Key facts

  • Chapter IV of the EU Cyber Resilience Act (Articles 35 to 51) started to apply on 11 June 2026. These are the rules governing notified bodies, the third party assessors some manufacturers must use before placing a product on the EU market.
  • As of late June 2026, zero notified bodies have been designated for the CRA in the Commission’s NANDO database.
  • Article 35(2) sets a target of 11 December 2026 for sufficient notified body capacity across Member States.
  • The CRA applies in full from 11 December 2027.
  • Most manufacturers can self assess under module A (Annex VIII). Manufacturers of important products in Annex III Class II, and critical products in Annex IV, are required to use a notified body.
  • The bottleneck is coming. Manufacturers who wait for designations to appear will compete for scarce capacity in the run up to full application.

What actually happened on 11 June 2026?

Under Article 71 of the CRA, Chapter IV switched on. That chapter covers the legal machinery for notified bodies: how Member States designate notifying authorities, how conformity assessment bodies apply to become notified, how they are assessed and monitored, and how they are removed from the list if they no longer meet the requirements.

Under Article 2(29), a notified body is a conformity assessment body that a Member State has designated through the procedure in Article 43. Once designated, it appears in the Commission’s NANDO database (New Approach Notified and Designated Organisations), accessible at here.

The activation of Chapter IV is a foundation laying step. It does not create bodies. It creates the legal conditions under which bodies can be created.

Which manufacturers actually need a CRA notified body?

For most products with digital elements, the answer is: none. Under Article 32, every manufacturer must run a conformity assessment showing that its product meets the essential cybersecurity requirements in Annex I. The lightest route is module A, the internal control procedure set out in Annex VIII. This is a self assessment. The manufacturer evaluates its own product, assembles the technical documentation, and signs the EU Declaration of Conformity.

For higher risk categories, the rules tighten:

  • Important products (Annex III, Class I). A manufacturer can self assess only if it fully applies the relevant harmonised standards, common specifications, or a European cybersecurity certification scheme. Without those, a notified body is required.
  • Important products (Annex III, Class II). Third party assessment is required outright. Options are module B plus C (EU type examination plus production conformity) or module H (full quality assurance).
  • Critical products (Annex IV). These face the strictest treatment. They may be required to obtain a European cybersecurity certificate once the relevant schemes are activated. Until then, the same third party fallback routes apply.

 

The conformity assessment routes themselves are set out in Annex VIII. Module A is manufacturer self assessment. Module B plus C combines a notified body EU type examination (module B) with a production conformity phase the manufacturer runs (module C). Module H is a single route where a notified body approves the manufacturer’s quality management system and monitors it on an ongoing basis. Only module A avoids third party involvement.

Why are no notified bodies designated yet?

The designation chain is long. Under Article 36, each Member State must first designate a notifying authority, the national body responsible for evaluating conformity assessment bodies. Once a notifying authority is in place, it can start assessing candidate bodies. Once a body is assessed and notified, the Commission publishes it in NANDO.

That process only opened on 11 June 2026. As of late June 2026, no CRA designations appear in NANDO. National accreditation phases are running in parallel across Member States, but formal designations have not yet reached the database.

Article 35(2) sets the target: Member States are to strive to ensure a sufficient number of notified bodies by 11 December 2026, expressly to avoid bottlenecks that hinder market entry. That target is a best efforts objective, not a guarantee that every product category will have adequate capacity by that date.

You can verify the current state of CRA designations at any time by opening NANDO and filtering by Regulation (EU) 2024/2847.

What should manufacturers do now?

The absence of designations is not a reason to wait. If anything, it compresses your timeline in the opposite direction.

  1. Classify your product. Determine whether your product is a default category, an important product in Annex III Class I or II, or a critical product in Annex IV. This single decision determines whether you can self assess at all and, if not, how much lead time you need to secure notified body capacity.
  2. Prepare your documentation regardless of route. The Annex I essential requirements and the technical documentation package are the same whoever signs off. Whether you self assess or engage a notified body, you need a cybersecurity risk assessment, security by design evidence, product testing outputs, a software bill of materials, and the technical documentation that supports your Declaration of Conformity. None of that work is wasted, and starting now puts you in the strongest position when notified bodies open their books.
  3. Engage early. Several existing conformity assessment bodies operating under the Radio Equipment Directive and related frameworks have announced CRA readiness programmes. When formal designations arrive, demand will spike. Manufacturers who have already prepared their documentation and identified their target bodies will move first.

 

For manufacturers of important or critical products, the scarce resource in the run up to 11 December 2027 will not be the standard, or the harmonised guidance, or the paperwork. It will be a notified body with an open slot.

How Cyber Cert Labs and Attestra help

Cyber Cert Labs leads CRA-AI, the EU cofunded project under the Digital Europe Programme delivering a complete CRA compliance stack for manufacturers. The project has three parts:

  • Attestra, the AI native platform we have built to handle the CRA workflow from first obligation through CE Mark. Attestra covers cybersecurity risk assessment mapped to Annex I, product testing and evidence collection, vulnerability handling and reporting (available now for the 11 September 2026 Article 14 deadline), and automated generation of the technical documentation pack and Declaration of Conformity.
  • Attestra Academy, the training curriculum that gets your product, engineering, and compliance teams operational on the CRA.
  • Two free assessments to help manufacturers get started: a five minute CRA Scope Assessment that classifies your product against Annex III and Annex IV, and a thirty minute CRA Readiness Assessment that scores your product security against the CRA essential requirements.

 

If you are not sure whether the notified body question applies to your product, the CRA Scope Assessment is the fastest way to find out. If you already know you need a third party route, Attestra assembles the documentation your notified body will ask for on day one. Contact Us

Related resources