CRA guide
Do you need a notified body under the CRA?
Whether you self-assess or need third-party involvement depends entirely on which of the CRA's three tiers your product falls into. Here's what's on the important and critical lists, and what each tier requires (CRA Article 32).
Default category — self-assessment, no notified body
Everything not listed in Annex III or Annex IV is default category — roughly 90% of products. You demonstrate conformity by internal control (Module A, Annex VIII): no notified body involved.
Important, Class I (CRA Annex III)
Class I products can still self-assess (Module A) if you fully apply the relevant harmonised standards, common specifications, or a cybersecurity certification scheme at “substantial” assurance level. If you haven't — or none exist yet — you move to third-party assessment (CRA Article 32(2)): EU-type examination (Module B) plus production control (Module C), or full quality assurance (Module H).
- Identity- and privileged-access-management software/hardware, incl. authentication and access-control readers (incl. biometric)
- Standalone and embedded browsers
- Password managers
- Anti-malware software (search, remove or quarantine)
- Products with a VPN function
- Network management systems
- Security information and event management (SIEM) systems
- Boot managers
- Public key infrastructure and digital-certificate issuance software
- Physical and virtual network interfaces
- Operating systems
- Routers, internet-connection modems, and switches
- Microprocessors with security-related functionality
- Microcontrollers with security-related functionality
- ASICs and FPGAs with security-related functionality
- Smart-home general-purpose virtual assistants
- Smart-home products with security functionality (smart locks, security cameras, baby monitors, alarm systems)
- Internet-connected toys with social-interactive or location-tracking features
- Personal wearables with a health-monitoring purpose (not already covered by EU medical-device rules), or wearables intended for children
Important, Class II (CRA Annex III)
Class II always requires third-party involvement (CRA Article 32(3)): EU-type examination (Module B) plus production control (Module C), full quality assurance (Module H), or a substantial-level certification scheme. There's no self-assessment route for Class II, regardless of standards applied.
- Hypervisors and container-runtime systems supporting virtualised OS execution
- Firewalls, intrusion detection and prevention systems
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Critical (CRA Annex IV)
Critical products use a European cybersecurity certification scheme where one exists and applies (CRA Article 8(1)); otherwise they fall back to the Class II procedures above (CRA Article 32(4)).
- Hardware devices with security boxes
- Smart-meter gateways within smart metering systems, and other devices for advanced security purposes incl. secure cryptoprocessing
- Smartcards or similar devices, including secure elements
Practical takeaway
If your product isn't on either list, you're default category and self-assessment applies. If it is, the specific class — and whether you've applied harmonised standards in full — determines whether you can still avoid a notified body. When in doubt, classify the specific product rather than guessing from the category name.
Key points
- Default (not listed) = internal control, no notified body.
- Important Class I (19 categories, Annex III) = self-assess only if harmonised standards are fully applied; otherwise third-party.
- Important Class II (4 categories, Annex III) = always third-party assessment.
- Critical (3 categories, Annex IV) = certification scheme, or the Class II procedures as a fallback.
Frequently asked questions
- Does “important” always mean I need a notified body?
- Not necessarily for Class I — you can still self-assess if you fully apply the relevant harmonised standards or a substantial-level certification scheme. Class II and critical products require third-party involvement in all cases.
- My connected device isn't on either list — am I default category?
- If it doesn't match an Annex III or Annex IV category, yes. Run the free readiness check to confirm against your product's specific function.
Related
General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.