The short answer
Most products with digital elements are self-assessed. You do the conformity assessment yourself, draw up the technical documentation, sign the declaration and affix the CE marking. No third party is involved and nobody grants you permission.
That changes for two groups: important products in Annex III Class II, and critical products in Annex IV. For those, the route to CE marking involves a notified body unless you apply harmonised standards in full — and for some, even that is not enough.
Which class are you in?
The lists are exhaustive, not illustrative. If your product is not described in Annex III or Annex IV, it is in the default category — being security-adjacent, or being important to your customers, does not move you up.
| Class | Examples | Route |
|---|---|---|
| Default | Most software, mobile and desktop apps, SDKs, most connected devices | Self-assessment (Module A) |
| Annex III, Class I | Password managers, VPNs, browsers, operating systems, routers, SIEM, smart home security | Self-assessment only if harmonised standards are applied in full; otherwise a notified body |
| Annex III, Class II | Hypervisors, container runtimes, firewalls, IDS/IPS, tamper-resistant microprocessors | Notified body involvement required |
| Annex IV (critical) | Hardware security boxes, smart meter gateways, smartcards and secure elements | Notified body, and potentially an EU cybersecurity certification scheme |
The Class I trap
Annex III Class I is where most people get this wrong, because the answer is conditional rather than yes or no.
You may self-assess a Class I product only if you apply the relevant harmonised standards, common specifications or European cybersecurity certification schemes in full. Apply them partially, or apply none because none yet exist for your product, and the self-assessment route closes and a notified body is required.
Harmonised standards under the CRA are still being developed. Planning on self-assessing a Class I product in 2027 on the basis of standards that have not been published is a plan with a dependency you do not control.
What a notified body actually does
A notified body is an independent conformity assessment body designated by a member state. It does not write your documentation and it does not fix your product. It examines what you have produced and issues a certificate if it holds up.
- You still write the technical documentation to Annex VII. That work does not transfer.
- You still do the risk assessment, the SBOM, the vulnerability handling and the CVD policy.
- They assess. Expect questions, findings, and a round of remediation before a certificate.
- You pay them, and lead times lengthen as the December 2027 deadline approaches and demand concentrates.
What this means for your timeline
Self-assessment is bounded by your own capacity. Notified body assessment is bounded by someone else’s queue, and there are a limited number of designated bodies for a market of over 600,000 manufacturers.
If you are in Annex III Class II or Annex IV, the practical deadline is not 11 December 2027. It is whenever your chosen body can take you, working backwards from that date with time for findings and remediation.