CRA product classes
The Cyber Resilience Act sorts products with digital elements into four tiers. Default, important Class I, important Class II, and critical. The tier does not change what the product has to do, which stays the Annex I essential requirements in every case. It changes who has to agree that you have done it, and that is the difference between signing your own declaration and booking a notified body 12 months out.
The four classes in one paragraph
A product with digital elements is a default product unless it appears in Annex III or Annex IV, and the large majority of products are default products. Annex III lists 19 Class I categories and 4 Class II categories of important products. Annex IV lists 3 categories of critical products. Default products self-assess under Module A. Class I keeps Module A only where harmonised standards, common specifications or a European cybersecurity certification scheme cover every applicable essential requirement. Class II loses Module A in every case. Critical products take a mandated certification scheme where one exists, and otherwise the Class II routes.
The classification turns on core functionality, meaning the main features and technical capabilities without which the product could not meet its intended purpose. A product has one core functionality for this purpose and it belongs in the technical documentation. The technical descriptions of the categories are set out in Commission Implementing Regulation (EU) 2025/2392, and Commission guidance C(2026) 5252 explains how to apply them.
What each class changes
Article 32 sets the conformity assessment route per tier. This is the only thing the classification decides.
| Class | Where it is defined | Conformity assessment route | Third party |
|---|---|---|---|
| Default | Not listed in Annex III or Annex IV | Module A, internal control | No |
| Important, Class I | Annex III, Class I — 19 categories | Module A only with full standards coverage, otherwise B+C or H | Conditional |
| Important, Class II | Annex III, Class II — 4 categories | Module B + C, Module H, or a certification scheme | Always |
| Critical | Annex IV — 3 categories | Mandated certification scheme, otherwise the Class II routes | Always |
Default
The large majority of products with digital elements
Self-assessment against the Annex I essential requirements, with the technical documentation and the EU declaration of conformity produced by the manufacturer alone. No notified body is involved at any point.
Important, Class I
Security-relevant products with an established standards baseline
Module A survives only where harmonised standards, common specifications, or a European cybersecurity certification scheme cover every applicable essential requirement. Where that coverage is incomplete, the manufacturer moves to EU type-examination plus conformity to type (Module B + C) or full quality assurance (Module H).
Important, Class II
Products whose compromise carries wider consequences
Module A is unavailable in every case, whatever the standards coverage. The manufacturer uses EU type-examination followed by conformity to type, full quality assurance, or a European cybersecurity certification scheme at assurance level at least substantial.
Critical
Products with the most severe systemic impact
Where the Commission has mandated a European cybersecurity certification scheme by delegated act under Article 8(1), conformity is demonstrated through that scheme at assurance level at least substantial. Where no scheme is mandated or available, the Class II routes apply. No such delegated act has been adopted yet, so a critical product today follows the Class II routes in practice.
Annex III Class I — 19 categories
Important products where existing standards and market maturity provide some assurance baseline. Module A survives here, on condition of complete standards coverage.
- Identity and access managementIdentity management systems, privileged access management software and hardware, and authentication and access control readers including biometric readers
- BrowsersStandalone and embedded browsers
- Password managersSoftware designed primarily to store and manage credentials
- Malware detection softwareProducts that search for, remove, or quarantine malicious software
- VPN productsProducts with a virtual private network function
- Network management systemsProducts managing network devices and configurations
- SIEM systemsSecurity information and event management software
- Boot managersSecure boot and firmware management tools
- Public key infrastructureCertificate issuance and PKI software
- Network interfacesPhysical and virtual network interfaces
- Operating systems
- Routers, modems intended for connection to the internet, and switchesIncluding consumer models
- Microprocessors with security-related functionalities
- Microcontrollers with security-related functionalities
- ASICs and FPGAs with security-related functionalities
- Smart home general purpose virtual assistants
- Smart home products with security functionalitiesSmart door locks, security cameras, baby monitors, alarm systems
- Internet-connected toysThose with social interactive features or location tracking, covered by Directive 2009/48/EC
- Personal wearablesHealth monitoring wearables and wearables intended to be worn by children
Full text in Annex III, with the technical descriptions in Commission Implementing Regulation (EU) 2025/2392.
