European cybersecurity regulation now directly shapes international testing infrastructure. Nemko Group, an established European conformity assessment body, designated South Korea's Telecommunications Technology Association (TTA) as a Notified Body Test Laboratory (NBTL) for CE marking.
1. The Designation and Local Testing Capability
The designation authorizes TTA to conduct formal CE certification testing for digital products within South Korea.
Previously, non-EU manufacturers had to ship physical prototypes and test equipment to laboratories located inside the European Union. This process created substantial transport delays, customs friction, language barriers, and high evaluation expenses.
With NBTL status in Seongnam and Seoul, TTA can execute technical testing locally. The test results flow directly into Nemko's conformity assessment workflows to issue CE conformity certificates under European Union rules.
2. Context under the EU Cyber Resilience Act (CRA)
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) applies to all products with digital elements made available on the European single market. The regulation applies regardless of the geographical origin of the manufacturer.
| CRA Milestone | Statutory Date | Mandatory Obligation |
|---|---|---|
| Article 14 Reporting | 11 September 2026 | 24-hour early warning for actively exploited vulnerabilities and severe incidents. |
| Full CRA Enforcement | 11 December 2027 | Mandatory CE mark, Annex I essential security requirements, and technical documentation. |
Under CRA Article 32, manufacturers must select an approved conformity assessment procedure:
- Module A (Internal Control): Permitted for standard default products when harmonised European standards exist.
- Module B+C (EU-Type Examination) or Module H (Full Quality Assurance): Mandatory for Class I products without harmonised standards, Class II products (Annex IV), and critical products (Annex III). These routes require third-party evaluation by a Notified Body.
3. What This Means for Hardware and Software Exporters
South Korea is a major exporter of semiconductors, smart consumer electronics, connected industrial controllers, and telecommunications equipment to the European Union.
Small and medium-sized manufacturers (SMEs) frequently lack European testing facilities. The TTA-Nemko partnership provides local access to standardized evaluation procedures, including ETSI EN 303 645 for consumer IoT and IEC 62443 for industrial systems.
However, laboratory hardware testing solves only one part of CRA compliance.
4. The Boundary Between Testing Labs and Ongoing Compliance
A test report from an accredited laboratory proves conformity at a single point in time. The CRA requires continuous lifecycle compliance:
- Article 13(5) & Annex I Part II: Manufacturers must maintain a dynamic Software Bill of Materials (SBOM) and systematically address newly discovered vulnerabilities throughout the support period.
- Article 13(6) & ISO/IEC 29147: Manufacturers must provide a public point of contact and an active Coordinated Vulnerability Disclosure (CVD) process.
- Article 14: Exploited vulnerabilities must be reported to the European CSIRT network and ENISA within 24 hours of awareness.
- Annex VII: The complete technical file must remain available to market surveillance authorities for at least 10 years after product placement.
Next Steps for Manufacturers
Organizations preparing for European market access must coordinate their physical testing with automated compliance tooling:
- Engage accredited test laboratories early for products requiring Module B or Module H third-party certification.
- Establish a structured Coordinated Vulnerability Disclosure portal to fulfill Article 13 and ISO/IEC 29147 obligations.
- Implement automated CSAF advisory generation and SBOM tracking before the September 2026 reporting deadline.
You can track recognized conformity assessment bodies in the CVD Portal Notified Bodies Directory and review article-by-article requirements in the CRA Knowledge Base.