ConformanceHouse
Scope and risk · Updated 14 September 2026

Do I need a notified body under the CRA?

Short answer. Only three groups of products need a third party. Everything else, the manufacturer signs off itself.

  • Not in Annex III or Annex IV — self-assess. Module A. No notified body, no fee. This is the large majority of products.
  • Annex III Class I — self-assessment is available only if you apply the relevant harmonised standards in full. Otherwise a notified body.
  • Annex III Class II, or Annex IV critical — no self-assessment route at all.

So the question is really a lookup: is your product on either list?

This is the question that decides whether CRA compliance is a document exercise or a procurement project, and manufacturers routinely assume the worse answer. The lists are short and they are worth reading properly once.

The four routes in Article 32

Article 32 sets out the conformity assessment procedures. There are four, and which of them you may use depends entirely on your classification.

RouteWhat it isThird party?
Module AInternal control. You assess conformity, compile the technical documentation, sign the declaration and affix the CE marking.No
Module B + CEU-type examination by a notified body, then conformity to that type based on internal production control by you.Yes
Module HConformity based on full quality assurance — the notified body assesses and monitors your quality system rather than the individual product type.Yes
Certification schemeA European cybersecurity certification scheme adopted under the Cybersecurity Act, at substantial assurance level where the article requires a level.Yes

And the mapping from class to permitted routes:

Your productRoutes available
Default — not in Annex III or IV Module A, or B+C, or H, or a certification scheme
Annex III Class I, standards applied in full The default routes remain available, module A included
Annex III Class I, standards not applied in full, only partly applied, or not yet in existence B+C, or H
Annex III Class II B+C, or H, or a certification scheme at substantial level. No module A.
Annex IV critical A European cybersecurity certification scheme; and where the conditions for that are not met, the Class II routes

The default category: you sign it yourself

If your product performs none of the security functions listed in Annex III, you are in the default category, and module A is open to you. In practice that means:

No external audit. No certification fee. No queue for a notified body's calendar. The obligation is real and the documentation is substantial, but it is work you can do yourself and control the timing of — which is a completely different kind of problem from the other routes.

Annex III Class I, and the conditional trap

This is where most of the misreading happens. Class I is commonly described as “self-assessable”, and it is, but read Article 32(2) closely: the notified-body routes are mandatory where the manufacturer has not applied, or has applied only in part, the relevant harmonised standards, common specifications or European cybersecurity certification schemes at substantial assurance level — or where such standards, specifications or schemes do not exist.

That last clause is the one to sit with. Self-assessment of a Class I product is conditional on a standard existing for you to apply, and on your applying it in full.

Why this matters right now. The harmonised standards underpinning the CRA are still being developed under the Commission's standardisation request to CEN and CENELEC, and the published schedules for them have already moved. Until the relevant standard for your product type exists, has been cited in the Official Journal, and has been applied by you in full, the plain reading of Article 32(2) does not leave a Class I manufacturer in the self-assessment route.

Two consequences. First, a Class I manufacturer planning to self-assess is planning around a standard that has to land in time, and that is a dependency on somebody else's schedule, not yours. Second, this is the single strongest reason for a Class I manufacturer to check the classification carefully rather than assume: the difference between default and Class I is the difference between controlling your own timeline and not.

Note also that Article 32(2)'s condition is about applying standards, not about having them — so partial application is treated the same as no application. There is no partial credit in this paragraph.

Annex III Class II: no self-assessment

Class II is the higher-risk half of the important-products list, and module A is simply not available. Your options are EU-type examination plus internal production control, full quality assurance, or a European cybersecurity certification scheme at substantial assurance level.

If you land in Class II, a third party is in your critical path. That is the point at which CRA compliance stops being a documentation project and becomes something your release schedule has to be planned around.

Annex IV: critical products

Annex IV is the shortest and heaviest list. Critical products are expected to go through a European cybersecurity certification scheme, and where the conditions for that route are not met, the Class II routes apply instead.

This is a small and specific set of products — hardware devices with security boxes, smart meter gateways, smartcards and similar secure elements. If you make one of these you almost certainly already know it, because you are probably already dealing with Common Criteria or an equivalent regime.

