Whether a notified body is required depends primarily on product classification and the Article 32 route. Default-category products can generally use Module A, although a manufacturer may choose a stricter procedure. Class I has conditional third-party assessment. Class II requires one of the stricter Article 32(3) routes. Critical products follow Article 32(4). A qualifying cybersecurity certification route can sometimes serve instead of a notified-body Module B plus C or Module H procedure.
Third-Party Assessment Starts With Article 32 Classification
There is no single rule that every product with digital elements requires a notified body. Article 32 makes the conformity route depend on product classification and, for important class I products, on the conformity references applied to the relevant essential cybersecurity requirements. Manufacturers should therefore classify the product before deciding whether internal control is sufficient or a third-party procedure is required.
- Default-category product.
- Important product class I.
- Important product class II.
- Critical product.
- Qualifying Annex III free and open-source software.
Default-Category Products Can Generally Use Module A
Products that are not classified as important or critical can generally use the Article 32(1) internal control procedure based on Module A. The manufacturer remains free to choose a stricter conformity procedure involving a third party if it considers that appropriate. Third-party assessment is therefore possible for a default-category product without being automatically mandatory.
- Module A generally remains available.
- Third-party assessment is not automatically mandatory.
- Manufacturer may voluntarily choose a stricter route.
- Annex I requirements remain unchanged regardless of route.
Important Class I Products Have a Conditional Third-Party Trigger
Article 32(2) creates the key conditional third-party rule for important class I products. For the relevant essential cybersecurity requirements, the product and manufacturer processes must be submitted to Module B followed by Module C or to Module H where the manufacturer has not applied or has applied only in part the relevant harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least substantial, or where those relevant conformity references do not exist.
- Relevant harmonised standard not applied.
- Relevant harmonised standard applied only in part.
- Relevant common specification not applied.
- Relevant common specification applied only in part.
- Relevant qualifying certification scheme not applied or only partly applied.
- Relevant conformity reference does not exist.
The Class I Trigger Applies to the Relevant Essential Requirements
Article 32(2) ties the mandatory procedure to the essential cybersecurity requirements concerned. The manufacturer should therefore map the product's Annex I requirements to the harmonised standards, common specifications or qualifying certification scheme being relied upon. A generic statement that the product uses a standard is not enough if the standard does not cover the relevant requirement or has only been partially applied.
- Identify applicable Annex I requirements.
- Identify the conformity reference relied upon.
- Map coverage to each relevant requirement.
- Record partial application.
- Document the procedure decision.
Class I Third-Party Routes Are Module B Plus C or Module H
Where the Article 32(2) trigger applies, the manufacturer uses either the EU-type examination procedure based on Module B followed by conformity to EU-type based on Module C, or the full quality assurance procedure based on Module H. Module B alone is not the complete B plus C conformity route because the approved EU type must subsequently be followed by Module C production control.
- Module B followed by Module C.
- Or Module H.
- Module B is the EU-type examination stage.
- Module C addresses conformity to the approved EU type.
Important Class II Products Use Article 32(3)
Important products in Annex III class II do not use ordinary Module A as their standard route. Article 32(3) requires conformity to be demonstrated through Module B followed by Module C, Module H, or, where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9) at assurance level at least substantial.
- Module B plus C.
- Module H.
- Qualifying cybersecurity certification scheme.
- Ordinary Module A is not the Article 32(3) route.
Class II Does Not Depend on the Same Standards Trigger as Class I
The Article 32(3) rule for important class II products is structurally different from the class I rule. Class II does not become eligible for ordinary Module A merely because relevant harmonised standards have been fully applied. Article 32(3) itself specifies the permitted procedures. This is why a manufacturer should not reuse the class I decision tree for a class II product.
- Class I has a conditional Article 32(2) trigger.
- Class II directly follows Article 32(3).
- Full standards application does not create an ordinary Module A class II route.
- Document classification before procedure selection.
Critical Products Follow Article 32(4)
Critical products with digital elements listed in Annex IV follow Article 32(4). Where the conditions in Article 8(1) are met, conformity is demonstrated using the required European cybersecurity certification scheme. Where those conditions are not met, Article 32(4) directs the manufacturer to one of the procedures referred to in Article 32(3). A critical product should therefore not be routed through ordinary Module A.
