Signal Scanner · REGULATION, STANDARDS & POLICY CHANGE

Rules Without Referees: The EU's Missing Certification Machinery

The consensus is that Europe is easing its digital rulebook. Beneath it, the binding constraint has moved to the machinery that enforces it: the AI Act and Cyber Resilience Act require certification by notified bodies that barely exist, exposing product manufacturers, high-risk AI providers and importers.

The story out of Brussels this year is relief. The Digital Omnibus is simplifying compliance and buying time: in May the co-legislators agreed to defer the AI Act's high-risk obligations to 2027 and 2028, and much of the debate has been about how far to cut the burden. That framing hides the harder problem. The rules that survive still require third-party certification, and the machinery to deliver it, the accredited notified bodies and the harmonised standards they apply, does not yet exist. The deadline moved; the bottleneck did not. Who certifies the products, and can they be ready in time?

Signal Identification

This is an implementation gap, not a rule-making story. The signal is not that Europe is regulating digital products; it is that the conformity-assessment layer the rules depend on, the notified bodies that must sign off and the standards they apply, is missing at the moment the obligations arrive. The extra time the Omnibus bought buys delay, not capacity.

Time horizon: 1–3 years (CRA notified-body rules live since June 2026; sufficient bodies targeted end-2026; CRA full application and AI Act high-risk rules both 2027–2028) Plausibility band: High Geographic / Jurisdictional Scope: EU-27 primary (AI Act, Cyber Resilience Act); extraterritorial reach to any firm placing digital products or high-risk AI on the EU market, including US, UK and Asian exporters Sectors exposed: manufacturers of connected and digital products; high-risk AI providers (biometrics, safety components); medical devices and IVDs; the testing, inspection and certification industry; importers and distributors; compliance and regtech

What's Changing

Start with the Cyber Resilience Act. Its rules on notified bodies began to apply on 11 June 2026, and for critical products such as smart cards, secure elements and smart meter gateways, using one is mandatory (European Commission, 08/06/2026). Yet the Commission's own register lists CRA notified bodies only once they exist, and none are designated. Even the entry criteria are fresh: ENISA published the competence requirements assessors must meet in June, noting they depend on harmonised standards "currently under development" (ENISA, 04/06/2026). The Commission's timeline targets sufficient bodies only by 11 December 2026, with full application a year later (European Commission, 23/04/2026).

The AI Act is on the same path. As of April 2026 zero notified bodies were designated in the EU register for AI Act conformity assessment, no harmonised standards had been published, and no common specifications existed (Reg Intel, 08/04/2026). Rather than build faster, Europe bought time: in May the Council agreed to defer high-risk obligations to 2 December 2027 and 2 August 2028 (Council of the European Union, 07/05/2026), a delay Covington notes is meant to give bodies such as CEN-CENELEC "additional time to prepare the necessary standards" (Covington, 28/05/2026).

The gap: when the machinery arrives versus when the rules bite

MACHINERY DEADLINES Jun 2026 CRA rules live, 0 bodies Dec 2026 target: sufficient bodies 2027 standards expected Dec 2027 CRA full; AI Act Annex III Aug 2028 AI Act Annex I

Sources: European Commission; ENISA; Council of the European Union; Covington.

Disruption Pathway

The pathway is already visible in medical devices. When the EU made third-party certification mandatory under the Medical Device Regulation, notified-body capacity did not keep up: the Commission's 2026 survey counted 33,175 applications against only 17,549 certificates issued, with reviews running 13 to 18 months (MedDeviceGuide, 02/05/2026). The AI Act and CRA now point the same way. Stage one, through 2026, is designation: Member States stand up notified bodies against criteria only just written. Stage two, into 2027, is a queue, as demand for scarce assessors outruns supply when deadlines approach. Stage three is triage, where regulators extend deadlines again or let unassessed products onto the market.

Stress concentrates in three places: manufacturers of CRA critical products and high-risk AI who cannot be certified in time; the thin testing-and-certification industry, which must hire and train scarce auditors before it can be accredited; and importers, who carry legal liability for products they cannot verify. Two adaptations follow. Firms will front-load engagement, booking assessment slots and building technical files years ahead, as medtech now does. And Brussels will lean harder on self-assessment and on harmonised standards as a substitute for scarce bodies, sharpening the legitimacy question the TU Delft analysis raises: private standards writers, not legislators, end up setting the operative rules (Journal of Standardisation, 03/06/2026).

Why This Matters

For the boards this reaches, product and AI compliance leaders, their general counsel, and the importers and distributors downstream, the risk has changed shape: not just a fine for non-compliance, but being unable to obtain the certificate that lets a product stay on the EU market. That reframes timing. Certification lead times of a year or more, against a designation base near zero, mean the firms most exposed should act well before the 2027 and 2028 deadlines, not after. Waiting for the standards to land wastes the very runway the Omnibus bought. The scarce resource is assessor capacity, and it is booked first-come.

Decision-action posture for this signal: Prepare: the deadlines sit in 2027 and 2028, but certification lead times and a near-zero base of notified bodies mean exposed firms should be booking capacity now.

Counter-Argument

The strongest objection is that the deadlines will simply keep moving. The Omnibus already deferred the AI Act's high-risk rules once, tying them to the arrival of standards and tools, and the Commission has shown it will not enforce obligations the machinery cannot support (Council of the European Union, 07/05/2026). If certification capacity is not ready, the reasoning goes, Brussels extends again and the chokepoint never binds.

Even so, indefinite delay has limits. The Cyber Resilience Act's notified-body rules are already live and its critical-product certification is mandatory, and repeated slippage would gut the credibility of the digital rulebook the EU is selling as a competitiveness asset. The medical-device precedent shows the bottleneck bites even after extensions: transition dates were pushed several times, yet the backlog persisted. Delay redistributes the pain; it does not remove it.

Implications

On the available evidence this is durable, not a passing hiccup. Mandatory third-party assessment is written into both the AI Act and the CRA, and standing up an accredited notified-body base takes years, not quarters. The inflection window runs from now to 2028. Firms that treat certification capacity as a scarce, bookable input gain; those that wait for the standards to be final lose their place in the queue. The wider shift is where regulatory power now sits: less in the text of the law, more in who can assess against it, and in the private bodies writing the standards that assessment applies.

Early Indicators to Monitor

Disconfirming Signals

Strategic Questions

Keywords

Conformity assessment; notified bodies; EU AI Act; Cyber Resilience Act; harmonised standards; CEN-CENELEC; NANDO; Digital Omnibus; Medical Device Regulation; CE marking; certification capacity; market access

Bibliography

Source tiers: Tier 1, governments, regulators and intergovernmental bodies. Tier 2, think-tanks, academic institutes, major consultancies and quality data providers. Tier 3, quality journalism and specialist trade press. Tier 4, vendor, company and practitioner sources, used only as directional corroboration.


Prepared by Shaping Tomorrow: 20 July 2026