Cyber Resilience Act – Regulation (EU) 2024/2847 – Article 37 – Requirements relating to notifying authorities
Articles
Article 37Requirements relating to notifying authorities
1. A notifying authority shall be established in such a way that no conflict of interest with conformity assessment bodies occurs.
2. A notifying authority shall be organised and shall function so as to safeguard the objectivity and impartiality of its activities.
3. A notifying authority shall be organised in such a way that each decision relating to notification of a conformity assessment body is taken by competent persons different from those who carried out the assessment.
4. A notifying authority shall not offer or provide any activities that conformity assessment bodies perform or consultancy services on commercial or competitive basis.
5. A notifying authority shall safeguard the confidentiality of the information it obtains.
6. A notifying authority shall have a sufficient number of competent personnel at its disposal for the proper performance of its tasks.
https://cra.digiphile.law/article/article-37.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.