Stavenor

Guides

CRA Important Products: Class I, Class II and the Core Functionality Test

Updated 20 September 20263 min read

Under the Cyber Resilience Act, a product's classification decides how you prove conformity — and whether you may self-assess at all.


Three levels

Level Where listed Conformity route
Default Not in Annex III or IV Self-assessment — internal control, module A
Important, Class I Annex III, Class I — 19 categories Module A only if harmonised standards, common specifications or identified certification schemes are applied in full; otherwise modules B+C or H
Important, Class II Annex III, Class II — 4 categories Notified body — modules B+C or H
Critical Annex IV — 3 categories May be required to obtain a European cybersecurity certificate by delegated act

The test that is most often got wrong

Core functionality, not mere integration. Recital 45: an important product is one whose core functionality is that of a listed category. A product that merely integrates such a function is not thereby important. A device that embeds a firewall is not a Class II product; a device whose core function is a firewall is.

The Commission is to adopt an implementing act specifying the technical description of the categories. Check whether it has been adopted, and use it where available.


Annex III, Class I — all 19 categories

  1. Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
  2. Standalone and embedded browsers
  3. Password managers
  4. Software that searches for, removes, or quarantines malicious software
  5. Products with the function of virtual private network (VPN)
  6. Network management systems
  7. Security information and event management (SIEM) systems
  8. Boot managers
  9. Public key infrastructure and digital certificate issuance software
  10. Physical and virtual network interfaces
  11. Operating systems
  12. Routers, modems intended for the connection to the internet, and switches
  13. Microprocessors with security-related functionalities
  14. Microcontrollers with security-related functionalities
  15. ASICs and FPGAs with security-related functionalities
  16. Smart home general purpose virtual assistants
  17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
  18. Internet connected toys covered by Directive 2009/48/EC
  19. Personal wearable products worn or placed on a human body with a health monitoring purpose to which Regulation (EU) 2017/745 or 2017/746 do not apply, or personal wearables intended for use by and for children

Annex III, Class II — 4 categories

  1. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
  2. Firewalls, intrusion detection and prevention systems
  3. Tamper-resistant microprocessors
  4. Tamper-resistant microcontrollers

Annex IV — critical products

  1. Hardware devices with security boxes
  2. Smart meter gateways within smart metering systems, and other devices for advanced security purposes, including for secure cryptoprocessing
  3. Smartcards or similar devices, including secure elements

The Class I trap

A Class I manufacturer may use module A only by applying harmonised standards, common specifications or identified certification schemes in full. Until the relevant harmonised standards are cited in the Official Journal, that route is not available — plan for a notified body as the fallback.

Sources

Position as at 20 September 2026. General information, not legal advice.