What is actually on the lists

The lists work by product category and function, not by industry. Broadly:

Annex III Class I covers products whose job is security or network control — identity management and access control software, password managers, standalone malware protection, VPNs, network management systems, security information and event management, boot managers, public key infrastructure and certificate issuance software, physical and virtual network interfaces, operating systems, routers, modems and switches, microprocessors and microcontrollers with security-related functionality, ASICs and FPGAs with security-related functionality, smart home assistants, connected toys with social or location features, and personal wearables for health monitoring.

Annex III Class II covers hypervisors and container runtimes, firewalls, intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers.

Annex IV covers hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices including secure elements.

Do not classify from a summary, including this one. Two reasons.

The categories are drafted narrowly and the wording carries the decision. “A microprocessor with security-related functionality” is not the same as “a microprocessor”, and the qualifying words are where marginal products are decided.

The list has already been elaborated by a separate act. The Commission adopted an implementing regulation giving technical descriptions of the Annex III and Annex IV categories, precisely because the annex headings alone were not operable. If your product is anywhere near a boundary, that act and the annex text are what you read, not a vendor page. And the Commission has the power to amend Annex III by delegated act, so the lists can move.

What each module involves

Module A, internal control. You do the work and keep the file. The notified body does not appear. Your obligations are real — the technical documentation in Annex VII, the declaration in Annex V, series-production controls — but the only party that can hold up your release is you.

Module B + C, EU-type examination plus internal production control. You submit a representative example and the documentation to a notified body; it examines the type and issues a certificate; then you produce in conformity with that certified type and declare that you have. Two practical consequences: there is a review-and-correct cycle with a third party before you can ship, and a substantial modification to the product can send you back to the notified body, because what was certified was a type.

Module H, full quality assurance. The notified body assesses your quality system and then monitors it, rather than examining each product type. Heavier to set up and usually only worth it for a manufacturer with several products in scope — at which point it can be lighter overall than type-examining each one.

European cybersecurity certification scheme. Certification under a scheme adopted under the Cybersecurity Act. The obvious catch is availability: a scheme has to exist for your product category and at the right assurance level before this route is open to you.

Why this is a scheduling problem, not a budget problem

Manufacturers who discover they need a notified body usually ask what it will cost. That is the less dangerous question. There is no published tariff — bodies quote per product and per module, and the notified bodies for the CRA are still being designated by Member States, so a market price has not settled yet.

The question that hurts is when. Two effects compound:

  1. You cannot place the product on the EU market until the procedure is complete. A third party is now the gate on your release date.
  2. Everyone needing a body needs one at the same time. The substantive obligations apply from 11 December 2027. Demand for a newly designated pool of bodies will not be evenly distributed across the months before that date.

Which makes the classification check something worth doing now rather than in 2027, even if the answer turns out to be the comfortable one. If you are in the default category, you know your CRA work is yours to schedule. If you are not, the lead time is the thing you need to find out about earliest.

What to do now

  1. Classify the product deliberately, against the Annex III and Annex IV text and the implementing regulation's descriptions, not against a blog summary. Write down the conclusion and the reason — that reasoning belongs in your technical documentation anyway.
  2. If you are default, you are self-assessing. Start on the Annex VII technical documentation; it is the long pole.
  3. If you are Class I, do both things: track the harmonised standards for your product type, and price the module B+C route as the fallback, because Article 32(2) puts you there if the standard is not available and fully applied.
  4. If you are Class II or Annex IV, start finding a notified body now and treat the lead time as a release dependency.
  5. Re-check after any substantial modification, and whenever Annex III is amended. Your classification is not a one-time answer.
How to check everything on this page. The routes come from Article 32 of Regulation (EU) 2024/2847, the modules from Annex VIII, the classification lists from Annex III and Annex IV, the technical documentation from Annex VII and the declaration of conformity from Annex V. Read them on EUR-Lex rather than taking this page's word for it.

An honest note on confidence: the route-to-class mapping in Article 32 paragraphs 1 to 4 was checked against two independent reproductions of the article, which agreed. The reading that a Class I manufacturer who does apply the standards in full retains the paragraph 1 routes including module A follows from the structure of the article rather than from an express sentence saying so, so treat it as an inference and confirm it against the text. The Annex III and Annex IV summaries here are working paraphrases for orientation only, and a marginal classification needs the annex wording and the implementing regulation. Nothing here is legal advice.

Find out which route you are on, in two minutes

The free check walks the same classification logic and tells you your class, whether you can self-assess, and which documents you have to produce.

Take the free check

Already know you are self-assessing? Then the file is the work. See what Conformance House produces — €390 a year for one product.