Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

Find and work with a notified body

Last updated:

A notified body is an independent conformity-assessment body authorised by a Member State and notified to the Commission for specific CRA tasks. A manufacturer may choose any notified body in the EU whose published scope covers the relevant product and procedure.

  1. Open the Commission’s NANDO database.
  2. Search under Regulation (EU) 2024/2847 — Cyber Resilience Act.
  3. Check the identification number, country and contact details, but above all the notified scope.
  4. Confirm that the scope covers your product type and the required procedure — module B and/or module H.
  5. Recheck the live NANDO record on the date of selection. General accreditation or notification under another law is not enough; the body must be notified under the CRA.

Prepare before making contact

Ask for written confirmation of scope, schedule, fees, required evidence, product-change rules and the process for resolving non-conformities. A notified body must act proportionately and take account of company size, but it may not lower the required rigour or protection level.

Important: the NANDO entry is the authoritative practical check of notification status and scope. A logo, marketing claim or certificate under another regime is not a substitute.