Source: OJ L 2024/2847, 20.11.2024

Current language: EN

Article 37 Requirements relating to notifying authorities


Summary What does Article 37 of the CRA regulation say?

This article sets out the integrity and structural requirements that notifying authorities must meet.

It builds directly on Article 36, which establishes the role of the notifying authority, by specifying how that authority must be organised and operate in practice.

The overarching theme is independence: the authority must be free from conflicts of interest, operate objectively and impartially, and must not compete with the very conformity assessment bodies it oversees.

Important points:

  • Notifying authorities are required to be structured so that no conflict of interest arises with conformity assessment bodies, including a separation between those who conduct assessments and those who make notification decisions.
  • Notifying authorities are prohibited from offering or providing, on a commercial or competitive basis, any activities that conformity assessment bodies perform, nor any consultancy services.
  • Notifying authorities must safeguard the confidentiality of information obtained and have sufficient competent personnel to carry out their tasks.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. A notifying authority shall be established in such a way that no conflict of interest with conformity assessment bodies occurs.

    1. A notifying authority shall be organised and shall function so as to safeguard the objectivity and impartiality of its activities.

    1. A notifying authority shall be organised in such a way that each decision relating to notification of a conformity assessment body is taken by competent persons different from those who carried out the assessment.

    1. A notifying authority shall not offer or provide any activities that conformity assessment bodies perform or consultancy services on commercial or competitive basis.

    1. A notifying authority shall safeguard the confidentiality of the information it obtains.

    1. A notifying authority shall have a sufficient number of competent personnel at its disposal for the proper performance of its tasks.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod