Regulation (EU) 2024/2847 · Articles 7, 8 and 32

CRA product classes

The Cyber Resilience Act sorts products with digital elements into four tiers. Default, important Class I, important Class II, and critical. The tier does not change what the product has to do, which stays the Annex I essential requirements in every case. It changes who has to agree that you have done it, and that is the difference between signing your own declaration and booking a notified body 12 months out.

The four classes in one paragraph

A product with digital elements is a default product unless it appears in Annex III or Annex IV, and the large majority of products are default products. Annex III lists 19 Class I categories and 4 Class II categories of important products. Annex IV lists 3 categories of critical products. Default products self-assess under Module A. Class I keeps Module A only where harmonised standards, common specifications or a European cybersecurity certification scheme cover every applicable essential requirement. Class II loses Module A in every case. Critical products take a mandated certification scheme where one exists, and otherwise the Class II routes.

The classification turns on core functionality, meaning the main features and technical capabilities without which the product could not meet its intended purpose. A product has one core functionality for this purpose and it belongs in the technical documentation. The technical descriptions of the categories are set out in Commission Implementing Regulation (EU) 2025/2392, and Commission guidance C(2026) 5252 explains how to apply them.

What each class changes

Article 32 sets the conformity assessment route per tier. This is the only thing the classification decides.

ClassWhere it is definedConformity assessment routeThird party
DefaultNot listed in Annex III or Annex IVModule A, internal controlNo
Important, Class IAnnex III, Class I — 19 categoriesModule A only with full standards coverage, otherwise B+C or HConditional
Important, Class IIAnnex III, Class II — 4 categoriesModule B + C, Module H, or a certification schemeAlways
CriticalAnnex IV — 3 categoriesMandated certification scheme, otherwise the Class II routesAlways

Default

The large majority of products with digital elements

Self-assessment against the Annex I essential requirements, with the technical documentation and the EU declaration of conformity produced by the manufacturer alone. No notified body is involved at any point.

Important, Class I

Security-relevant products with an established standards baseline

Module A survives only where harmonised standards, common specifications, or a European cybersecurity certification scheme cover every applicable essential requirement. Where that coverage is incomplete, the manufacturer moves to EU type-examination plus conformity to type (Module B + C) or full quality assurance (Module H).

Important, Class II

Products whose compromise carries wider consequences

Module A is unavailable in every case, whatever the standards coverage. The manufacturer uses EU type-examination followed by conformity to type, full quality assurance, or a European cybersecurity certification scheme at assurance level at least substantial.

Critical

Products with the most severe systemic impact

Where the Commission has mandated a European cybersecurity certification scheme by delegated act under Article 8(1), conformity is demonstrated through that scheme at assurance level at least substantial. Where no scheme is mandated or available, the Class II routes apply. No such delegated act has been adopted yet, so a critical product today follows the Class II routes in practice.

Annex III Class I — 19 categories

Important products where existing standards and market maturity provide some assurance baseline. Module A survives here, on condition of complete standards coverage.

  • Identity and access managementIdentity management systems, privileged access management software and hardware, and authentication and access control readers including biometric readers
  • BrowsersStandalone and embedded browsers
  • Password managersSoftware designed primarily to store and manage credentials
  • Malware detection softwareProducts that search for, remove, or quarantine malicious software
  • VPN productsProducts with a virtual private network function
  • Network management systemsProducts managing network devices and configurations
  • SIEM systemsSecurity information and event management software
  • Boot managersSecure boot and firmware management tools
  • Public key infrastructureCertificate issuance and PKI software
  • Network interfacesPhysical and virtual network interfaces
  • Operating systems
  • Routers, modems intended for connection to the internet, and switchesIncluding consumer models
  • Microprocessors with security-related functionalities
  • Microcontrollers with security-related functionalities
  • ASICs and FPGAs with security-related functionalities
  • Smart home general purpose virtual assistants
  • Smart home products with security functionalitiesSmart door locks, security cameras, baby monitors, alarm systems
  • Internet-connected toysThose with social interactive features or location tracking, covered by Directive 2009/48/EC
  • Personal wearablesHealth monitoring wearables and wearables intended to be worn by children

Full text in Annex III, with the technical descriptions in Commission Implementing Regulation (EU) 2025/2392.

Annex III Class II — 4 categories

A short, closed list. Anything outside these four is not Class II. Hardware security modules, smart meter gateways and smartcards sit one tier higher in Annex IV. Routers, modems, switches and non-tamper-resistant microprocessors sit one tier lower in Class I.

  • Hypervisors and container runtime systemsProducts supporting virtualised execution of operating systems and similar environments
  • Firewalls, intrusion detection and prevention systemsIn hardware or software form
  • Tamper-resistant microprocessors
  • Tamper-resistant microcontrollers

Annex IV critical — 3 categories

Also closed. Industrial control systems, automotive microcontrollers and tamper-resistant microprocessors are not critical products under the CRA, which is the most common misreading of this annex.

  • Hardware devices with security boxesHardware security modules, secure cryptoprocessors, and trusted execution environments
  • Smart meter gatewaysGateways within smart metering systems as defined in the Electricity Market Directive, and other devices for advanced security purposes including secure cryptoprocessing
  • Smartcards and similar devicesIncluding secure elements

Four things that decide a borderline case

The core functionality test comes from Articles 7 and 8, and Commission guidance C(2026) 5252 explains how to apply it. These four consequences are where classifications go wrong.

