Do I need a notified body under the CRA?
Short answer. Only three groups of products need a third party. Everything else, the manufacturer signs off itself.
- Not in Annex III or Annex IV — self-assess. Module A. No notified body, no fee. This is the large majority of products.
- Annex III Class I — self-assessment is available only if you apply the relevant harmonised standards in full. Otherwise a notified body.
- Annex III Class II, or Annex IV critical — no self-assessment route at all.
So the question is really a lookup: is your product on either list?
This is the question that decides whether CRA compliance is a document exercise or a procurement project, and manufacturers routinely assume the worse answer. The lists are short and they are worth reading properly once.
- The four routes in Article 32
- The default category: you sign it yourself
- Annex III Class I, and the conditional trap
- Annex III Class II: no self-assessment
- Annex IV: critical products
- What is actually on the lists
- What each module involves
- Why this is a scheduling problem, not a budget problem
- What to do now
The four routes in Article 32
Article 32 sets out the conformity assessment procedures. There are four, and which of them you may use depends entirely on your classification.
| Route | What it is | Third party? |
|---|---|---|
| Module A | Internal control. You assess conformity, compile the technical documentation, sign the declaration and affix the CE marking. | No |
| Module B + C | EU-type examination by a notified body, then conformity to that type based on internal production control by you. | Yes |
| Module H | Conformity based on full quality assurance — the notified body assesses and monitors your quality system rather than the individual product type. | Yes |
| Certification scheme | A European cybersecurity certification scheme adopted under the Cybersecurity Act, at substantial assurance level where the article requires a level. | Yes |
And the mapping from class to permitted routes:
| Your product | Routes available |
|---|---|
| Default — not in Annex III or IV | Module A, or B+C, or H, or a certification scheme |
| Annex III Class I, standards applied in full | The default routes remain available, module A included |
| Annex III Class I, standards not applied in full, only partly applied, or not yet in existence | B+C, or H |
| Annex III Class II | B+C, or H, or a certification scheme at substantial level. No module A. |
| Annex IV critical | A European cybersecurity certification scheme; and where the conditions for that are not met, the Class II routes |
The default category: you sign it yourself
If your product performs none of the security functions listed in Annex III, you are in the default category, and module A is open to you. In practice that means:
- You carry out the cybersecurity risk assessment and build the product to meet the essential requirements in Annex I.
- You compile the technical documentation set out in Annex VII and keep it available.
- You draw up and sign the EU declaration of conformity in Annex V — your own signature, taking your own responsibility.
- You affix the CE marking.
No external audit. No certification fee. No queue for a notified body's calendar. The obligation is real and the documentation is substantial, but it is work you can do yourself and control the timing of — which is a completely different kind of problem from the other routes.
Annex III Class I, and the conditional trap
This is where most of the misreading happens. Class I is commonly described as “self-assessable”, and it is, but read Article 32(2) closely: the notified-body routes are mandatory where the manufacturer has not applied, or has applied only in part, the relevant harmonised standards, common specifications or European cybersecurity certification schemes at substantial assurance level — or where such standards, specifications or schemes do not exist.
That last clause is the one to sit with. Self-assessment of a Class I product is conditional on a standard existing for you to apply, and on your applying it in full.
Two consequences. First, a Class I manufacturer planning to self-assess is planning around a standard that has to land in time, and that is a dependency on somebody else's schedule, not yours. Second, this is the single strongest reason for a Class I manufacturer to check the classification carefully rather than assume: the difference between default and Class I is the difference between controlling your own timeline and not.
Note also that Article 32(2)'s condition is about applying standards, not about having them — so partial application is treated the same as no application. There is no partial credit in this paragraph.
Annex III Class II: no self-assessment
Class II is the higher-risk half of the important-products list, and module A is simply not available. Your options are EU-type examination plus internal production control, full quality assurance, or a European cybersecurity certification scheme at substantial assurance level.
If you land in Class II, a third party is in your critical path. That is the point at which CRA compliance stops being a documentation project and becomes something your release schedule has to be planned around.
Annex IV: critical products
Annex IV is the shortest and heaviest list. Critical products are expected to go through a European cybersecurity certification scheme, and where the conditions for that route are not met, the Class II routes apply instead.
This is a small and specific set of products — hardware devices with security boxes, smart meter gateways, smartcards and similar secure elements. If you make one of these you almost certainly already know it, because you are probably already dealing with Common Criteria or an equivalent regime.
