← CRA FAQConformity and CE marking

Which CRA product class is my product in?

Also asked

  • What is core functionality under the CRA?
  • Does integrating a class I component make my product class I?
  • Can I self-assess a class I product?
  • Who decides which CRA class a product is in?

Your class turns on core functionality. Where a product has the core functionality of a category listed in Annex III it is an important product, class I or class II as that annex divides them. Where it has the core functionality of an Annex IV category it is critical. Everything else is default. Default and class I products can use internal control under module A, class I only while harmonised standards cover every applicable requirement. Class II and critical products always need a third party.

The classification decides only the conformity assessment route. The Annex I essential requirements themselves apply identically across all four tiers.

At a glance

Default
Not in Annex III or IV. Module A internal control
Important class I
Annex III class I. Module A only with full standards coverage
Important class II
Annex III class II. Module B+C, H, or a certification scheme
Critical
Annex IV. Certification scheme under Article 8(1), otherwise the class II routes
Deciding test
Core functionality of a listed category
Conformity due
11 December 2027

Last reviewed 7 August 2026

Verified against Regulation (EU) 2024/2847 Articles 7, 8, 32 and 71 as published in OJ L, 20.11.2024, read in full text on EUR-Lex on 7 August 2026, and Commission guidance C(2026) 5252 final of 27 July 2026.

The test is core functionality, not product name

Article 7(1) is the operative rule for important products. Products with digital elements which have the core functionality of a product category set out in Annex III are important products and are subject to the conformity assessment procedures in Article 32(2) and (3).[1] Article 8(1) does the equivalent job for the Annex IV critical categories.[2]

Core functionality means the main features and technical capabilities without which the product could not meet its intended purpose. A product has one core functionality for classification purposes, and Commission guidance C(2026) 5252 expects it to be identified in the technical documentation.[5]

This is why the product name decides nothing. A general-purpose microcontroller is a default product. The same part shipped with security-related functionality is Annex III class I. A tamper-resistant version of it is class II. The marketing name can stay identical across all three.

CRA referenceArticle 7(1) and Article 8(1)

Integrating a listed product does not move your tier

This is settled in the Regulation itself rather than only in guidance, and it is the single most useful sentence in Article 7 for a manufacturer building on components. The second sentence of Article 7(1) states that the integration of a product with digital elements which has the core functionality of an Annex III category shall not in itself render the product in which it is integrated subject to the Article 32(2) and (3) procedures.[1]

A smartphone containing an operating system does not thereby acquire the core functionality of an operating system. A machine containing a firewall module does not become a class II product because of it.

The qualification is worth reading closely. Where a manufacturer also offers modules of an integrated product separately, for separate purchase, licensing or subscription, guidance treats each module as assessed on its own.[5] Selling the component as a product puts the component in its own category, whatever the host product is.

CRA referenceArticle 7(1), second sentence

What each class changes, precisely

Article 32 sets four routes: internal control based on module A, EU-type examination based on module B followed by conformity to type based on module C, full quality assurance based on module H, and where available and applicable a European cybersecurity certification scheme under Article 27(9).[3]

A default product may use any of them, which in practice means module A.

For an Annex III class I product, Article 32(2) is conditional rather than absolute. Where the manufacturer has not applied, or has applied only in part, harmonised standards, common specifications or European cybersecurity certification schemes at assurance level at least substantial, or where those do not exist, the product must go to module B plus C or to module H. Complete coverage keeps module A available.[3]

For an Annex III class II product, Article 32(3) removes module A in every case. The routes are B plus C, H, or a certification scheme at assurance level at least substantial.[3]

For an Annex IV critical product, Article 32(4) requires a European cybersecurity certification scheme in accordance with Article 8(1), and where the Article 8(1) conditions are not met, any of the Article 32(3) procedures.[3][2]

CRA referenceArticle 32(1) to (4)

Why this is the determination with a lead time

Conformity is due when the Regulation applies in full on 11 December 2027.[4] For a default product that date is a deadline for finishing your own documentation. For a class II or critical product it is a deadline for finishing a notified body's queue, and third-party assessment schedules are measured in quarters rather than weeks.

