Conformity assessment
The presumption of conformity
A product that conforms, wholly or partly, to harmonised standards whose references have been published in the Official Journal of the European Union is presumed to conform to the essential requirements those standards cover.
Three routes open that presumption:
- harmonised standards cited in the OJ;
- common specifications adopted by the Commission through an implementing act, in the absence of a satisfactory harmonised standard;
- European cybersecurity certification schemes adopted under Regulation (EU) 2019/881, at assurance level at least “substantial”.
The presumption is a shift in the burden of proof, not an exemption: it removes neither the technical documentation, nor the declaration, nor the marking.
The state of standardisation
The Commission addressed standardisation request M/606 to CEN and CENELEC. The work is carried out by joint technical committee JTC 13, working group 9, and comprises:
- horizontal standards — principles of cyber resilience, generic security requirements, vulnerability handling — applicable to all products;
- vertical standards, by Annex III product category.
This is the main source of schedule uncertainty. A standard adopted but not yet cited in the OJ confers no presumption. This page must be re-read at each publication; see updates.
The assessment modules
| Module | Name | Who assesses | Open to |
|---|---|---|---|
| A | Internal control of production | The manufacturer | Default; class I conditionally on full application of standards |
| B | EU type-examination | Notified body | Classes I and II, Critical — followed by module C |
| C | Conformity to type based on internal control | The manufacturer, after module B | Same |
| H | Conformity based on full quality assurance | Notified body (system audit) | Classes I and II, Critical |
Choosing between B+C and H is discussed in Important class II.
Notified bodies
A notified body is an accredited conformity assessment body, designated by a national notifying authority, notified to the Commission and listed in the NANDO database, where it receives an identification number.
The Regulation requires independence, technical competence, impartiality, confidentiality and liability insurance. They are subject to information obligations towards the notifying authority and towards other bodies.
The corresponding chapter has applied since 11 June 2026.
Two things to anticipate:
- capacity — the entire European market must pass through these bodies before 11 December 2027, with a limited number of bodies at the outset;
- sectoral competence — not every body will cover every Annex III category; check the exact scope of the notification in NANDO before contracting.
The certification route
Holding a European cybersecurity certificate, issued under a scheme adopted pursuant to the Cybersecurity Act at assurance level at least “substantial” and covering the relevant essential requirements, counts as conformity assessment.
For critical products in Annex IV, the Commission may make that route mandatory by delegated act — see Critical products.
Costs and lead times: what to budget
The Regulation of course sets no tariff. The line items to provision are known:
- notified body assessment fees, per product and per cycle;
- internal cost of preparing the file, generally higher than the external cost;
- the cost of the version freeze during examination, in days of delayed market entry;
- maintenance cost: certificate extensions, surveillance audits, reassessment after substantial modification;
- for critical products subject to certification, the evaluation laboratory and certificate maintenance.
Micro, small and medium-sized enterprises
The Regulation provides support measures: a simplified technical documentation form made available by the Commission for micro and small enterprises, awareness and training actions by Member States, and consideration of company size when setting penalties.
These measures lighten the documentation burden; they reduce no substantive requirement.