Partner Academy / CRA regulation / Module 7

Classifying a product across the three tiers

How Annex III important products and Annex IV critical products differ from the default tier, and why classification follows function.

Three tiers of risk

The CRA sorts products into three tiers that decide how conformity is proven. A default product appears in neither Annex III nor Annex IV and can use self-assessment. Important products are listed in Annex III and split into Class I and the higher-risk Class II. Critical products are listed in Annex IV and carry the highest assurance. The tier drives the whole compliance path, so getting it right is the first job on any engagement.

Annex III important products

Annex III Class I holds 19 categories, among them password managers, VPNs, SIEM systems, operating systems, routers and switches, smart-home security products such as smart locks and cameras, and internet-connected toys. Class II holds four higher-risk categories, which are hypervisors and container runtimes, firewalls and intrusion detection or prevention systems, and tamper-resistant microprocessors and microcontrollers. Class II always involves a third party, while Class I can sometimes self-assess once harmonised standards exist.

Annex IV critical products and classifying by function

Annex IV names the critical products, which are hardware devices with security boxes such as hardware security modules, smart meter gateways, and smartcards or secure elements. These carry the strictest route. Classification always follows the product's function rather than its name, so a consumer router is a default product while the same hardware managing an industrial network can be Class II. Notified bodies that assess these products are listed in the NANDO database.

Classify by what the product does, not what it is called. Function decides the tier, and the tier decides the conformity route.