Conformity · deep dive

CRA self-assessment vs. notified body: which route applies?

The CRA lets most manufacturers assess their own conformity — but not all. Which route you’re on is decided by how your product is classified, and getting that wrong late is expensive. Here’s how to tell, and what each route asks of you.

Updated 7 Jul 2026·~6 min read·For compliance & GRC leads

"Do we need a notified body?" is one of the first questions a compliance lead asks about the CRA, and the answer is usually reassuring — but not always, and the exceptions are the ones you want to spot early rather than in the last quarter of 2027.

Classification decides the route

The CRA doesn't let you pick your conformity route; your product's classification picks it for you. Three tiers, escalating scrutiny:

ClassRouteThird party?
DefaultModule A — internal controlNo
Important, Class ISelf-assess with harmonised standards, else third-partyConditional
Important, Class IIEU-type examination or full quality assuranceYes
CriticalThird party, up to European cybersecurity certificationYes

Default class: you self-assess

The large majority of products are default class and use Module A — internal control. You assess the product against the Annex I essential requirements yourself, compile the technical file, draw up and sign the Declaration of Conformity, and affix the CE mark. No external body is involved. This is the path most manufacturers will take, and it's entirely runnable in-house.

Important class: it depends

Products in Annex III are "important" and split in two. Class I can still self-assess — if it applies the relevant harmonised standards (or a cybersecurity certification scheme); without them, it falls to a third-party route. Class II doesn't get the shortcut: it requires a third-party route such as EU-type examination (Module B+C) or full quality assurance (Module H). The catch today is that the harmonised standards Class I would lean on aren't published yet, so the self-assess shortcut may not be available in practice at launch.

Critical class: third party, and then some

Annex IV "critical" products — the highest-risk categories — face the strictest route, potentially requiring European cybersecurity certification under an EU scheme at a defined assurance level. If your product is here, a third party is unavoidable and the lead time is long. Confirm this early.

Whichever route: the bar is the same

Self-assessment removes the notified body, not the requirements.

This is the point teams miss. Self-assessing doesn't mean a lighter standard — you meet the same essential requirements, hold the same ten-year technical file, and can be asked by a market-surveillance authority to justify any decision in it. The difference between the routes is who signs off, not how much rigour is required. That's why the evidence behind your vulnerability determinations matters regardless of route — it's the substance of the technical file either way. The full conformity mechanics are in the conformity & CE marking pillar; for a thin team, CRA compliance for SMEs covers doing it defensibly without a department.

Frequently asked

Can I self-assess under the CRA?

For most products, yes. Default-class products use Module A internal control — you assess conformity yourself, with no notified body. You still compile the full technical file and sign the Declaration of Conformity, and keep them for ten years.

When do I need a notified body?

When your product is important Class II or critical, or important Class I without applying the relevant harmonised standards. These routes require third-party involvement — EU-type examination, full quality assurance, or for critical products European cybersecurity certification.

Does self-assessment mean lower requirements?

No. Self-assessment removes the third party, not the requirements. You meet the same Annex I essential requirements and hold the same technical documentation; you attest to conformity yourself, and an authority can still hold you to the same evidence bar.

Design partners

Assemble the evidence either route needs.

Whether you self-assess or prepare a notified-body package, the technical file is built from the same evidence trail. See how it assembles from your vulnerability handling.