What is actually on the lists
The lists work by product category and function, not by industry. Broadly:
Annex III Class I covers products whose job is security or network control — identity management and access control software, password managers, standalone malware protection, VPNs, network management systems, security information and event management, boot managers, public key infrastructure and certificate issuance software, physical and virtual network interfaces, operating systems, routers, modems and switches, microprocessors and microcontrollers with security-related functionality, ASICs and FPGAs with security-related functionality, smart home assistants, connected toys with social or location features, and personal wearables for health monitoring.
Annex III Class II covers hypervisors and container runtimes, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers.
Annex IV covers hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices including secure elements.
The categories are drafted narrowly and the wording carries the decision. “A microprocessor with security-related functionality” is not the same as “a microprocessor”, and the qualifying words are where marginal products are decided.
The list has already been elaborated by a separate act. The Commission adopted an implementing regulation giving technical descriptions of the Annex III and Annex IV categories, precisely because the annex headings alone were not operable. If your product is anywhere near a boundary, that act and the annex text are what you read, not a vendor page. And the Commission has the power to amend Annex III by delegated act, so the lists can move.
What each module involves
Module A, internal control. You do the work and keep the file. The notified body does not appear. Your obligations are real — the technical documentation in Annex VII, the declaration in Annex V, series-production controls — but the only party that can hold up your release is you.
Module B + C, EU-type examination plus internal production control. You submit a representative example and the documentation to a notified body; it examines the type and issues a certificate; then you produce in conformity with that certified type and declare that you have. Two practical consequences: there is a review-and-correct cycle with a third party before you can ship, and a substantial modification to the product can send you back to the notified body, because what was certified was a type.
Module H, full quality assurance. The notified body assesses your quality system and then monitors it, rather than examining each product type. Heavier to set up and usually only worth it for a manufacturer with several products in scope — at which point it can be lighter overall than type-examining each one.
European cybersecurity certification scheme. Certification under a scheme adopted under the Cybersecurity Act. The obvious catch is availability: a scheme has to exist for your product category and at the right assurance level before this route is open to you.
Why this is a scheduling problem, not a budget problem
Manufacturers who discover they need a notified body usually ask what it will cost. That is the less dangerous question. There is no published tariff — bodies quote per product and per module, and the notified bodies for the CRA are still being designated by Member States, so a market price has not settled yet.
The question that hurts is when. Two effects compound:
- You cannot place the product on the EU market until the procedure is complete. A third party is now the gate on your release date.
- Everyone needing a body needs one at the same time. The substantive obligations apply from 11 December 2027. Demand for a newly designated pool of bodies will not be evenly distributed across the months before that date.
Which makes the classification check something worth doing now rather than in 2027, even if the answer turns out to be the comfortable one. If you are in the default category, you know your CRA work is yours to schedule. If you are not, the lead time is the thing you need to find out about earliest.
What to do now
- Classify the product deliberately, against the Annex III and Annex IV text and the implementing regulation's descriptions, not against a blog summary. Write down the conclusion and the reason — that reasoning belongs in your technical documentation anyway.
- If you are default, you are self-assessing. Start on the Annex VII technical documentation; it is the long pole.
- If you are Class I, do both things: track the harmonised standards for your product type, and price the module B+C route as the fallback, because Article 32(2) puts you there if the standard is not available and fully applied.
- If you are Class II or Annex IV, start finding a notified body now and treat the lead time as a release dependency.
- Re-check after any substantial modification, and whenever Annex III is amended. Your classification is not a one-time answer.
An honest note on confidence: the route-to-class mapping in Article 32 paragraphs 1 to 4 was checked against two independent reproductions of the article, which agreed. The reading that a Class I manufacturer who does apply the standards in full retains the paragraph 1 routes including module A follows from the structure of the article rather than from an express sentence saying so, so treat it as an inference and confirm it against the text. The Annex III and Annex IV summaries here are working paraphrases for orientation only, and a marginal classification needs the annex wording and the implementing regulation. Nothing here is legal advice.
Find out which route you are on, in two minutes
The free check walks the same classification logic and tells you your class, whether you can self-assess, and which documents you have to produce.
Already know you are self-assessing? Then the file is the work. See what Conformance House produces — €390 a year for one product.