Annex III Class II — 4 categories
A short, closed list. Anything outside these four is not Class II. Hardware security modules, smart meter gateways and smartcards sit one tier higher in Annex IV. Routers, modems, switches and non-tamper-resistant microprocessors sit one tier lower in Class I.
- Hypervisors and container runtime systemsProducts supporting virtualised execution of operating systems and similar environments
- Firewalls, intrusion detection and prevention systemsIn hardware or software form
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Annex IV critical — 3 categories
Also closed. Industrial control systems, automotive microcontrollers and tamper-resistant microprocessors are not critical products under the CRA, which is the most common misreading of this annex.
- Hardware devices with security boxesHardware security modules, secure cryptoprocessors, and trusted execution environments
- Smart meter gatewaysGateways within smart metering systems as defined in the Electricity Market Directive, and other devices for advanced security purposes including secure cryptoprocessing
- Smartcards and similar devicesIncluding secure elements
Four things that decide a borderline case
The core functionality test comes from Articles 7 and 8, and Commission guidance C(2026) 5252 explains how to apply it. These four consequences are where classifications go wrong.
Classification follows function, not product name
A general-purpose microcontroller is a default product. The same part shipped with security-related functionality such as secure boot or key storage is Class I. A tamper-resistant version of it is Class II. Nothing in the name changes, and the tier changes twice.
A product has exactly one core functionality
Core functionality means the main features and technical capabilities without which the product could not meet its intended purpose. It is singular for classification purposes and it must be identified in the technical documentation. Additional functions do not add a second classification.
Integrating a listed product does not pull you into its category
This one is in the Regulation, not just the guidance. The second sentence of Article 7(1) states that integrating a product with the core functionality of an Annex III category shall not in itself render the host product subject to the Article 32(2) and (3) procedures. A smartphone containing an operating system does not thereby have the core functionality of an operating system. The qualification: where the manufacturer also offers modules of an integrated product separately, for separate purchase, licensing or subscription, each module is assessed on its own.
Substantially exceeding a category takes you out of it
Security orchestration, automation and response software generally exceeds the SIEM category, because incident response forms a core part of its capabilities. A log collection and visualisation tool that performs no correlation and gives no actionable security insight falls short of it. Both sit outside Class I, and the judgement is made on the product's actual technical characteristics rather than on how it is marketed.
Worked examples of each of these sit in the Commission's own classification examples.
What the class costs you in time
Conformity is due by 11 December 2027, when the CRA applies in full. For a default product that date is the deadline for finishing your own paperwork. For a Class II or critical product it is the deadline for finishing someone else's queue.
Third-party assessment for the higher tiers can run 6 to 18 months, the first examination often finds non-conformities that need remediation and re-test, and notified body capacity is limited while designations are still expanding. Working back from December 2027, a critical-product manufacturer that has not yet engaged a notified body is behind the calendar rather than ahead of it.
Class I sits in a different position. The lever there is standards coverage, because complete coverage by harmonised standards or a certification scheme is what keeps Module A available and keeps a notified body out of the project entirely. That makes tracking the EN 40000 series a commercial decision rather than a technical one.
Frequently asked
What are the CRA product classes?
How many CRA product categories are there?
What is the difference between Class I and Class II under the CRA?
Are most products in a CRA class?
Who decides which CRA class a product is in?
Can the Commission change the CRA product classes?
When does CRA classification have to be done?
Find your class in two minutes
The classifier walks the Annex III and Annex IV categories against your product's core functionality and returns the tier, the conformity route open to you, and the reasoning in a form you can paste into the technical documentation.
Free, no account needed to run it. EU data residency by default.
CVD Portal supports CRA compliance work but does not provide legal advice and does not by itself establish conformity or a presumption of conformity. It is an independent platform, not affiliated with or endorsed by the EU or ENISA.