Standards & accreditation bodies
- ENISAOpens on an external siteThe EU agency that receives Article 14 reports and runs the single reporting platform.ENISA
- TUNACOpens on an external siteThe accreditation body that issued our ISO/IEC 17025 accreditation, 2-0155 — recognised internationally through the ILAC Mutual Recognition Arrangement. Verify it here.TUNAC
- ILAC signatory searchOpens on an external siteConfirm for yourself that a TUNAC report is recognised under the mutual recognition arrangement.ILAC MRA
- ETSIOpens on an external sitePublisher of EN 303 645, the consumer IoT baseline we assess against.ETSI
- BSIOpens on an external siteThe German federal cyber security authority behind Section 31 BSIG and the C5 catalogue.BSI