CRA Bureau
All guides

Do you need a notified body under the CRA?

7 min readUpdated 18 September 2026Cites Cyber Resilience Act

The short answer

Article 32

Which class are you in?

ClassExamplesRoute
DefaultMost software, mobile and desktop apps, SDKs, most connected devicesSelf-assessment (Module A)
Annex III, Class IPassword managers, VPNs, browsers, operating systems, routers, SIEM, smart home securitySelf-assessment only if harmonised standards are applied in full; otherwise a notified body
Annex III, Class IIHypervisors, container runtimes, firewalls, IDS/IPS, tamper-resistant microprocessorsNotified body involvement required
Annex IV (critical)Hardware security boxes, smart meter gateways, smartcards and secure elementsNotified body, and potentially an EU cybersecurity certification scheme

The Class I trap

Article 32(2)

What a notified body actually does

  • You still write the technical documentation to Annex VII. That work does not transfer.
  • You still do the risk assessment, the SBOM, the vulnerability handling and the CVD policy.
  • They assess. Expect questions, findings, and a round of remediation before a certificate.
  • You pay them, and lead times lengthen as the December 2027 deadline approaches and demand concentrates.

What this means for your timeline

Article 71

The mistake that wastes a year

Assuming you can self-assess, then discovering you cannot

Check your own product

Free, no account needed.

Related guides