Notified Body
A notified body is an independent conformity assessment body that a member state has notified to the European Commission. Under the Cyber Resilience Act, a notified body carries out the third-party routes of Article 32, Module B with Module C, and Module H.
A notified body is an independent conformity assessment body that a member state has notified to the European Commission. Under the Cyber Resilience Act, a notified body carries out the third-party routes of Article 32, Module B with Module C, and Module H.
CRA RegulatoryLast updated 26 September 2026
What Is a Notified Body?
A Notified Body is an independent conformity assessment organisation that has been formally accredited by a national accreditation body and notified to the European Commission by its member state. These organisations are authorised to perform third-party conformity assessments under specific EU legislation, issuing certificates that manufacturers need to affix the CE mark to their products. Under the Cyber Resilience Act, Notified Bodies carry out cybersecurity-focused assessments, examining whether a product's design, development processes, and vulnerability handling mechanisms meet the essential requirements set out in Annex I. A list of all notified bodies is published in the NANDO (New Approach Notified and Designated Organisations) database maintained by the European Commission.
When Is a Notified Body Required Under the CRA?
Article 32 of Regulation (EU) 2024/2847 sets the conformity route by product class. A notified body is involved only in Module B followed by Module C, and in Module H.
| Product class | Routes under Article 32 | Notified body involved |
|---|---|---|
| Default | Module A, Module B with Module C, Module H, or an applicable certification scheme | Only if the manufacturer chooses Module B with Module C, or Module H |
| Important, Class I (Annex III) | Module A only where harmonised standards, common specifications or a certification scheme at assurance level at least ‘substantial’ are applied in full. Otherwise Module B with Module C, or Module H | Yes, unless the full-application condition is met |
| Important, Class II (Annex III) | Module B with Module C, Module H, or a certification scheme at assurance level at least ‘substantial’ | Yes, for Module B with Module C and for Module H |
| Critical (Annex IV) | A certification scheme under Article 8(1). Where the conditions of Article 8(1) are not met, a Class II route | Yes, when a Class II route with Module B or Module H is used |
Applying harmonised standards does not open Module A to a Class II product. The CRA notified bodies directory lists candidate bodies and explains how to check a designation in NANDO. For the marking that follows a third-party route, see CRA CE marking.
What Does a Notified Body Assessment Cover?
A Notified Body assessment for CRA purposes typically covers three areas. First, a review of technical documentation - verifying that security requirements have been identified, risk assessments conducted, threat models produced, and secure development processes followed. Second, an examination of vulnerability handling procedures - confirming that the manufacturer has a published CVD policy, a PSIRT function, a process for CVSS scoring and triage, and a mechanism for issuing security advisories. Third, testing of the product itself, either through review of existing test evidence or through independent testing, to verify that the essential cybersecurity requirements of Annex I are met. Under Annex VIII, a notified body issues an EU-type examination certificate that states the conditions, if any, for its validity. The manufacturer must inform the notified body of every modification that may affect conformity, and such a modification needs additional approval.
Choosing and Working With a Notified Body
Manufacturers should select a Notified Body with specific expertise in their product category - cybersecurity competence varies significantly between organisations. Key considerations include: whether the body is listed in NANDO for the relevant EU directive and CRA modules; the body's experience with software-intensive products; its capacity to assess vulnerability handling processes and not just hardware; and its geographic availability. Manufacturers should engage a Notified Body well before the CRA's compliance deadline for their product class. Providing complete technical documentation upfront, including threat models, SBOM, and vulnerability handling logs, significantly reduces assessment time and cost. CVD Portal's compliance export features are designed to generate the documentation artefacts Notified Bodies commonly request.
CVD Portal makes Notified Body compliance straightforward.
Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Create my free CVD portalCreate your free CVD portalFrequently asked
How do I find an accredited Notified Body for CRA assessments?+
Search the European Commission's NANDO database for bodies notified under Regulation (EU) 2024/2847. Chapter IV of the CRA, which governs notification, has applied since 11 June 2026. A body notified under other EU legislation, such as the Radio Equipment Directive, is not notified for the CRA by that fact alone. The CRA notified bodies directory lists candidate bodies and how to check each one.
Can a manufacturer switch Notified Body mid-assessment?+
Yes, a manufacturer can change their Notified Body, but doing so will typically require restarting the assessment process, as each body conducts its own independent review. There is no automatic transfer of assessment work between bodies. Manufacturers should avoid switching unless there is a compelling reason, as it creates delays and additional cost.
How long is a Notified Body certificate valid?+
The CRA does not set one fixed period. Under Annex VIII, the EU-type examination certificate states the conditions, if any, for its validity. The manufacturer must inform the notified body of every modification to the approved type or the vulnerability handling processes that may affect conformity, and each such modification needs additional approval as an addition to the original certificate.
Sector checklists covering Notified Body
This definition is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.
Browse the full CRA Compliance Checklist
See how Notified Body fits into your complete CRA compliance programme.