Skip to content

Notified body vs self-declaration

Two routes to “you may place it on the market”

Section titled “Two routes to “you may place it on the market””

Every product covered by EU product-safety law has to be shown to meet that law before it goes on sale. EU law offers two procedural routes for getting there, and the risk class of the product decides which one you are allowed to use.

  • Self-declaration of conformity. The manufacturer does the assessment itself, compiles the technical documentation, signs a Declaration of Conformity, and places the product on the market under its own responsibility. No outside party signs off first. This is permitted for the lowest-risk classes — for medical devices, MDR Class I (the lowest, non-sterile, non-measuring class) self-declares.

  • Third-party conformity assessment by a notified body. For higher-risk classes, the manufacturer’s own attestation is not enough. An independent, accredited third party — a notified body — must review the technical documentation, the quality system, and (for devices) the clinical evidence, and issue a certificate. Only then may the product be placed on the market. For medical devices, Class IIa and above take this route: the MDR conformity-assessment procedure —MDR Art. 52, Annexes IX/X/XI— requires the manufacturer to involve a notified body. (And because a medical screener is also a high-risk AI system, the EU AI Act, Art. 43(3) routes the AI system’s assessment into that same MDR sectoral procedure rather than a separate one: a single assessment, run by the MDR notified body.)

The dividing line is who has to be convinced. Self-declaration: you convince yourself (and stand behind it). Notified body: an accredited outsider, independent of you, has to be convinced first.

A notified body is not just “an auditor”. It is an organisation with three properties the law insists on:

  1. Designated and accredited. A member-state authority designates it for specific regulations and device categories, after an accreditation process verifies its competence. The Commission publishes the list (the NANDO database). A random consultancy is not a notified body.
  2. Independent of the manufacturer. This is the heart of it. The notified body must have no commercial or organisational stake in the product passing. The whole value of a third-party assessment is that the assessor does not benefit from a “yes”. (The MDR — and the EU AI Act, Art. 31 — write this independence in.)
  3. Empowered to issue a certificate. The output is a legally recognised certificate of conformity assessment, which is what unlocks the CE mark and market placement for the higher classes.

Take any of those three away and you do not have a notified body. That is exactly why a signing engine — however rigorous its evidence — cannot be one.

The froga engine produces a lot that looks adjacent to conformity assessment: it measures controls, computes a residual, assembles the technical documentation (Annex IV), and signs the whole bundle so anyone can verify what was measured and by whom. That signed, reproducible evidence is genuinely valuable — it is the evidence a notified body would audit. But it is not the assessment, for three reasons that map one-to-one onto the three properties above:

  • No accreditation/designation. The engine is a tool the manufacturer runs. No member-state authority has designated it; it is not in NANDO. It cannot issue a certificate that any regulator recognises.
  • No independence. The signature on the bundle is the developer’s own key — in the demo, a fictional signer (Dev Demo), not an accredited, independent third party. A manufacturer signing its own evidence is self-declaration, by definition. Independence (MDR; AI Act Art. 31) is the one thing self-signing structurally cannot provide.
  • A technical gate is not a clinical evaluation. Even a real notified body for a medical device must see a clinical evaluation (MDR Annex XIV) — a benefit-risk determination that the device is clinically safe and effective for its intended purpose. That is a clinical-scientific judgement, outside any risk-management engine. The engine can show that a sensitivity gate passed; it cannot show that the device is clinically beneficial. A passing technical gate ≠ clinical benefit-risk.

One more distinction, so the boundary is sharp. Later in the course you meet Aitor, an external auditor / buyer who runs froga verify with only a public key to check that a supplier’s signed evidence is authentic and the gates are green. That third-party verification is real and useful — but Aitor is not a notified body either. Verifying a signature confirms the evidence is what the signer says it is; a notified-body conformity assessment confirms the product meets the regulation and issues a recognised certificate. A buyer’s acceptance gate (“the signatures verify and nothing is RED”) is a procurement decision, not a conformity decision. The engine and its verifiers can establish authenticity and surface gaps; only an accredited notified body can certify the higher-risk classes.

What is the difference between self-declaration of conformity and a third-party conformity assessment by a notified body — and which applies to an MDR Class IIa device?

Self-declaration means the manufacturer assesses its own product, signs a Declaration of Conformity, and places it on the market under its own responsibility — no outside party signs off first. It is allowed for the lowest-risk classes (e.g. MDR Class I). A third-party conformity assessment means an independent, accredited notified body must review the evidence and issue a certificate before the product can go on the market — required for higher-risk classes. An MDR Class IIa device takes the third-party route: its conformity-assessment procedure (MDR Art. 52) requires the involvement of a notified body; it cannot self-declare.

The froga engine signs the evidence bundle and assembles the technical documentation. Why is it still not a notified body?

Because a notified body has three properties the engine lacks. (1) It is accredited and designated by a member-state authority and listed in NANDO — the engine is a tool the manufacturer runs, designated by no one, and cannot issue a recognised certificate. (2) It is independent of the manufacturer — but the engine signs with the developer’s own key (a fictional signer in the demo), which is self-declaration, the opposite of independence (MDR; AI Act Art. 31). (3) It can issue a certificate; the engine cannot. The engine produces the evidence a notified body would audit — it is not the audit.

A retina screener's sensitivity gate passes (recall > 0.80). Does that mean the device has met the MDR's clinical requirement?

No. A passing technical gate is not a clinical evaluation. The MDR (Annex XIV) requires a clinical evaluation — a benefit-risk determination that the device is clinically safe and effective for its intended purpose — which is a clinical-scientific judgement outside any risk-management engine. The engine can prove a sensitivity metric passed on a held-out cohort; it cannot prove the device is clinically beneficial, and a single fold on one cohort is not a clinical-validation study. The clinical evaluation, like the notified-body certificate, lives beyond the engine’s boundary — which is exactly why the cycle honestly pauses.