Skip to main content
Glossary termPublished inCRA

Notified body (CRA)

What does "Notified body" mean under the Cyber Resilience Act?

A conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation

Article 43 of the Cyber Resilience Act (Regulation (EU) 2024/2847):

  • 1. Notifying authorities shall notify only conformity assessment bodies which have satisfied the requirements laid down in Article 39.
  • 2. The notifying authority shall notify the Commission and the other Member States using the New Approach Notified and Designated Organisations information system developed and managed by the Commission.
  • 3. The notification shall include full details of the conformity assessment activities, the conformity assessment module or modules and product or products with digital elements concerned and the relevant attestation of competence.
  • 4. Where a notification is not based on an accreditation certificate as referred to in Article 42(2), the notifying authority shall provide the Commission and the other Member States with documentary evidence which attests to the conformity assessment body's competence and the arrangements in place to ensure that that body will be monitored regularly and will continue to satisfy the requirements laid down in Article 39.
  • 5. The body concerned may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within two weeks of a notification where an accreditation certificate is used or within two months of a notification where accreditation is not used. Only such a body shall be considered to be a notified body for the purposes of this Regulation.
  • 6. The Commission and the other Member States shall be notified of any subsequent relevant changes to the notification.

Defined in / by

Also defined different in / by

Last updated: 22 August 2026.

Regulations

  • Cyber Resilience Act (CRA)

    The Cyber Resilience Act is Regulation (EU) 2024/2847. Its reporting obligations under Article 14 apply from 11 September 2026, to every product with digital elements on the Union market, including products placed there before the Regulation's main obligations start on 11 December 2027. Actively exploited vulnerabilities must be reported within 24 hours.

    Next
    Article 14 reporting obligations apply: actively exploited vulnerabilities and severe incidents

    Checked