Module 2 of 8 · 30 min
Product classification: default, important, critical
The three-tier risk model: the default category, Annex III Class I and Class II important products, Annex IV critical products, and classification by function rather than name.
Learning objectives
- Place a given product in the default, important Class I, important Class II, or critical tier
- Recall representative Annex III Class I and Class II categories and the Annex IV critical categories
- Explain why classification follows intended purpose and core functionality rather than product naming
- Connect each tier to the conformity assessment routes it permits
- Recognise the Commission's power to amend the annex lists by delegated act
Three tiers, one decision
Classification is the first compliance decision because it determines how conformity must be demonstrated. On the Commission's own estimate around ninety percent of products fall in the default category: they appear in neither Annex III nor Annex IV and may use internal control, Module A, with no third party. That proportion is an impact-assessment estimate, not a figure stated in the regulation, so treat it as scale rather than a rule. Important products listed in Annex III split into Class I and the higher-risk Class II. Critical products listed in Annex IV carry the highest assurance expectations and can be required to obtain a European cybersecurity certification such as EUCC.
Annex III important products
Class I covers categories such as identity management and privileged access software, standalone and embedded browsers, password managers, VPN products, network management systems, SIEM systems, boot managers, operating systems, routers and modems intended for internet connection, microcontrollers and microprocessors with security functionalities, smart home virtual assistants, smart home security products such as smart locks, cameras and baby monitors, and internet-connected toys with social or location features. Class II is the short higher-risk list: hypervisors and container runtime systems, firewalls and intrusion detection or prevention systems, and tamper-resistant microprocessors and microcontrollers.
Annex IV critical products
The critical list names hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices including secure elements. For these, the Commission may by delegated act require a European cybersecurity certificate at assurance level at least substantial. Until such a scheme is mandated, critical products follow the important-product routes. The EUCC scheme, the EU's Common Criteria based certification, is the leading candidate, and ENISA has published material on how EUCC certification maps to CRA requirements.
Function over name
Classification follows the product's intended purpose and core functionality, not its marketing name. A consumer router sold for home use sits in the default tier under a different entry than an industrial firewall, while the same silicon marketed as a tamper-resistant secure element lands in Annex III Class II or Annex IV. Dual-function products classify by the security function they actually provide. When a product embeds a component that is itself listed, the component's classification does not automatically escalate the whole product; the product is assessed on its own intended purpose.
Exam trap: two answer options will differ only in class. Verify the category against the actual annex lists, then check whether the stem's product matches the listed intended purpose.
Official sources for this module
- Regulation (EU) 2024/2847 — full official text (EUR-Lex)Official text
- The Cyber Resilience Act — summary of the legislative text (European Commission)Official text
- ENISA webinar — EUCC and CRA interplay (morning session, recorded)Recorded session
- ENISA webinar — EUCC and CRA interplay (afternoon session, recorded)Recorded session
Module 2 quiz
10 questions, pass mark 70%, 3 attempts. Starting an attempt consumes it.
Enroll and confirm your email to take the quiz.