1

Classification follows function, not product name

A general-purpose microcontroller is a default product. The same part shipped with security-related functionality such as secure boot or key storage is Class I. A tamper-resistant version of it is Class II. Nothing in the name changes, and the tier changes twice.

2

A product has exactly one core functionality

Core functionality means the main features and technical capabilities without which the product could not meet its intended purpose. It is singular for classification purposes and it must be identified in the technical documentation. Additional functions do not add a second classification.

3

Integrating a listed product does not pull you into its category

This one is in the Regulation, not just the guidance. The second sentence of Article 7(1) states that integrating a product with the core functionality of an Annex III category shall not in itself render the host product subject to the Article 32(2) and (3) procedures. A smartphone containing an operating system does not thereby have the core functionality of an operating system. The qualification: where the manufacturer also offers modules of an integrated product separately, for separate purchase, licensing or subscription, each module is assessed on its own.

4

Substantially exceeding a category takes you out of it

Security orchestration, automation and response software generally exceeds the SIEM category, because incident response forms a core part of its capabilities. A log collection and visualisation tool that performs no correlation and gives no actionable security insight falls short of it. Both sit outside Class I, and the judgement is made on the product's actual technical characteristics rather than on how it is marketed.

Worked examples of each of these sit in the Commission's own classification examples.

What the class costs you in time

Conformity is due by 11 December 2027, when the CRA applies in full. For a default product that date is the deadline for finishing your own paperwork. For a Class II or critical product it is the deadline for finishing someone else's queue.

Third-party assessment for the higher tiers can run 6 to 18 months, the first examination often finds non-conformities that need remediation and re-test, and notified body capacity is limited while designations are still expanding. Working back from December 2027, a critical-product manufacturer that has not yet engaged a notified body is behind the calendar rather than ahead of it.

Class I sits in a different position. The lever there is standards coverage, because complete coverage by harmonised standards or a certification scheme is what keeps Module A available and keeps a notified body out of the project entirely. That makes tracking the EN 40000 series a commercial decision rather than a technical one.

Frequently asked

What are the CRA product classes?
The Cyber Resilience Act sorts products with digital elements into four tiers. Default products are those listed in neither Annex III nor Annex IV, and they self-assess under Module A. Important products in Annex III Class I, 19 categories, keep Module A only where harmonised standards, common specifications or a European cybersecurity certification scheme cover every applicable essential requirement. Important products in Annex III Class II, 4 categories, always need third-party involvement. Critical products in Annex IV, 3 categories, take a mandated European cybersecurity certification scheme where one exists and otherwise follow the Class II routes.
How many CRA product categories are there?
Twenty-six listed categories across two annexes. Annex III Class I has 19, Annex III Class II has 4, and Annex IV has 3. Everything not described by one of those 26 categories is a default product. The Commission can add categories to either annex by delegated act, so the lists are closed today and not permanently fixed.
What is the difference between Class I and Class II under the CRA?
The conformity route. A Class I manufacturer can still self-assess under Module A, but only where harmonised standards, common specifications or a European cybersecurity certification scheme cover all of the applicable essential requirements. A Class II manufacturer loses Module A outright, in every case, whatever the standards coverage. Class II therefore always means a notified body under Module B plus C or Module H, or a European cybersecurity certification scheme at assurance level at least substantial.
Are most products in a CRA class?
No. The large majority of products with digital elements are default products, appearing in neither Annex III nor Annex IV, and they self-assess under Module A with no notified body involved. The classes are the exception rather than the rule. This matters commercially, because manufacturers frequently assume third-party assessment applies to them when it does not.
Who decides which CRA class a product is in?
The manufacturer, in the first instance, and the determination is recorded in the technical documentation. The classification rests on whether the product has the core functionality of a listed category, judged on its actual technical characteristics. Market surveillance authorities can challenge that determination after the fact, which is why the reasoning belongs in the technical file rather than in someone's head.
Can the Commission change the CRA product classes?
Yes. Article 7(2) and Article 8 let the Commission amend Annex III and Annex IV by delegated act, adding or withdrawing categories as risk and market conditions change. The technical descriptions of the current categories are set out in Commission Implementing Regulation (EU) 2025/2392. A classification decision should therefore be re-checked rather than treated as settled once.
When does CRA classification have to be done?
Before 11 December 2027, when the conformity assessment and CE marking regime applies. The practical deadline is earlier for Class II and critical products, because third-party assessment for those can take 6 to 18 months and notified body capacity is limited. A manufacturer of a critical product that has not engaged a notified body is already working against the calendar.

Find your class in two minutes

The classifier walks the Annex III and Annex IV categories against your product's core functionality and returns the tier, the conformity route open to you, and the reasoning in a form you can paste into the technical documentation.

Free, no account needed to run it. EU data residency by default.

CVD Portal supports CRA compliance work but does not provide legal advice and does not by itself establish conformity or a presumption of conformity. It is an independent platform, not affiliated with or endorsed by the EU or ENISA.