Academy

11 July 2026 · 5 min read

What is a notified body, and do you need one?

Most CE-marked hardware is self-declared with no outside review. A notified body only enters the picture for specific, higher-risk product categories.

By The Conformery Team

Engineer in safety gear inspecting industrial machinery, representing the third-party conformity assessment a notified body carries out

Photo: Photo by Sergey Sergeev on Pexels

Most founders hear "notified body" and assume every CE-marked product needs one to sign off before it can ship. For the large majority of hardware — routers, sensors, chargers, consumer electronics under the standard Low Voltage, EMC and Radio Equipment directives — that's not true. You self-declare, and a notified body never enters the process at all unless your specific product category or your chosen conformity route requires one.

What a notified body actually is

A notified body is a private, independent conformity-assessment organisation — not a government office — that has been formally assessed, designated and is actively monitored by an EU member state before it's authorised to carry out third-party conformity assessments under specific EU legislation. Being "notified" means the European Commission and other member states have been told this organisation is authorised to issue conformity certificates for the specific product categories and directives it's been designated for — a notified body accredited for machinery isn't automatically authorised for medical devices or radio equipment.

When self-declaration is enough

Under most CE directives relevant to general hardware — Low Voltage, EMC, and standard-risk Radio Equipment — the manufacturer can self-assess: apply the relevant harmonised standards, compile the technical file, and sign the Declaration of Conformity yourself, with no external body reviewing it before you ship. This is the same "module A" self-declaration route the Cyber Resilience Act borrows for its own default product category.

When a notified body becomes mandatory

Third-party assessment via a notified body is required where the underlying legislation specifically demands it — typically for higher-risk product categories or where you haven't applied a relevant harmonised standard in full and need an alternative route to demonstrate conformity. In the compliance space this checker covers, the clearest example is the Cyber Resilience Act's Important Class II and Critical product tiers, where self-assessment isn't available at all, regardless of what standards you've applied — a notified body (or an approved cybersecurity certification scheme) is required outright.

How to find out if you need one

  • Identify every directive or regulation that applies to your product (CE-relevant directives, and separately the CRA if your product has digital elements) — each has its own conformity-assessment rules.
  • Check whether your specific product falls into a category, or a risk class, that the legislation explicitly routes to third-party assessment.
  • If you're self-declaring, confirm you've actually applied the relevant harmonised standards in full — partial or non-standard compliance is one of the more common reasons a manufacturer ends up needing a notified body they didn't expect to.

Run your product through the free requirements checker to see which directives apply and whether any of them push you toward third-party assessment.

Sources

  1. 01European Commission — Cyber Resilience Act: Conformity assessment
  2. 02European Commission — CE marking

Not sure which rules apply to you?

Answer a few honest questions about your product and see every applicable regulation for the EU, UK and US, each linked to its official source.

Check your requirements

Related reading