Which CRA product class is my product in?
Also asked
- What is core functionality under the CRA?
- Does integrating a class I component make my product class I?
- Can I self-assess a class I product?
- Who decides which CRA class a product is in?
Your class turns on core functionality. Where a product has the core functionality of a category listed in Annex III it is an important product, class I or class II as that annex divides them. Where it has the core functionality of an Annex IV category it is critical. Everything else is default. Default and class I products can use internal control under module A, class I only while harmonised standards cover every applicable requirement. Class II and critical products always need a third party.
The classification decides only the conformity assessment route. The Annex I essential requirements themselves apply identically across all four tiers.
At a glance
- Default
- Not in Annex III or IV. Module A internal control
- Important class I
- Annex III class I. Module A only with full standards coverage
- Important class II
- Annex III class II. Module B+C, H, or a certification scheme
- Critical
- Annex IV. Certification scheme under Article 8(1), otherwise the class II routes
- Deciding test
- Core functionality of a listed category
- Conformity due
- 11 December 2027
Last reviewed 7 August 2026
Verified against Regulation (EU) 2024/2847 Articles 7, 8, 32 and 71 as published in OJ L, 20.11.2024, read in full text on EUR-Lex on 7 August 2026, and Commission guidance C(2026) 5252 final of 27 July 2026.
The test is core functionality, not product name
Article 7(1) is the operative rule for important products. Products with digital elements which have the core functionality of a product category set out in Annex III are important products and are subject to the conformity assessment procedures in Article 32(2) and (3).[1] Article 8(1) does the equivalent job for the Annex IV critical categories.[2]
Core functionality means the main features and technical capabilities without which the product could not meet its intended purpose. A product has one core functionality for classification purposes, and Commission guidance C(2026) 5252 expects it to be identified in the technical documentation.[5]
This is why the product name decides nothing. A general-purpose microcontroller is a default product. The same part shipped with security-related functionality is Annex III class I. A tamper-resistant version of it is class II. The marketing name can stay identical across all three.
Integrating a listed product does not move your tier
This is settled in the Regulation itself rather than only in guidance, and it is the single most useful sentence in Article 7 for a manufacturer building on components. The second sentence of Article 7(1) states that the integration of a product with digital elements which has the core functionality of an Annex III category shall not in itself render the product in which it is integrated subject to the Article 32(2) and (3) procedures.[1]
A smartphone containing an operating system does not thereby acquire the core functionality of an operating system. A machine containing a firewall module does not become a class II product because of it.
The qualification is worth reading closely. Where a manufacturer also offers modules of an integrated product separately, for separate purchase, licensing or subscription, guidance treats each module as assessed on its own.[5] Selling the component as a product puts the component in its own category, whatever the host product is.
What each class changes, precisely
Article 32 sets four routes: internal control based on module A, EU-type examination based on module B followed by conformity to type based on module C, full quality assurance based on module H, and where available and applicable a European cybersecurity certification scheme under Article 27(9).[3]
A default product may use any of them, which in practice means module A.
For an Annex III class I product, Article 32(2) is conditional rather than absolute. Where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least substantial, or where those do not exist, the product must go to module B plus C or to module H. Complete coverage keeps module A available.[3]
For an Annex III class II product, Article 32(3) removes module A in every case. The routes are B plus C, H, or a certification scheme at assurance level at least substantial.[3]
For an Annex IV critical product, Article 32(4) requires a European cybersecurity certification scheme in accordance with Article 8(1), and where the Article 8(1) conditions are not met, any of the Article 32(3) procedures.[3][2]
Why this is the determination with a lead time
Conformity is due when the Regulation applies in full on 11 December 2027.[4] For a default product that date is a deadline for finishing your own documentation. For a class II or critical product it is a deadline for finishing a notified body's queue, and third-party assessment schedules are measured in quarters rather than weeks.
That asymmetry is why classification comes first in any sensible sequence. Every other stage can proceed in parallel once it is settled, and none of them can be scheduled sensibly before it.
One timing detail supports early engagement. Under Article 71(2) the notified body provisions in Chapter IV, Articles 35 to 51, applied from 11 June 2026, well ahead of the rest of the Regulation, precisely so that the assessment infrastructure exists before manufacturers need it.[4]
Sources
Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.
- [1]
Publications Office of the European Union · Article 7(1) to (3) · CELEX:32024R2847 · OJ L, 20.11.2024
“shall not in itself render the product in which it is integrated subject to the conformity assessment procedures referred to in Article 32(2) and (3)”
Accessed 2026-08-07
- [2]
Publications Office of the European Union · Article 8(1) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-08-07
- [3]
Publications Office of the European Union · Article 32(1) to (5) · CELEX:32024R2847 · OJ L, 20.11.2024
Accessed 2026-08-07
- [4]Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71 (Entry into force and application)Binding
Publications Office of the European Union · Article 71(2) · CELEX:32024R2847 · OJ L, 20.11.2024
“This Regulation shall apply from 11 December 2027”
Accessed 2026-08-07
- [5]Commission guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act), C(2026) 5252 finalCommission guidance
European Commission · C(2026) 5252
Non-binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.
Accessed 2026-08-07
Further reading on this site
Follow-up questions
Our product nearly matches a category but does more. Are we in it?+
Possibly not. Guidance treats a product that substantially exceeds or substantially falls short of a category as outside it, judged objectively on the product's actual technical characteristics rather than on how it is marketed. Security orchestration, automation and response software generally exceeds the SIEM category because incident response forms a core part of its capabilities. A log viewer that performs no correlation falls short of it.
Can our class change without us changing the product?+
Yes. Article 7(3) empowers the Commission to amend Annex III by delegated act, adding a category within either class, moving a category between classes, or withdrawing one. Article 8(1) works similarly for the certification requirement attached to Annex IV categories. Treat a classification as a position to re-check rather than a fact settled once.
Does open source in an Annex III category lose module A?+
No. Article 32(5) lets manufacturers of products with digital elements qualifying as free and open-source software that fall under the Annex III categories demonstrate conformity using one of the Article 32(1) procedures, which keeps internal control available to them. This is operative in the Regulation rather than a concession in guidance.
The provisions behind this answer
Terms used in this answer
Work out where your product actually lands
Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.