CRA Important Products: Class I, Class II and the Core Functionality Test
Updated 20 September 20263 min read
Under the Cyber Resilience Act, a product's classification decides how you prove conformity — and whether you may self-assess at all.
Three levels
| Level | Where listed | Conformity route |
|---|---|---|
| Default | Not in Annex III or IV | Self-assessment — internal control, module A |
| Important, Class I | Annex III, Class I — 19 categories | Module A only if harmonised standards, common specifications or identified certification schemes are applied in full; otherwise modules B+C or H |
| Important, Class II | Annex III, Class II — 4 categories | Notified body — modules B+C or H |
| Critical | Annex IV — 3 categories | May be required to obtain a European cybersecurity certificate by delegated act |
The test that is most often got wrong
Core functionality, not mere integration. Recital 45: an important product is one whose core functionality is that of a listed category. A product that merely integrates such a function is not thereby important. A device that embeds a firewall is not a Class II product; a device whose core function is a firewall is.
The Commission is to adopt an implementing act specifying the technical description of the categories. Check whether it has been adopted, and use it where available.
Annex III, Class I — all 19 categories
- Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
- Standalone and embedded browsers
- Password managers
- Software that searches for, removes, or quarantines malicious software
- Products with the function of virtual private network (VPN)
- Network management systems
- Security information and event management (SIEM) systems
- Boot managers
- Public key infrastructure and digital certificate issuance software
- Physical and virtual network interfaces
- Operating systems
- Routers, modems intended for the connection to the internet, and switches
- Microprocessors with security-related functionalities
- Microcontrollers with security-related functionalities
- ASICs and FPGAs with security-related functionalities
- Smart home general purpose virtual assistants
- Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
- Internet connected toys covered by Directive 2009/48/EC
- Personal wearable products worn or placed on a human body with a health monitoring purpose to which Regulation (EU) 2017/745 or 2017/746 do not apply, or personal wearables intended for use by and for children
Annex III, Class II — 4 categories
- Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
- Firewalls, intrusion detection and prevention systems
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Annex IV — critical products
- Hardware devices with security boxes
- Smart meter gateways within smart metering systems, and other devices for advanced security purposes, including for secure cryptoprocessing
- Smartcards or similar devices, including secure elements
The Class I trap
A Class I manufacturer may use module A only by applying harmonised standards, common specifications or identified certification schemes in full. Until the relevant harmonised standards are cited in the Official Journal, that route is not available — plan for a notified body as the fallback.
Sources
- Regulation (EU) 2024/2847, Articles 7, 8 and 32; Annexes III, IV and VIII; recital 45 — Official Journal of the European Union
Position as at 20 September 2026. General information, not legal advice.