- Confirm Annex IV classification.
- Check Article 8(1) conditions.
- Use the relevant cybersecurity certification scheme where required.
- Otherwise use an Article 32(3) procedure.
A Certification Scheme Can Be an Alternative to a Notified-Body Route
Third-party conformity under the CRA is not limited to Module B plus C or Module H. Article 32 also recognises European cybersecurity certification schemes where available and applicable under the conditions specified by the Regulation. For class II products, the Article 32(3) certification route requires assurance level at least substantial. Manufacturers should therefore distinguish a notified-body conformity procedure from conformity demonstrated through a qualifying cybersecurity certification scheme.
- Notified-body route: Module B plus C.
- Notified-body route: Module H.
- Separate qualifying certification route where available and applicable.
- Check the assurance level and legal applicability.
Qualifying Annex III FOSS Has the Article 32(5) Exception
Article 32(5) creates a specific exception for manufacturers of products qualifying as free and open-source software that fall within Annex III categories. Those manufacturers may use one of the Article 32(1) procedures, including Module A, if the Article 31 technical documentation is made available to the public when the product is placed on the market. This exception means an Annex III classification does not by itself settle the procedure for qualifying FOSS products.
- Product qualifies as free and open-source software.
- Product falls within Annex III.
- Article 32(1) procedures become available.
- Technical documentation must be public at market placement.
A Notified Body Must Be Properly Notified for the CRA
Where the applicable route involves a notified body, the manufacturer should use a body notified for the relevant CRA conformity assessment activities. CRA notified bodies are conformity assessment bodies that have completed the notification process and are authorised to perform the applicable activities within their notification scope. Manufacturer due diligence should therefore include confirming the body's status and scope rather than choosing a security consultancy merely because it offers testing services.
- Confirm notified-body status.
- Confirm CRA notification scope.
- Confirm the relevant module.
- Distinguish notified-body assessment from ordinary security consultancy.
Third-Party Assessment Covers Product and Manufacturer Processes
Article 32 requires assessment of both the product with digital elements and the processes put in place by the manufacturer. The third party therefore does not examine only a binary, firmware image or hardware specimen. Depending on the procedure, the assessment also addresses the manufacturer's vulnerability handling processes and the evidence demonstrating conformity with Annex I Part II.
- Product requirements under Annex I Part I.
- Vulnerability handling under Annex I Part II.
- Technical documentation.
- Supporting evidence.
- Relevant security testing.
Technical Documentation Must Be Ready for Third-Party Review
A third-party route does not replace the manufacturer's technical documentation obligation. Module B expressly requires technical documentation capable of assessing conformity and including an adequate analysis and assessment of risks. The notified body also examines supporting evidence for the technical design, development solutions and vulnerability handling processes. Manufacturers should therefore complete the evidence package before expecting the third party to close the conformity assessment.
- Article 31 technical documentation.
- Annex VII content.
- Cybersecurity risk assessment.
- Architecture and design evidence.
- Vulnerability handling evidence.
- Test results and supporting evidence.
Third-Party Findings Must Be Corrected
A notified body is not required to approve a product merely because an assessment has been purchased. Article 47 requires the body to identify non-compliance and require corrective measures where applicable requirements are not met. Under Module B, where the type and vulnerability handling processes do not satisfy the applicable Annex I requirements, the notified body refuses to issue the EU-type examination certificate and gives detailed reasons.
- Assessment can identify non-conformity.
- Corrective measures are required.
- Evidence may need to be updated.
- Module B certificate can be refused.
- Retesting or reassessment may be required.
A Practical Third-Party Assessment Decision Tree
First classify the product. If it is a default-category product, Module A is generally available and third-party assessment is optional. If it is class I, apply the Article 32(2) standards, common-specifications and certification-coverage test. If it is class II, select an Article 32(3) route. If it is critical, apply Article 32(4). If an Annex III product qualifies as free and open-source software, separately test the Article 32(5) exception.
- 1. Determine product classification.
- 2. Check whether Module A remains available.
- 3. For class I, apply Article 32(2).
- 4. For class II, apply Article 32(3).
- 5. For critical products, apply Article 32(4).
- 6. For qualifying Annex III FOSS, check Article 32(5).
- 7. Record the route decision.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.