Brightsight advances to become a CRA Notified Body for Module B and Module H

10.08.2026 10:52 AM
The countdown to the EU Cyber Resilience Act (CRA) has already begun. With the legal obligation to report actively exploited vulnerabilities and severe incidents starting in September 2026 and full enforcement by December 2027, manufacturers of products with digital elements are preparing for a new cybersecurity regulatory landscape.

We are proud to announce that Brightsight is progressing through the accreditation process towards becoming a CRA Notified Body, further expanding our capabilities to support manufacturers in meeting future CRA conformity assessment requirements. 

As part of this commitment, we are preparing to offer comprehensive conformity assessment services covering both Module B and Module H. What does this mean for your product, and how can it accelerate your speed-to-market in Europe? Let’s break it down.

Brightsight’s role in the CRA ecosystem

At Brightsight, we don’t just observe regulatory changes; we actively participate in them. We are making steady progress in our accreditation journey to act as a Notified Body under the CRA.

Manufacturers preparing for the CRA need a partner with proven cybersecurity expertise. Brightsight is actively investing in the capabilities required to support organizations throughout their CRA compliance journey.

Our teams bring extensive experience across a broad range of cybersecurity evaluation and compliance frameworks, including Common Criteria, SESIP, EUCC, IEC 62443, ETSI EN 303 645, ISO/SAE 21434, EMVCo and PCI. This multidisciplinary expertise provides a strong foundation for supporting manufacturers as they prepare for Cyber Resilience Act compliance. 

Brightsight's journey towards becoming a CRA Notified Body

Brightsight is progressing through the accreditation process required to operate as a CRA Notified Body for Module B and Module H. The roadmap below reflects current and upcoming activities. This accreditation will enable Brightsight to support manufacturers in meeting CRA conformity assessment requirements as the regulation becomes fully applicable.

01

CURRENT STATUS

Accreditation in progress

Brightsight is progressing through the accreditation process required to operate as a CRA Notified Body for Module B and Module H.

02

NEXT MILESTONE

Temporary accreditation granted (TAB)

Accreditation with restrictive conditions granted by the national accreditation body (RvA), enabling pilot conformity assessment activities.

03

NOTIFICATION PHASE

Notification as a CRA 

Notified Body

Notification application submission to the Dutch  notifying authority (RDI) to initiate the notification process through NANDO towards the European Commission and Member States.

04

FINAL MILESTONE

CRA Notified Body designation

Formal designation by the national authority and recognition as a CRA Notified Body across the EU.

What this means for you

While our formal designation is being finalized, your compliance journey should not wait. By engaging with Brightsight today for gap assessments and security evaluations, you can begin assessing your product's readiness against the CRA's Essential Requirements 

and start building valuable technical evidence early in the development process. 

Once our Notified Body status is officially granted, relevant technical evidence generated during earlier evaluation activities may be considered as part of future conformity assessment activities, where appropriate. This approach can help reduce duplicated effort, improve efficiency and support a smoother path towards CRA compliance and access to the European market.

What are the CRA conformity paths and which one should you choose?

Once formally designated as a CRA Notified Body, we will offer conformity assessment services under both Module B (EU-Type Examination) and Module H (Full Quality Assurance).

Module B

FOCUS ON THE PRODUCT ITSELF

The Notified Body assesses the product design, technical documentation, cybersecurity risk assessment and supporting evidence to determine compliance with the applicable CRA requirements.

Module H

FOCUS ON QUALITY MANAGEMENT SYSTEM

Module H focuses on the manufacturer's quality management system and the processes used to ensure that products are designed, developed and maintained in compliance with the CRA throughout their lifecycle.

While both routes can be used to demonstrate compliance with CRA requirements, they are designed for different situations. Module B focuses on the assessment of a specific product, whereas Module H focuses on the manufacturer's quality management system and its ability to consistently deliver compliant products.

Successfully completing the applicable conformity assessment is a crucial step toward issuing the EU Declaration of Conformity and affixing the mandatory CE marking to your product, ensuring uninterrupted access to the European Market.

Module B - a direct focus on the product

Module B is a classic product evaluation that focuses directly on the architecture and design of the product itself.  This process includes:

  • Review of product design and cybersecurity architecture
  • Assessment of technical documentation and supporting evidence
  • Verification of compliance with applicable CRA requirements
  • Independent evaluation by a qualified CRA Notified Body

Module B is particularly well suited for manufacturers seeking conformity assessment for a specific product or product version. By focusing directly on the product's architecture, design, technical documentation, and supporting evidence, this conformity assessment route provides an independent evaluation of compliance with the applicable CRA requirements. It is especially suitable for products with relatively stable designs and limited updates, where compliance needs to be demonstrated at the product level.

