Cyber Resilience Act
Conformity assessment body
Legal definition Art. 3(28) CRA
“a conformity assessment body as defined in Article 2, point (13), of Regulation (EC) No 765/2008”
A conformity assessment body is an organisation that performs conformity assessment activities: testing, calibration, certification and inspection. The Cyber Resilience Act (CRA) does not define the term itself in Article 3, point (28). It points instead to Article 2, point (13), of Regulation (EC) No 765/2008, where the operative wording sits: “a body that performs conformity assessment activities including calibration, testing, certification and inspection”.
That cross-reference is not a formality. Regulation (EC) No 765/2008 governs accreditation and market surveillance horizontally, across the whole single market. So the CRA does not build its own assessment landscape; it plugs into the existing one of test laboratories, certification bodies and inspection bodies, many of which have nothing to do with products with digital elements.
How this differs from a notified body
The two terms sit next to each other in Article 3 and get mixed up constantly. Under point (29), a Notified body is a conformity assessment body designated in accordance with Article 43 and other relevant Union harmonisation legislation. Every notified body is therefore a conformity assessment body. The reverse does not hold.
For manufacturers, that is where the practical weight of the term lies. A laboratory can have been accredited for years and still be unable to issue an attestation that counts in a CRA procedure. Article 43(5) puts it plainly: the body may perform the activities of a notified body only where no objections are raised by the Commission or the other Member States within the period following notification, and only such a body is considered a notified body for the purposes of the Regulation.
What Article 39 requires
The heading of Article 39 speaks of notified bodies, while its text addresses the conformity assessment body. For the purposes of notification, that body shall meet the requirements in paragraphs 2 to 12. Those requirements have to be satisfied before notification, not after it. Six points carry the weight:
- Legal form: established under national law and holding legal personality
- Independence: a third-party body that is not the designer, developer, manufacturer, supplier, importer, distributor, installer, purchaser, owner, user or maintainer of the products it assesses, nor the authorised representative of any of those parties
- Freedom from conflicts of interest: no activity that may conflict with independence of judgement or integrity in relation to the conformity assessment activities the body is notified for, which paragraph 4 applies expressly to consultancy services
- Competence: personnel, documented and reproducible procedures, means and access to all necessary equipment for every Annex VIII task it is notified for; assessment staff must know the essential cybersecurity requirements in Annex I, the applicable harmonised standards and the common specifications
- Impartiality: remuneration of top level management and assessment personnel must not depend on the number of assessments carried out or on their results
- Insurance and secrecy: liability insurance unless the Member State assumes liability, and professional secrecy, with an exception only towards the Market surveillance authority of the Member State where the body operates
Two further duties reach beyond any single engagement. The body participates in relevant standardisation work and in the notified body coordination group set up under Article 51, or ensures that its assessment personnel are informed of those activities. And it operates on consistent, fair, proportionate and reasonable terms and conditions, avoiding unnecessary burden for economic operators and taking the interests of microenterprises and small and medium-sized enterprises into account, particularly on fees.
The route to notification
The body applies to the Notifying authority of the Member State in which it is established (Article 42). The application carries a description of the conformity assessment activities, the procedures and the products for which the body claims competence, plus, where applicable, an accreditation certificate from a national accreditation body attesting that the body fulfils the requirements of Article 39.
Going without an accreditation certificate is possible, just harder. The body then supplies all documentary evidence needed to verify, recognise and regularly monitor its compliance with Article 39. The cost of that route shows up in the objection window under Article 43(5): two weeks with an accreditation certificate, two months without one. Member States may in any case have the assessment and monitoring carried out by a national accreditation body under Regulation (EC) No 765/2008 (Article 36(2)).
The CRA also grants the body a presumption of conformity of its own. Where it demonstrates conformity with the criteria of relevant harmonised standards or parts thereof whose references have been published in the Official Journal of the European Union, it is presumed to comply with Article 39 in so far as those standards cover the requirements (Article 40). That presumption attaches to the body, not to the products it later assesses.
What happens to an existing notification under other Union law that lays down similar requirements is not settled by any article, but by recital 100. It gives the example of a body notified for a European cybersecurity certification scheme adopted under Regulation (EU) 2019/881, or notified under Delegated Regulation (EU) 2022/30: such a body should be newly assessed and newly notified under the CRA. Where requirements overlap, the same recital lets the relevant authorities define synergies to avoid duplicated work.
Why this already matters in 2026
Chapter IV, Articles 35–51, applies from 11 June 2026, while the CRA otherwise applies from 11 December 2027 and Article 14 from 11 September 2026 (Article 71(2)). The sequence is deliberate. Bodies first have to meet the requirements and be notified, and only then can manufacturers commission a third-party Conformity assessment at all. Under Article 35(2), Member States shall strive to ensure that a sufficient number of notified bodies exists in the Union by 11 December 2026, so as to avoid bottlenecks and hindrances to market entry.
If you need external assessment, two questions belong at the start of the search. Is the body actually notified under the CRA, or does it so far only meet the Article 39 requirements? And does its notification cover the module and the product category that your procedure under Article 32 calls for?
Practical questions
-
For the same product, effectively no. Article 39(4) bars the body from being directly involved in the design, development, production, import, distribution, marketing, installation, use or maintenance of the products it assesses. It also bars any activity that may conflict with independence of judgement or integrity in relation to the conformity assessment activities for which it is notified, and it names consultancy services expressly. That is not a blanket ban on consultancy across the industry, but it does force a separation case by case: whoever helped build your vulnerability handling process cannot then assess it. Settle the roles before you sign.
-
Yes, on one condition. Article 39(3) expressly allows a body to belong to a business association or professional federation whose member undertakings are involved in the design, development, production, provision, assembly, use or maintenance of the products it assesses. It may then be considered an independent third-party body provided its independence and the absence of any conflict of interest are demonstrated. That demonstration belongs to the notification procedure under Articles 42 and 43, not to you as a manufacturer. Association membership alone therefore rules nothing out.
-
Personnel of a conformity assessment body observe professional secrecy for all information obtained in carrying out their tasks under Annex VIII, and proprietary rights are protected (Article 39(10)). The only exception is the market surveillance authorities of the Member State where the body carries out its activities. The body must have documented procedures ensuring this, and you can ask to see them before you appoint it. If a notified body passes work to a subsidiary or subcontractor, it needs your agreement, and that subsidiary or subcontractor has to meet the same Article 39 requirements (Article 41).
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.