Source: OJ L 2024/2847, 20.11.2024

Current language: FR

Article 35 Notification


Summary What does Article 35 of the CRA regulation say?

This brief but practically important article opens the chapter on notified bodies by establishing two foundational obligations for Member States.

It sets up the notification mechanism — whereby Member States must inform the Commission and each other about bodies authorised to carry out conformity assessments — and it introduces a capacity goal, requiring Member States to work toward having enough of these bodies in place by a specific date.

The article connects directly to the conformity assessment framework established elsewhere in the regulation, as notified bodies are the entities that assess whether products with digital elements meet the essential cybersecurity requirements set out in Annex I.

Important points:

  • Member States are required to notify the Commission and all other Member States of any bodies authorised to conduct conformity assessments under this Regulation.
  • Member States must strive to ensure a sufficient number of notified bodies exist in the Union by 11 December 2026.
  • The sufficiency requirement is explicitly aimed at preventing bottlenecks and hindrances to market entry.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Les États membres notifient à la Commission et aux autres États membres les organismes autorisés à procéder à l’évaluation de la conformité conformément au présent règlement.

    1. Les États membres, au plus tard le 11 décembre 2026, s’efforcent d’assurer la disponibilité, en nombre suffisant, d’organismes notifiés dans l’Union pour effectuer des évaluations de la conformité, afin d’éviter les goulets d’étranglement et les obstacles à l’entrée sur le marché.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod