Cyber Resilience Act (CRA)
Organizations interested in applying for notification as a Conformity Assessment Body (CAB) for the Cyber Resilience Act (CRA)
Regulation (EU) 2024/2847, known as the Cyber Resilience Act (CRA), establishes a common cybersecurity framework for products with digital elements placed on the market in the European Union. Its scope covers software products, hardware, and remote data processing solutions, including components sold separately.
The main objective of the CRA is to significantly strengthen the security of these products by establishing obligations directly applicable to economic operators.
Compliance with the CRA is demonstrated through a product conformity assessment process, the result of which is evidenced, among other things, by the European Commission mark, which reflects compliance with the specific cybersecurity requirements established in the Regulation.
For certain product categories, particularly important Class II products and critical products, the Cyber Resilience Act (CRA) requires the involvement of a notified Conformity Assessment Body (CAB), which acts as an independent third party to verify compliance with the cybersecurity requirements set out in the Regulation.
CABs play a vital role in ensuring the consistent, reliable, and technically sound application of the CRA throughout the internal market. Once notified by a Member State, they can provide their services across the European Union under the principle of mutual recognition.
CRA Implementation Timetable
The Cyber Resilience Act is being implemented progressively, according to the timetable set out in the Regulation:
- November 20, 2024 – Publication in the Official Journal of the European Union. The Cyber Resilience Act is officially published in the OJEU, and the countdown to its entry into force begins (OJEU L, Regulation (EU) 2024/2847).
- December 10, 2024 – Entry into force of the Regulation. The CRA formally enters into force as an EU Regulation, becoming part of the legal order, although most of the substantive obligations are not yet applicable (Article 71(1)).
- June 11, 2026 – From this date, the CRA provisions relating to the designation of notifying authorities and the notification of Conformity Assessment Bodies (CABs) come into effect (Chapter IV; Article 71(2)(b) of Regulation (EU) 2024/2847).
- September 11, 2026 – Commencement of vulnerability and incident notification obligations. Manufacturers are required to notify actively exploited vulnerabilities and certain cybersecurity incidents, including those related to products already on the market (Article 14; Article 71(2)(a)).
- December 11, 2026 — Member States shall endeavor to ensure, by December 11, 2026 at the latest, that there are a sufficient number of notified bodies in the Union to carry out conformity assessments, in order to avoid bottlenecks and barriers to market access.
- December 11, 2027 — Full application of the Cyber Resilience Act. All substantive obligations of the CRA shall apply in full to products with digital elements placed on the Union market, including conformity assessment and CE marking (Article 71(2)(c)).
Transitional notification procedure
While the European Commission completes the development and adoption of the harmonised rules and other standards necessary for the full implementation of the CRA, the Notifying Authority has developed a procedure for processing the notification of a Conformity Assessment Body (CAB), which consists of the following steps:
1.
Before initiating the notification procedure, the applicant entity must obtain accreditation from ENAC in accordance with the requirements established in the transitional procedure. This accreditation, which will constitute an expansion of the scope of the accreditation granted under ISO/IEC 17065, will serve as the technical and legal basis for the Notifying Authority to carry out the designation and subsequent notification of the body.
2.
The applicant entity shall submit a notification request to the Notifying Authority, which shall include:
- Legal and administrative information
- Organizational information
- Technical information
- Personnel information
- Subcontracting information
- Accreditation for the transitional procedure for the CRA issued by ENAC
3.
4.
The notification will take effect upon its publication in the NANDO system. Only from that moment may the organization act as a CRA Notified Body within its authorized scope.
Organizations eligible for the Fast-Track procedure
Organizations that meet at least one of the following criteria may be eligible for the Fast-Track procedure defined by the European Commission:
- Notified bodies under Directive 2014/53/EU (RED) that are accredited according to ISO/IEC 17065 and whose technical competence in cybersecurity has been assessed;
- Certification bodies accredited according to ISO/IEC 17065 that operate under the EUCC scheme and wish to expand their scope to include CRA activities.
Laboratories (ITSEF) accredited under ISO/IEC 17025 are excluded from this accelerated mechanism and may only participate through subcontracting or agreements, under the responsibility of a certification body.
Documentation and contact
To facilitate the preparation of interested organizations, the Notifying Authority provides the documentation for the Fast Track v1 procedure.
For any questions related to the notification process or the transitional procedure, you can contact the Notifying Authority via the following email address: 



