Source: OJ L 2024/2847, 20.11.2024

Current language: EN

Article 41 Subsidiaries of and subcontracting by notified bodies


Summary What does Article 41 of the CRA regulation say?

This article governs the rules that apply when notified bodies — the organisations responsible for carrying out conformity assessments — choose to subcontract tasks or use subsidiaries.

It builds directly on Article 39, which sets out the core requirements that notified bodies themselves must meet, and extends those same standards down to any third party they engage.

The article makes clear that outsourcing conformity assessment work does not dilute the notified body's accountability; it remains fully responsible regardless of who actually performs the tasks.

Important points:

  • Notified bodies retain full responsibility for all tasks performed by subcontractors or subsidiaries, regardless of where those entities are established.
  • Subcontracting or use of a subsidiary requires the agreement of the manufacturer whose product is being assessed.
  • Notified bodies are required to keep documentation on subcontractor and subsidiary qualifications and work available to the notifying authority upon request.

Springlex's summary of the article, a reading aid, not a substitute for the legal text.

    1. Where a notified body subcontracts specific tasks connected with conformity assessment or has recourse to a subsidiary, it shall ensure that the subcontractor or the subsidiary meets the requirements set out in Article 39 and shall inform the notifying authority accordingly.

    1. Notified bodies shall take full responsibility for the tasks performed by subcontractors or subsidiaries wherever they are established.

    1. Activities may be subcontracted or carried out by a subsidiary only with the agreement of the manufacturer.

    1. Notified bodies shall keep at the disposal of the notifying authority the relevant documents concerning the assessment of the qualifications of the subcontractor or the subsidiary and the work carried out by them under this Regulation.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod