Skip to main content
Glossary termPublished inEU AI ActCRA

Notifying authority

What does "Notifying authority" mean under the EU AI Act and the Cyber Resilience Act?

The national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring

Defined in / by

Last updated: 22 August 2026.

Regulations

  • Cyber Resilience Act (CRA)

    The Cyber Resilience Act is Regulation (EU) 2024/2847. Its reporting obligations under Article 14 apply from 11 September 2026, to every product with digital elements on the Union market, including products placed there before the Regulation's main obligations start on 11 December 2027. Actively exploited vulnerabilities must be reported within 24 hours.

    Next
    Article 14 reporting obligations apply: actively exploited vulnerabilities and severe incidents

    Checked

  • EU Artificial Intelligence Act (EU AI Act)

    The EU AI Act is Regulation (EU) 2024/1689. On 2 August 2026 its transparency rules and enforcement machinery took effect, but the high-risk regime for credit scoring and life and health insurance pricing did not: Regulation (EU) 2026/1744 moved it to 2 December 2027. Prohibitions have applied since February 2025.

    Next
    New Art. 5 prohibitions; Art. 50(2) marking deadline for pre-existing generative systems

    Checked