That asymmetry is why classification comes first in any sensible sequence. Every other stage can proceed in parallel once it is settled, and none of them can be scheduled sensibly before it.

One timing detail supports early engagement. Under Article 71(2) the notified body provisions in Chapter IV, Articles 35 to 51, applied from 11 June 2026, well ahead of the rest of the Regulation, precisely so that the assessment infrastructure exists before manufacturers need it.[4]

CRA referenceArticle 71(2)

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 7(1) to (3) · CELEX:32024R2847 · OJ L, 20.11.2024

    shall not in itself render the product in which it is integrated subject to the conformity assessment procedures referred to in Article 32(2) and (3)

    Accessed 2026-08-07

  2. [2]

    Publications Office of the European Union · Article 8(1) · CELEX:32024R2847 · OJ L, 20.11.2024

    Accessed 2026-08-07

  3. [3]

    Publications Office of the European Union · Article 32(1) to (5) · CELEX:32024R2847 · OJ L, 20.11.2024

    Accessed 2026-08-07

  4. [4]

    Publications Office of the European Union · Article 71(2) · CELEX:32024R2847 · OJ L, 20.11.2024

    This Regulation shall apply from 11 December 2027

    Accessed 2026-08-07

  5. [5]

    European Commission · C(2026) 5252

    Non-binding. Only the Court of Justice of the European Union can give an authoritative interpretation of the CRA.

    Accessed 2026-08-07

Further reading on this site

Follow-up questions

Our product nearly matches a category but does more. Are we in it?+

Possibly not. Guidance treats a product that substantially exceeds or substantially falls short of a category as outside it, judged objectively on the product's actual technical characteristics rather than on how it is marketed. Security orchestration, automation and response software generally exceeds the SIEM category because incident response forms a core part of its capabilities. A log viewer that performs no correlation falls short of it.

Can our class change without us changing the product?+

Yes. Article 7(3) empowers the Commission to amend Annex III by delegated act, adding a category within either class, moving a category between classes, or withdrawing one. Article 8(1) works similarly for the certification requirement attached to Annex IV categories. Treat a classification as a position to re-check rather than a fact settled once.

Does open source in an Annex III category lose module A?+

No. Article 32(5) lets manufacturers of products with digital elements qualifying as free and open-source software that fall under the Annex III categories demonstrate conformity using one of the Article 32(1) procedures, which keeps internal control available to them. This is operative in the Regulation rather than a concession in guidance.

Terms used in this answer

Default Class Product (CRA)Default Class products are the baseline category under the EU Cyber Resilience Act - products with digital elements that do not fall into the Important Class I or Class II elevated risk classifications. The vast majority of consumer and commercial connected products are Default Class. Manufacturers may self-certify conformity through an internal control procedure.Important Product Class IImportant Product Class I is the lower tier of the CRA's two-tier classification for products with digital elements that present a significant cybersecurity risk. Class I products face an elevated conformity assessment pathway compared to Default Class products, but less stringent than Class II. Examples include identity management software and general-purpose browsers.Important Product Class IIImportant Product Class II is the highest risk tier under the EU Cyber Resilience Act's product classification system, covering products with digital elements whose compromise could have severe or widespread impact. Class II products - including industrial control systems, medical devices, and critical infrastructure components - face mandatory third-party conformity assessment.Conformity Assessment ProcedureA Conformity Assessment Procedure is the formal process by which a manufacturer demonstrates that a product meets applicable EU essential requirements before affixing the CE mark and placing it on the market. Under the Cyber Resilience Act, the required procedure depends on the product's risk classification.Notified BodyA Notified Body is an independent third-party organisation accredited by an EU member state to conduct conformity assessments on behalf of manufacturers. Under the Cyber Resilience Act, Notified Bodies are required for Class II and certain Class I products that cannot self-certify compliance.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.