CRA notified bodies and testing laboratories
The conformity-assessment bodies and cybersecurity testing labs a manufacturer on a third-party route is most likely to engage as a Cyber Resilience Act notified body once designations are published. Filter by country and standard.
Do you need a notified body?
Most products with digital elements use internal control (Module A) and the manufacturer self-assesses, affixes the CE marking, and needs no notified body. A third-party conformity assessment, and therefore a notified body, applies to important products in Class II, critical products under Annex IV, and Class I products where the manufacturer does not fully apply the relevant harmonised standards.
Not sure which route applies? Run the free product classifier, the CRA self-assessment, or review the CRA certification and conformity routes.
Verify designation in NANDO before relying on any body
As of 2026-08-30, the European Commission had not yet published notified bodies designated specifically under the CRA. The organisations below are established EU conformity-assessment bodies and accredited cybersecurity testing laboratories you are likely to work with. A body marked "Candidate" has stated publicly that it applied for CRA designation. None of them holds one yet. Always confirm current status in the official NANDO database.
Showing 12 of 12 organisations.
TÜV SÜD
Germany
Notified body under other EU directives and an accredited cybersecurity testing lab. CRA designation not confirmed.
Visit website →TÜV Rheinland
Germany
Accredited cybersecurity testing lab. CRA designation not confirmed.
Visit website →DEKRA
Germany
Accredited cybersecurity and RED testing lab. CRA designation not confirmed.
Visit website →Applus+ Laboratories
Spain
ITSEF / Common Criteria evaluation lab. CRA designation not confirmed.
Visit website →Brightsight
Netherlands
States publicly that it has applied to the Dutch notifying authority (RvA) for CRA Modules B and H and is progressing through accreditation. Not yet designated; no NANDO entry.
Visit website →SGS
Belgium
Global testing, inspection and certification body. CRA designation not confirmed.
Visit website →Bureau Veritas
France
Conformity-assessment body active in connected-product testing. CRA designation not confirmed.
Visit website →Eurofins Cyber Security
Netherlands
Network of accredited security evaluation labs across the EU. CRA designation not confirmed.
Visit website →UL Solutions
Germany
Accredited testing lab with EU operations. CRA designation not confirmed.
Visit website →DNV
Norway
Certification body strong in industrial and OT security. CRA designation not confirmed.
Visit website →Nemko Group
Norway
EU conformity-assessment body and notified body under RED/EMC. Operates international testing lab partnerships including TTA in South Korea for CRA CE testing.
Visit website →TTA (Telecommunications Technology Association)
South Korea
Designated Notified Body Test Laboratory (NBTL) by Nemko Group to conduct CE certification testing for the EU Cyber Resilience Act.
Visit website →CRA notified body questions
Are there CRA notified bodies yet?
No. The CRA rules on notified bodies began to apply on 11 June 2026, but as of 2026-08-30 no body had appeared in NANDO against Regulation (EU) 2024/2847. Designations have to arrive before the CRA's main obligations apply on 11 December 2027. Until a body is listed in NANDO under the CRA, treat every listing here as a candidate rather than a confirmed CRA notified body.
How do I verify a notified body's CRA designation?
Check the official NANDO database and confirm the body is designated against Regulation (EU) 2024/2847. A body designated under other EU legislation, such as the Radio Equipment Directive, is not automatically designated for the CRA.
When do I need a notified body under the CRA?
Only when a third-party conformity assessment applies. That covers important products in Class II, critical products under Annex IV, and Class I products where the manufacturer does not fully apply the relevant harmonised standards. Most products with digital elements use internal control (Module A) and need no notified body.
Which conformity assessment routes involve a notified body?
Under Article 32, EU-type examination (Module B followed by Module C) and full quality assurance (Module H) both involve a notified body. Internal control (Module A) is a manufacturer self-assessment and involves none.
Assemble an audit-ready technical file first
Whether you self-assess or engage a notified body, your Annex VII technical file is the deliverable.
Get Started for Free