Rules Without Referees: The EU's Missing Certification Machinery
The consensus is that Europe is easing its digital rulebook. Beneath it, the binding constraint has moved to the machinery that enforces it: the AI Act and Cyber Resilience Act require certification by notified bodies that barely exist, exposing product manufacturers, high-risk AI providers and importers.
The story out of Brussels this year is relief. The Digital Omnibus is simplifying compliance and buying time: in May the co-legislators agreed to defer the AI Act's high-risk obligations to 2027 and 2028, and much of the debate has been about how far to cut the burden. That framing hides the harder problem. The rules that survive still require third-party certification, and the machinery to deliver it, the accredited notified bodies and the harmonised standards they apply, does not yet exist. The deadline moved; the bottleneck did not. Who certifies the products, and can they be ready in time?
Signal Identification
This is an implementation gap, not a rule-making story. The signal is not that Europe is regulating digital products; it is that the conformity-assessment layer the rules depend on, the notified bodies that must sign off and the standards they apply, is missing at the moment the obligations arrive. The extra time the Omnibus bought buys delay, not capacity.
What's Changing
Start with the Cyber Resilience Act. Its rules on notified bodies began to apply on 11 June 2026, and for critical products such as smart cards, secure elements and smart meter gateways, using one is mandatory (European Commission, 08/06/2026). Yet the Commission's own register lists CRA notified bodies only once they exist, and none are designated. Even the entry criteria are fresh: ENISA published the competence requirements assessors must meet in June, noting they depend on harmonised standards "currently under development" (ENISA, 04/06/2026). The Commission's timeline targets sufficient bodies only by 11 December 2026, with full application a year later (European Commission, 23/04/2026).
The AI Act is on the same path. As of April 2026 zero notified bodies were designated in the EU register for AI Act conformity assessment, no harmonised standards had been published, and no common specifications existed (Reg Intel, 08/04/2026). Rather than build faster, Europe bought time: in May the Council agreed to defer high-risk obligations to 2 December 2027 and 2 August 2028 (Council of the European Union, 07/05/2026), a delay Covington notes is meant to give bodies such as CEN-CENELEC "additional time to prepare the necessary standards" (Covington, 28/05/2026).
The gap: when the machinery arrives versus when the rules bite
Sources: European Commission; ENISA; Council of the European Union; Covington.
Disruption Pathway
The pathway is already visible in medical devices. When the EU made third-party certification mandatory under the Medical Device Regulation, notified-body capacity did not keep up: the Commission's 2026 survey counted 33,175 applications against only 17,549 certificates issued, with reviews running 13 to 18 months (MedDeviceGuide, 02/05/2026). The AI Act and CRA now point the same way. Stage one, through 2026, is designation: Member States stand up notified bodies against criteria only just written. Stage two, into 2027, is a queue, as demand for scarce assessors outruns supply when deadlines approach. Stage three is triage, where regulators extend deadlines again or let unassessed products onto the market.
Stress concentrates in three places: manufacturers of CRA critical products and high-risk AI who cannot be certified in time; the thin testing-and-certification industry, which must hire and train scarce auditors before it can be accredited; and importers, who carry legal liability for products they cannot verify. Two adaptations follow. Firms will front-load engagement, booking assessment slots and building technical files years ahead, as medtech now does. And Brussels will lean harder on self-assessment and on harmonised standards as a substitute for scarce bodies, sharpening the legitimacy question the TU Delft analysis raises: private standards writers, not legislators, end up setting the operative rules (Journal of Standardisation, 03/06/2026).
Why This Matters
For the boards this reaches, product and AI compliance leaders, their general counsel, and the importers and distributors downstream, the risk has changed shape: not just a fine for non-compliance, but being unable to obtain the certificate that lets a product stay on the EU market. That reframes timing. Certification lead times of a year or more, against a designation base near zero, mean the firms most exposed should act well before the 2027 and 2028 deadlines, not after. Waiting for the standards to land wastes the very runway the Omnibus bought. The scarce resource is assessor capacity, and it is booked first-come.