Module H - a direct focus on the quality management system (QMS)

Rather than assessing an individual product, Module H focuses on the manufacturer’s quality management system and the processes used to ensure that the product consistently complies with the applicable CRA requirements throughout their lifecycle. This route is often preferred for manufacturers managing multiple products, frequent software updates, or continuous development activities.

The Notified Body evaluates whether cybersecurity is systematically integrated into the organization's design, development, testing, vulnerability handling, update management, and post-market monitoring activities. This process includes:

  • Evaluation of the Quality Management System (QMS)
  • Assessment of risk management and cybersecurity governance processes
  • Review of technical documentation and supporting evidence
  • Verification of vulnerability handling processes
  • Independent evaluation by a qualified CRA Notified Body

By demonstrating that cybersecurity requirements are embedded throughout the organization, Module H provides a scalable conformity assessment route that can support long-term CRA compliance across multiple products and future product iterations.

Reusing evidence: Accelerating your "Speed-to-Market"

One of the greatest concerns for manufacturers facing the CRA is the potential for increased costs and duplicated certification efforts. At Brightsight, 
we believe organizations should be able to build on cybersecurity work they have already completed whenever possible.

Manufacturers that have already invested in cybersecurity evaluations, testing and certification activities may be able to build on existing results rather than starting from scratch. Where relevant and appropriate, existing technical evidence can support future conformity assessment activities, helping reduce duplicated effort, improve efficiency and streamline the path towards CRA compliance. 

Your clear path to CRA compliance

We understand that from the customer's perspective, the internal separation between the lab (ITSEF) and the Notified Body (CB) is not what matters; what is truly crucial is understanding what needs to be done to achieve CRA compliance.

Preparing for CRA compliance is an ongoing process. Brightsight can contribute at different stages of that journey - from understanding the requirements to formal conformity assessment once our CRA Notified Body designation is in place. 
We can support manufacturers at every stage of their CRA compliance journey, from initial readiness assessments to formal conformity assessment activities. 

  1. Understand CRA requirements: Through training and awareness sessions.
  2. Assess readiness: Via gap assessments and reviews of your architecture and processes.
  3. Address findings: Use assessment results to prioritize improvement actions and enhance CRA readiness. 
  4. CRA conformity assessment (Module B and Module H): Once formally designated as a CRA Notified Body, we will perform the formal assessment activities required under the applicable CRA conformity assessment path (Module B or Module H).

Start preparing for CRA compliance today. You do not need to wait for CRA applicability or Notified Body involvement to begin preparing. Brightsight's CRA preparation services can help you assess your current state, identify gaps and build the technical evidence
 that may support future conformity assessment activities. Starting early can help reduce risks, avoid last-minute challenges and streamline your path towards CRA compliance.

Sergio Casanova

Xavi Castells

Technology Strategy Coordinator
, Brightsight

Take the first step today

The CRA transition period is already underway. Do not wait for market bottlenecks to delay your product launch in 2027. By integrating Brightsight's expertise early in your development cycle, 
you can improve CRA readiness, reduce compliance risks and turn cybersecurity into a competitive advantage.

Want to understand how the CRA may apply to your product and which conformity assessment path may be applicable? 

Contact our team today to schedule an introductory CRA session or request a preliminary gap assessment.

Enjoyed this article?

Stay up to date with regulatory developments and evolving global cybersecurity requirements. Subscribe to our newsletter to receive the latest insights, updates, and announcements from Brightsight.

The Brightsight Bulletin

Sign up for the Brightsight Bulletin, our newsletter tailored for companies manufacturing and developing IT security products from across the payment, Internet of Things, medical, automotive, industrial, government, telecommunication and network or integrated circuit sectors.

Get informed about: 

  • The latest cybersecurity news and regulatory developments for your products’ security evaluation and certification;
  • Expert insights;
  • Brightsight activities, including events and webinars.

Whether you're shaping digital strategy, driving innovation, or simply staying informed, our curated content delivers clarity and inspiration straight to your inbox. Brightsight helps you see what’s next—before it happens.

The Brightsight Bulletin

Sign up for the Brightsight Bulletin, our newsletter tailored for companies manufacturing and developing IT security products from across the payment, Internet of Things, medical, automotive, industrial, government, telecommunication and network or integrated circuit sectors.

Get informed about: 

  • The latest cybersecurity news and regulatory developments for your products’ security evaluation and certification;
  • Expert insights;
  • Brightsight activities, including events and webinars.

Whether you're shaping digital strategy, driving innovation, or simply staying informed, our curated content delivers clarity and inspiration straight to your inbox. Brightsight helps you see what’s next—before it happens.