Cyber Resilience Act (CRA) › Chapter IV — Notification of conformity assessment bodies 1 Where a notified body subcontracts specific tasks connected with conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements set out in Article 39 and shall inform the notifying authority accordingly.
2 Notified bodies shall take full responsibility for the tasks performed by subcontractors or subsidiaries wherever they are established.
3 Activities may be subcontracted or carried out by a subsidiary only with the agreement of the manufacturer.
4 Notified bodies shall keep at the disposal of the notifying authority the relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation.
In practice Meroi Security’s note, not part of the regulation
Article 41 permits subcontracting and the use of subsidiaries with the manufacturer's agreement. The Blue Guide supplies the limit that makes the permission workable: a notified body may only subcontract a task for which it has the competence itself, and it may not subcontract a part of the work because it lacks the required competence and knowledge. Subcontractors need not be notified in their own right. The notifying authority assesses how far the body intends to rely on them, including outside the EU, and may withdraw or limit the scope of the notification where it cannot take overall responsibility for the arrangement. The body must keep a register of all its subcontracting activities and update it systematically, and individual external auditors or specialists have to meet the conditions of a subcontractor. The register and the competence limit are examples of practice described in the Blue Guide, and they are not mandated by the CRA.
Source: the Regulation, Article 41 ; Blue Guide 2022 (2022/C 247/01) §5.2.5, horizontal product-law guidance that predates the CRA
Need help applying this in practice?
Reading the regulation is the easy part. We help manufacturers work out
what it means for a specific product, and what evidence a notified body
will expect.
CRA compliance services
Source and currency. Text of Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements, reproduced from
EUR-Lex
(CELEX 32024R2847) as at 16 August 2026. © European Union,
1998–2026. Reuse is authorised under
the EUR-Lex legal notice .
Only the Official Journal of the European Union is authentic and produces
legal effect. This reader is provided for convenience and does not
constitute legal advice.