Do I need a notified body under the Cyber Resilience Act?
For most software makers the answer is no, and knowing that early saves both money and dread.
Default products — everything not listed in the important or critical categories — may use internal control, Module A: the manufacturer assesses conformity itself, with no third party involved [1]. Ordinary mobile apps, desktop tools, games, SaaS companion software and business applications are default products, and they never see a notified body [1].
Where a notified body enters
The third-party routes attach to the classed categories.
An important class I product — the 19 Annex III class I categories — must use EU-type examination plus internal production control (Modules B and C), full quality assurance (Module H), or a certification scheme at assurance level substantial, unless it applies harmonised standards, common specifications or such a scheme in full, which reopens self-assessment [2] [1]. An important class II product — the four class II categories — has no self-assessment path at all: Modules B and C, Module H, or a scheme at level substantial [3] [1]. A critical product — the three Annex IV categories — uses a European certification scheme where available, otherwise the class II procedures [4] [1].
So the notified-body question reduces to the classification question, and classification runs on the binding category descriptions — which is exactly what the checker walks through [1].
The timing problem nobody should ignore
Two supply constraints sit behind the third-party routes right now. No harmonised standards have yet been cited in the Official Journal — the standardisation request covers 41 standards with first deliverables expected in Q3 2026 — so the class I escape hatch of applying standards in full is not yet usable [5]. And the notified bodies themselves are still being designated, with the Commission targeting sufficient capacity by December 2026 on a best-efforts basis [6].
Full application lands on 11 December 2027 [7]. If your product is classed, the window between "assessment capacity exists" and "assessment must be complete" is tight, and it is shared with every other classed product in the market [6] [7]. Booking early is the whole strategy.
What to do with a genuine class I product today
The class I position is the interesting one, because it has two futures: if usable harmonised standards arrive in time and you apply them in full, you self-assess; if not, you need the notified-body slot [1] [5]. Prepare for both — build the technical file as if self-assessing, and get in a notified body's intake queue as insurance. The file is required either way, so none of that work is wasted [1].
Check where you stand
The checker classifies your product against the binding descriptions and tells you plainly: self-assessment, third party, or standards-dependent — with citations for each step.
What to do next
Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.
Sources
- Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIII — EUR-Lex ↩
- Annex III Class I — important products, class I (items 1–19). Annex III Class I; Implementing Regulation (EU) 2025/2392 — EUR-Lex ↩
- Annex III Class II — important products, class II (items 1–4). Annex III Class II; Implementing Regulation (EU) 2025/2392 — EUR-Lex ↩
- Annex IV — critical products (items 1–3). Annex IV; Implementing Regulation (EU) 2025/2392 — EUR-Lex ↩
- No harmonised standards for the CRA have been cited in the Official Journal as of the facts date; the Commission’s standardisation request M/606 covers 41 standards, with the first deliverables expected in Q3 2026. Commission / CEN-CENELEC — EUR-Lex ↩
- Notified bodies for the CRA are being designated; the Commission targets sufficient capacity by December 2026 (best efforts). Commission — EUR-Lex ↩
- The Regulation applies in full from 11 December 2027. Art. 71(2) — EUR-Lex ↩
Related
- Is my product an important product class I under the CRA?
Class I is the first tier of "important" products — 19 categories including password managers, VPNs, browsers and smart home assistants — and it changes which conformity route you may use, not whether you are in scope.
- Is my product an important product class II under the CRA?
Class II is the higher "important" tier — hypervisors, firewalls, tamper-resistant microprocessors and similar security-critical categories — and it removes self-assessment entirely: a notified body or certification scheme is mandatory.
- Is my product a critical product under Annex IV of the CRA?
Critical products are the three Annex IV categories — hardware devices with security boxes, smart meter gateways, and smartcards or similar secure elements. Almost no software product is on this list.
- What goes in a CRA declaration of conformity?
A one-document statement, in the Annex V structure, in which the manufacturer takes sole responsibility that the product meets the essential requirements. A simplified web-linked form exists, and it travels with the product's paperwork for a decade or more.
CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 10 September 2026 (Facts v2026.09.4). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.