"Do we need a notified body?" is one of the first questions a compliance lead asks about the CRA, and the answer is usually reassuring — but not always, and the exceptions are the ones you want to spot early rather than in the last quarter of 2027.
Classification decides the route
The CRA doesn't let you pick your conformity route; your product's classification picks it for you. Three tiers, escalating scrutiny:
| Class | Route | Third party? |
|---|---|---|
| Default | Module A — internal control | No |
| Important, Class I | Self-assess with harmonised standards, else third-party | Conditional |
| Important, Class II | EU-type examination or full quality assurance | Yes |
| Critical | Third party, up to European cybersecurity certification | Yes |
Default class: you self-assess
The large majority of products are default class and use Module A — internal control. You assess the product against the Annex I essential requirements yourself, compile the technical file, draw up and sign the Declaration of Conformity, and affix the CE mark. No external body is involved. This is the path most manufacturers will take, and it's entirely runnable in-house.
Important class: it depends
Products in Annex III are "important" and split in two. Class I can still self-assess — if it applies the relevant harmonised standards (or a cybersecurity certification scheme); without them, it falls to a third-party route. Class II doesn't get the shortcut: it requires a third-party route such as EU-type examination (Module B+C) or full quality assurance (Module H). The catch today is that the harmonised standards Class I would lean on aren't published yet, so the self-assess shortcut may not be available in practice at launch.
Critical class: third party, and then some
Annex IV "critical" products — the highest-risk categories — face the strictest route, potentially requiring European cybersecurity certification under an EU scheme at a defined assurance level. If your product is here, a third party is unavoidable and the lead time is long. Confirm this early.
Whichever route: the bar is the same
Self-assessment removes the notified body, not the requirements.
This is the point teams miss. Self-assessing doesn't mean a lighter standard — you meet the same essential requirements, hold the same ten-year technical file, and can be asked by a market-surveillance authority to justify any decision in it. The difference between the routes is who signs off, not how much rigour is required. That's why the evidence behind your vulnerability determinations matters regardless of route — it's the substance of the technical file either way. The full conformity mechanics are in the conformity & CE marking pillar; for a thin team, CRA compliance for SMEs covers doing it defensibly without a department.
Frequently asked
Can I self-assess under the CRA?
For most products, yes. Default-class products use Module A internal control — you assess conformity yourself, with no notified body. You still compile the full technical file and sign the Declaration of Conformity, and keep them for ten years.
When do I need a notified body?
When your product is important Class II or critical, or important Class I without applying the relevant harmonised standards. These routes require third-party involvement — EU-type examination, full quality assurance, or for critical products European cybersecurity certification.
Does self-assessment mean lower requirements?
No. Self-assessment removes the third party, not the requirements. You meet the same Annex I essential requirements and hold the same technical documentation; you attest to conformity yourself, and an authority can still hold you to the same evidence bar.