Product Assurance Learning

Home / Guides

Guide

CRA Important and Critical Products: Classes and Routes

Under the Cyber Resilience Act, Regulation (EU) 2024/2847, most products with digital elements fall in the default category and may use self-assessment. Products whose core functionality matches a category in Annex III are important products of class I or class II, and those matching Annex IV are critical products. Class II and critical products need a notified body or a European cybersecurity certification, and class I needs one unless you fully apply harmonised standards, common specifications or certification.

8 min readUpdated 7 October 2026By the VeridEx editorial team

The four CRA product categories at a glance

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements. The requirements are the same for every product. What changes with the category is the conformity assessment procedure you may use, and so whether a notified body must be involved. There are four categories:

  • Default category: every product with digital elements that is not listed in Annex III or Annex IV. This covers most products.
  • Important products, class I: the 19 product categories in Annex III, class I.
  • Important products, class II: the 4 product categories in Annex III, class II.
  • Critical products: the 3 product categories in Annex IV.

The category affects the conformity assessment route from the date the main obligations apply, 11 December 2027. For the full timeline, including the reporting obligations that have applied since 11 September 2026, see our Cyber Resilience Act dates guide.

Important products class I and class II: the Annex III list

Article 7 of the CRA defines important products. Class I and class II reflect the level of cybersecurity risk linked to the product's function. The names below are taken from Annex III. Some entries are shortened here, so read the full wording in the Official Journal.

Class I (Annex III, 19 categories)

  • Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
  • Standalone and embedded browsers
  • Password managers
  • Software that searches for, removes, or quarantines malicious software
  • Products with digital elements with the function of virtual private network (VPN)
  • Network management systems; security information and event management (SIEM) systems; boot managers
  • Public key infrastructure and digital certificate issuance software
  • Physical and virtual network interfaces; operating systems
  • Routers, modems intended for the connection to the internet, and switches
  • Microprocessors and microcontrollers with security-related functionalities; application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
  • Smart home general purpose virtual assistants
  • Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
  • Certain internet connected toys and certain personal wearable products (read the exact conditions in Annex III)

Class II (Annex III, 4 categories)

  • Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
  • Firewalls, intrusion detection and prevention systems
  • Tamper-resistant microprocessors
  • Tamper-resistant microcontrollers

Critical products under Annex IV

Article 8 deals with critical products. Annex IV currently lists three categories:

  • Hardware Devices with Security Boxes
  • Smart meter gateways within smart metering systems, and other devices for advanced security purposes, including for secure cryptoprocessing
  • Smartcards or similar devices, including secure elements

The Commission can amend Annex III and Annex IV by delegated act, adding, moving or removing categories, with a transition period. Check the consolidated text before you rely on a list you saved some time ago.

Implementing Regulation (EU) 2025/2392: the technical descriptions

The names in Annex III and Annex IV are short. Article 7(4) of the CRA required the Commission to adopt an implementing act with a technical description of each category by 11 December 2025. The Commission did so with Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 on the technical description of categories of important and critical products with digital elements. It was published in the Official Journal on 1 December 2025 and entered into force on 21 December 2025.

Its Annex I describes the important product categories, class I and class II. Its Annex II describes the critical product categories. When a category name could be read in more than one way, the technical description is the text to compare with your product. Read the description for every category that might be close to your product, and keep a copy of your reasoning.

The core functionality test

A product is important or critical only if it has the core functionality of a category in Annex III or Annex IV. Article 7(1) sets this rule. It is the main question in any classification.

Article 7(1) also says that integrating an important product into another product does not, in itself, make the host product subject to the stricter procedures. A component may be important while the product that contains it stays in the default category. The host product still has to meet all the CRA requirements.

In practice, ask these questions for each product:

  1. What is the main function the product is sold and used for?
  2. Does that main function match the name and the technical description of an Annex III or Annex IV category?
  3. Or does the product only contain a component, or a secondary feature, from a listed category?

Where the answer is unclear, record the arguments on both sides. Check the Commission guidance on the CRA, which the Commission started publishing in July 2026, for its reading of borderline cases.

CRA conformity assessment routes by category (Article 32)

Article 32(1) lists four procedures, set out in Annex VIII:

  • Module A, internal control: the manufacturer assesses conformity alone.
  • Modules B+C, EU-type examination followed by conformity to EU-type based on internal production control: a notified body examines the design and issues an EU-type examination certificate.
  • Module H, conformity based on full quality assurance: a notified body approves and monitors your quality system.
  • A European cybersecurity certification scheme under the EU Cybersecurity Act, where one is available and applicable.

