What is a notified body under the Cyber Resilience Act?
A CRA notified body is a conformity assessment body that has been assessed, designated, and notified for CRA conformity assessment tasks. It may be public or private, but it must meet the CRA requirements for legal personality, independence, competence, impartiality, confidentiality, and operational capability.
A body does not become a CRA notified body just because it performs cybersecurity audits, penetration testing, certification, or assessments under another EU law. For CRA purposes, the notification procedure must be completed and the body's public notification must cover the relevant CRA activities.
Defines notified bodies and sets the Article 39 requirements for independence, competence, impartiality, confidentiality, and capability.
Explains that notified bodies are assessed by Member State notifying authorities and listed through NANDO.