← All standards
CRA Article 32Conformity assessment

CRA notified bodies and testing laboratories

The conformity-assessment bodies and cybersecurity testing labs a manufacturer on a third-party route is most likely to engage as a Cyber Resilience Act notified body once designations are published. Filter by country and standard.

Do you need a notified body?

Most products with digital elements use internal control (Module A) and the manufacturer self-assesses, affixes the CE marking, and needs no notified body. A third-party conformity assessment, and therefore a notified body, applies to important products in Class II, critical products under Annex IV, and Class I products where the manufacturer does not fully apply the relevant harmonised standards.

Not sure which route applies? Run the free product classifier or the CRA self-assessment.

Verify designation in NANDO before relying on any body

As of 2026-07-14, the European Commission had not yet published notified bodies designated specifically under the CRA. The organisations below are established EU conformity-assessment bodies and accredited cybersecurity testing laboratories, listed as candidates you are likely to work with. None is asserted to hold a CRA designation. Always confirm current status in the official NANDO database.

Showing 9 of 9 organisations.

TÜV SÜD

Germany

Accredited lab
ETSI EN 303 645IEC 62443EUCCRED 3.3

Notified body under other EU directives and an accredited cybersecurity testing lab. CRA designation not confirmed.

Visit website →

TÜV Rheinland

Germany

Accredited lab
ETSI EN 303 645IEC 62443EUCC

Accredited cybersecurity testing lab. CRA designation not confirmed.

Visit website →

DEKRA

Germany

Accredited lab
ETSI EN 303 645EUCCRED 3.3

Accredited cybersecurity and RED testing lab. CRA designation not confirmed.

Visit website →

Applus+ Laboratories

Spain

Accredited lab
ETSI EN 303 645Common CriteriaEUCC

ITSEF / Common Criteria evaluation lab. CRA designation not confirmed.

Visit website →

SGS

Belgium

Accredited lab
ETSI EN 303 645RED 3.3IEC 62443

Global testing, inspection and certification body. CRA designation not confirmed.

Visit website →

Bureau Veritas

France

Accredited lab
ETSI EN 303 645RED 3.3

Conformity-assessment body active in connected-product testing. CRA designation not confirmed.

Visit website →

Eurofins Cyber Security

Netherlands

Accredited lab
ETSI EN 303 645Common CriteriaEUCCIEC 62443

Network of accredited security evaluation labs across the EU. CRA designation not confirmed.

Visit website →

UL Solutions

Germany

Accredited lab
ETSI EN 303 645IEC 62443

Accredited testing lab with EU operations. CRA designation not confirmed.

Visit website →

DNV

Norway

Accredited lab
IEC 62443

Certification body strong in industrial and OT security. CRA designation not confirmed.

Visit website →

CRA notified body questions

Are there CRA notified bodies yet?

As of 2026-07-14, the European Commission had not published any body designated specifically under the Cyber Resilience Act. Designations are expected to roll out ahead of the CRA application date of 11 December 2027. Until a body appears in NANDO against the CRA, treat every listing here as a candidate rather than a confirmed CRA notified body.

How do I verify a notified body's CRA designation?

Check the official NANDO database and confirm the body is designated against Regulation (EU) 2024/2847. A body designated under other EU legislation, such as the Radio Equipment Directive, is not automatically designated for the CRA.

When do I need a notified body under the CRA?

Only when a third-party conformity assessment applies. That covers important products in Class II, critical products under Annex IV, and Class I products where the manufacturer does not fully apply the relevant harmonised standards. Most products with digital elements use internal control (Module A) and need no notified body.

Which conformity assessment routes involve a notified body?

Under Article 32, EU-type examination (Module B followed by Module C) and full quality assurance (Module H) both involve a notified body. Internal control (Module A) is a manufacturer self-assessment and involves none.

Assemble an audit-ready technical file first

Whether you self-assess or engage a notified body, your Annex VII technical file is the deliverable.

Get Started for Free