A notified body is an independent conformity-assessment body authorised by a Member State and notified to the Commission for specific CRA tasks. A manufacturer may choose any notified body in the EU whose published scope covers the relevant product and procedure.
How to search
- Open the Commission’s NANDO database.
- Search under Regulation (EU) 2024/2847 — Cyber Resilience Act.
- Check the identification number, country and contact details, but above all the notified scope.
- Confirm that the scope covers your product type and the required procedure — module B and/or module H.
- Recheck the live NANDO record on the date of selection. General accreditation or notification under another law is not enough; the body must be notified under the CRA.
Prepare before making contact
- product description, version, boundaries and intended purpose;
- classification rationale under Annex III or IV and Regulation 2025/2392;
- selected module and requested assessment scope;
- architecture and baseline technical documentation;
- cybersecurity risk assessment and mapping to Annex I;
- standards, common specifications or certifications used, and the gaps the assessment must cover; and
- planned release, production and support-period dates.
Ask for written confirmation of scope, schedule, fees, required evidence, product-change rules and the process for resolving non-conformities. A notified body must act proportionately and take account of company size, but it may not lower the required rigour or protection level.
Important: the NANDO entry is the authoritative practical check of notification status and scope. A logo, marketing claim or certificate under another regime is not a substitute.