Decision-action posture for this signal: Prepare: the deadlines sit in 2027 and 2028, but certification lead times and a near-zero base of notified bodies mean exposed firms should be booking capacity now.
Counter-Argument
The strongest objection is that the deadlines will simply keep moving. The Omnibus already deferred the AI Act's high-risk rules once, tying them to the arrival of standards and tools, and the Commission has shown it will not enforce obligations the machinery cannot support (Council of the European Union, 07/05/2026). If certification capacity is not ready, the reasoning goes, Brussels extends again and the chokepoint never binds.
Even so, indefinite delay has limits. The Cyber Resilience Act's notified-body rules are already live and its critical-product certification is mandatory, and repeated slippage would gut the credibility of the digital rulebook the EU is selling as a competitiveness asset. The medical-device precedent shows the bottleneck bites even after extensions: transition dates were pushed several times, yet the backlog persisted. Delay redistributes the pain; it does not remove it.
Implications
On the available evidence this is durable, not a passing hiccup. Mandatory third-party assessment is written into both the AI Act and the CRA, and standing up an accredited notified-body base takes years, not quarters. The inflection window runs from now to 2028. Firms that treat certification capacity as a scarce, bookable input gain; those that wait for the standards to be final lose their place in the queue. The wider shift is where regulatory power now sits: less in the text of the law, more in who can assess against it, and in the private bodies writing the standards that assessment applies.
Early Indicators to Monitor
- The Commission's NANDO register lists its first designated notified bodies for the CRA and the AI Act.
- CEN-CENELEC publishes the first harmonised AI Act standards in the Official Journal, or misses the expected 2027 window.
- Member States report progress toward the 11 December 2026 target for sufficient CRA conformity assessment bodies.
- A national authority or the Commission signals a further deadline slip tied explicitly to certification capacity.
- Multi-year certification lead times begin to appear in notified-body and industry reporting.
Disconfirming Signals
- Notified bodies are designated quickly and in numbers, and lead times stay short as deadlines approach.
- Harmonised standards for the AI Act and CRA are published on schedule, cutting reliance on scarce third-party assessors.
- The Commission narrows mandatory third-party assessment so that most products can self-assess.
- The medical-device backlog clears, weakening the precedent that mandatory certification jams under load.
- Deadlines hold without extension and products still reach the market, showing capacity was adequate.
Strategic Questions
- Book conformity-assessment capacity now against uncertain rules, or wait for the standards and risk the queue?
- Which products or AI systems in the portfolio depend on a notified body that does not yet exist?
- Should compliance teams treat certification capacity, not the legal deadline, as the binding planning constraint?
Keywords
Conformity assessment; notified bodies; EU AI Act; Cyber Resilience Act; harmonised standards; CEN-CENELEC; NANDO; Digital Omnibus; Medical Device Regulation; CE marking; certification capacity; market access
Bibliography
Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.
- Tier 1 Cyber Resilience Act: conformity assessment. European Commission (08/06/2026).
- Tier 1 Cyber Resilience Act: implementation timeline. European Commission (23/04/2026).
- Tier 1 Technical Competence Requirements for CRA Notified Bodies. ENISA (04/06/2026).
- Tier 1 Artificial intelligence: Council and Parliament agree to simplify and streamline rules. Council of the European Union (07/05/2026).
- Tier 2 European standardization in flux: navigating delegation and control in AI governance. Journal of Standardisation (TU Delft) (03/06/2026).
- Tier 2 EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions. Covington (28/05/2026).
- Tier 3 EU AI Act Conformity Assessment: What to Do When the Infrastructure Isn't Ready. Reg Intel (08/04/2026).
- Tier 3 EU MDR Notified Body Capacity Crisis 2026-2027. MedDeviceGuide (02/05/2026).