The EU Cyber Resilience Act (CRA) introduces mandatory cybersecurity requirements for products with digital elements. For many manufacturers, compliance will involve a Cyber Resilience Act Notified Body (NB) or certification under an EU cybersecurity scheme such as EUCC.
Applus+ Laboratories is progressing through the CRA Notified Body accreditation and notification process and already performs CRA-aligned testing and documentation reviews that can be reused later in formal NB assessments. This helps you reduce delays, minimize rework, and keep your development roadmap on track while CRA standards and guidance continue to evolve.
Complete our quick form
A CRA Notified Body is an independent, accredited organization designated to perform third-party conformity assessment against CRA essential cybersecurity requirements. In practice, a Notified Body will:
For Important and Critical products, third-party assessment will be required. Specifically for Important Class I, third-party assessment is needed unless harmonized standards become available and allow self-assessment under Module A.
EU member states are currently working on the designation of CRA Notified Bodies. At this stage, formal listings are still pending, but the CRA implementation timeline is already running, and manufacturers cannot wait until the last moment to start preparing.
At Applus+ Laboratories, we have structured our CRA services so that testing and assessments performed today can be partially reused as input for future NB evaluations, once the formal designation is completed. This allows you to start building evidence and closing gaps well before CRA becomes fully applicable.
CRA-specific standards are still under development, and their approval and publication process includes multiple steps. In the short and medium term, this means that:
The CRA offers different conformity assessment routes. The most relevant ones for manufacturers are summarized below.
Under Module A, the manufacturer performs an internal conformity assessment and issues the EU declaration of conformity without involving a Notified Body.
When is it possible?
Key limitations:
Module B + C is the primary third-party route under the CRA for many products:
Advantages of Module B + C:
Under Module H, conformity is based on the assessment of the manufacturer’s cybersecurity quality management system, covering design, development, production and vulnerability handling, rather than on individual product testing. The system is assessed and subject to ongoing surveillance by a Notified Body, and compliant products bear the CE marking.
Advantages of Module H:
In addition to the CRA-specific modules, certain products — particularly Important and Critical categories — may rely on EU cybersecurity certification schemes under the Cybersecurity Act, such as EUCC.
In practice, this route is particularly suitable for manufacturers that already use EUCC or Common Criteria certification in the market. These products are often classified as Important or Critical under the CRA and typically play a security enabling role for other systems. EUCC builds on existing Protection Profiles and Common Criteria assessments, and can provide strong, reusable evidence of conformity relevant for CRA compliance, especially where presumption of conformity applies and where regulators or security-sensitive customers expect certified assurance.
Further analysis on how EUCC can be used in the context of CRA compliance is discussed in Applus+ Laboratories’ publication based on the EUCC scheme webinar.
Even when self-assessment could be legally possible in the future, working with a Notified Body provides significant strategic advantages. As highlighted in the Cyber Global Marketing Plan, the key principle is: “Evaluate now. Reuse later. Reduce rework.”
Benefits of involving a Notified Body:
You do not need to wait for harmonised standards or official NB listings to begin your CRA journey. Applus+ Laboratories already offers CRA-oriented services that can be reused within future Notified Body and EUCC evaluations, including:
This early work creates a solid evidence-base that you can build on, rather than starting from zero when CRA enforcement becomes critical.
Applus+ Laboratories provides a modular portfolio of precertification services specifically designed around CRA and future Notified Body assessments:
Applus+ Laboratories combines deep cybersecurity expertise with strong certification credentials:
Applus+ uses first-party and third-party cookies for analytical purposes and to show you personalized advertising based on a profile drawn up based on your browsing habits (eg. visited websites). You can accept all cookies by pressing the "Accept" button or configure or reject their use. Consult our Cookies Policy for more information.
They allow the operation of the website, loading media content and its security. See the cookies we store in our Cookies Policy.
They allow us to know how you interact with the website, the number of visits in the different sections and to create statistics to improve our business practices. See the cookies we store in our Cookies Policy.
Based on your behavior on the website (where you click, how long you browse, etc.) we establish parameters and a profile for you to display ads that correspond to your interests. See the cookies we store in our Cookies Policy.