Which of these you may use depends on the category:

CategoryExamples (Annex names)Allowed routesNotified body?
DefaultAny product with digital elements not listed in Annex III or IVA, B+C, H or a European cybersecurity certification schemeNo, unless you choose B+C or H
Important, class IPassword managers, VPN products, routers, smart home products with security functionalitiesA only if harmonised standards, common specifications or a European cybersecurity certification scheme (at least level "substantial") are applied; otherwise B+C or HYes, unless you fully apply those specifications or use certification
Important, class IIHypervisors, firewalls, tamper-resistant microcontrollersB+C, H, or a European cybersecurity certification scheme at least at level "substantial"Yes, or certification under a scheme
CriticalHardware Devices with Security Boxes, smartcards, secure elementsA European cybersecurity certificate if a delegated act under Article 8(1) requires it; otherwise the class II routesYes, or certification under a scheme

For class I, module A depends on full application. If you apply a harmonised standard only in part, or no suitable standard exists, you need B+C or H.

For critical products, Article 8(1) allows the Commission to require a European cybersecurity certificate at assurance level at least "substantial" for some Annex IV categories. Until such an act applies to your category, Article 8(2) sends you to the class II procedures. Check whether a delegated act has been adopted for your product.

Two further points from Article 32. Free and open-source software in an Annex III category may use any procedure in Article 32(1), provided the technical documentation is made public. Article 32(6) also requires conformity assessment fees to take into account the needs of microenterprises and small and medium-sized enterprises (SMEs), and to be reduced proportionately.

The CRA provisions on the notification of conformity assessment bodies have applied since 11 June 2026. Look for bodies notified under the CRA in NANDO, the Commission's database, and check that their scope covers your module and product category. Our guide Do I need a notified body? explains the modules and how to choose a body.

When are CRA harmonised standards expected?

For class I products, harmonised standards decide whether module A is possible. The Commission adopted standardisation request M/606, which covers 41 standards, both horizontal and product-specific. According to the Commission, the first request gives priority to standards for the important and critical product categories in Annex III and Annex IV.

The Commission's implementation timeline currently lists the first standardisation deliverables for the third quarter of 2026, and more by 30 October 2027. A standard gives presumption of conformity only once its reference is published in the Official Journal. Check the latest position before you plan a module A route, and read any restriction in the citation. Our guide on harmonised standards and presumption of conformity explains how citations work.

Radio products have a separate, current cybersecurity framework under the Radio Equipment Directive, with the EN 18031 series. See our RED cybersecurity guide.

Practical steps to classify your product

  1. Confirm the CRA applies. Check that your product is a product with digital elements and is not excluded by the CRA scope rules.
  2. Define the core functionality in one or two sentences, based on your intended purpose and marketing material.
  3. Screen Annex IV, then Annex III class II, then class I. Start from the strictest list so you do not miss a match.
  4. Compare with the technical descriptions in Implementing Regulation (EU) 2025/2392 for every category that looks close.
  5. Separate components from the product. A listed component inside your product does not, in itself, change your product's category.
  6. Record the decision in the technical documentation, with the version of the texts you used.
  7. Choose the route and, where needed, contact a notified body early, because capacity may be limited before December 2027.

The Cyber Resilience Act course works through these steps in detail.

Key points

  • CRA requirements are the same for all categories; the category decides the conformity assessment route.
  • Annex III lists 19 class I and 4 class II important product categories; Annex IV lists 3 critical categories.
  • Implementing Regulation (EU) 2025/2392 gives the technical description of each category.
  • Classification follows the core functionality of the product, and integrating a listed component does not, in itself, change the host product's category.
  • Class I can use module A only with harmonised standards, common specifications or certification applied; class II and critical products need a notified body or certification.

To see how the CRA fits into the wider CE system, start with the free first module of CE Marking Fundamentals.

Learn the whole route, step by step

CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.

Frequently asked questions

Is a router an important product under the CRA?

Yes, if routing is its core functionality. Annex III, class I, lists "routers, modems intended for the connection to the internet, and switches". Check the technical description in Implementing Regulation (EU) 2025/2392 to confirm your product matches it.

Do I need a notified body for a class I important product?

Only if you do not fully apply harmonised standards, common specifications or a European cybersecurity certification scheme at level "substantial" or higher. If you do, module A is allowed. Otherwise you must use EU-type examination (B+C) or full quality assurance (H), both with a notified body.

What is the difference between important and critical products in the CRA?

Important products are listed in Annex III, split into class I and class II. Critical products are listed in Annex IV and may be required to obtain a European cybersecurity certificate by delegated act. Without such an act, critical products follow the class II procedures.

Does a product become important if it contains a listed component?

Not in itself. Article 7(1) says that integrating a product with the core functionality of an Annex III category does not, in itself, subject the host product to the stricter procedures. The host product is classified by its own core functionality.

This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.

Related guides

Be first in line

Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.