Resources

Class I Products Cannot Self-Assess Yet. The Notified Body Queue Forms in 2027.

Resources

Class I Products Cannot Self-Assess Yet. The Notified Body Queue Forms in 2027.

Resources

Class I Products Cannot Self-Assess Yet. The Notified Body Queue Forms in 2027.

Under the Cyber Resilience Act, the conformity route for a product depends on its class. For Important Class I products, the cheapest route, self-assessment, depends on something that does not exist yet: a harmonised standard cited in the Official Journal.

The four tiers

Class

Examples

Conformity route

Default

Most products with digital elements

Self-assessment

Important Class I

Password managers, VPNs, network management products

Self-assessment against a harmonised standard, or third-party assessment

Important Class II

Operating systems, firewalls, microprocessors

Third-party assessment

Critical

Smart meters, smart cards, secure elements

Certification

The standards are late

The first core horizontal standards were due on 30 August 2026. That deadline has moved to 31 October 2026. Product-specific vertical standards moved from 30 October to 31 December 2026. None has been cited in the Official Journal yet, and notified bodies have only been designatable since 11 June 2026.

If your conformity route depends on a standard that arrives late, you are competing for assessment capacity.

If your conformity route depends on a standard that arrives late, you are competing for assessment capacity.

In plain language

Until a standard is cited, a Class I product cannot rely on self-assessment. That means a notified body. Everyone in the same position will be looking for one in the same twelve months.

Why 2027 gets crowded

CE marking against the CRA's essential requirements applies from 11 December 2027. Standards that arrive at the end of 2026 still need to be cited, read and implemented. Notified bodies are new to this regulation and building capacity. The arithmetic points one way: firms that classify and start now will get a slot, and some that start in 2027 will not.

What to do now

  • Classify every SKU. Default, Class I, Class II or Critical, with the reasoning written down.

  • Find the Class I exposure. These are the products whose route depends on the standards timeline.

  • Map the gap to Annex I. Secure by design, secure defaults, vulnerability handling, an SBOM and a support period of at least five years.

  • Book capacity early. Open conversations with notified bodies before the queue forms.

  • Put a figure on it. Express the remaining exposure in euros, so the board can fund the fix and an underwriter can recognise it.

Next step. Our CRA briefing pack covers scope, the four risk tiers, the reporting clock and the dates that have already slipped. CRA readiness starts from EUR 5,000 a year. Get the briefing pack →

For any comments or information please reach out to info@astragar.com

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

Get Started Now

Know the Real Cyber Risk Behind the Data

©Astragar All rights reserved.