Source: OJ L 2024/2847, 20.11.2024

Current language: FR

Article 41 Filiales et sous-traitants des organismes notifiés


Summary What does Article 41 of the CRA regulation say?

This article governs the rules that apply when notified bodies — the organisations responsible for carrying out conformity assessments — choose to subcontract tasks or use subsidiaries.

It builds directly on Article 39, which sets out the core requirements that notified bodies themselves must meet, and extends those same standards down to any third party they engage.

The article makes clear that outsourcing conformity assessment work does not dilute the notified body's accountability; it remains fully responsible regardless of who actually performs the tasks.

Important points:

  • Notified bodies retain full responsibility for all tasks performed by subcontractors or subsidiaries, regardless of where those entities are established.
  • Subcontracting or use of a subsidiary requires the agreement of the manufacturer whose product is being assessed.
  • Notified bodies are required to keep documentation on subcontractor and subsidiary qualifications and work available to the notifying authority upon request.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Lorsqu’un organisme notifié sous-traite des tâches spécifiques dans le cadre de l’évaluation de la conformité ou a recours à une filiale, il s’assure que le sous-traitant ou la filiale répond aux exigences énoncées à l’article 39 et informe l’autorité notifiante en conséquence.

    1. Les organismes notifiés assument l’entière responsabilité des tâches accomplies par les sous-traitants ou filiales, quel que soit leur lieu d’établissement.

    1. Des activités ne peuvent être sous-traitées ou réalisées par une filiale qu’avec l’accord du fabricant.

    1. Les organismes notifiés tiennent à la disposition de l’autorité notifiante les documents pertinents concernant l’évaluation des qualifications du sous-traitant ou de la filiale et le travail exécuté par celui-ci ou celle-ci en vertu du présent règlement.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod