Cyber Resilience Act
Important and critical product categories under the CRA.
Annex III lists product categories whose core functionality makes them important — Class I or Class II — and Annex IV lists critical categories that may become subject to mandatory European certification. The classification decides the conformity assessment route; it does not change the essential requirements or the Article 14 reporting duty, which apply to every product with digital elements.
Important product — Class I
Self-assessment only with fully applied standards · Art. 32(2)
- Annex III, Class I (1)
Identity & access management
Single sign-on and identity providers · Privileged access management (PAM) vaults and session brokers
- Annex III, Class I (2)
Browsers
Desktop and mobile web browsers · Embedded browser engines in kiosks, infotainment and set-top boxes
- Annex III, Class I (3)
Password managers
Consumer and enterprise password vaults · Browser-integrated credential managers shipped as separate products
- Annex III, Class I (4)
Anti-malware
Endpoint protection and EDR agents · Mail and file gateway scanners
- Annex III, Class I (5)
VPN products
Remote-access VPN gateways and clients · Site-to-site VPN appliances
- Annex III, Class I (6)
Network management systems
Network monitoring and configuration platforms · Wireless LAN controllers
- Annex III, Class I (7)
SIEM
Log collection, correlation and alerting platforms · Security data lakes marketed as SIEM
- Annex III, Class I (8)
Boot managers
UEFI boot loaders and shims · Embedded bootloaders shipped as products
- Annex III, Class I (9)
PKI & certificate issuance
Certificate authority software · Certificate lifecycle management platforms
- Annex III, Class I (10)
Network interfaces
Network interface cards with firmware · SmartNICs and DPUs
- Annex III, Class I (11)
Operating systems
Desktop, server and mobile operating systems · Embedded and real-time operating systems shipped commercially
- Annex III, Class I (12)
Routers, modems & switches
Consumer and SME routers and gateways · DSL, cable and fibre modems
- Annex III, Class I (13)–(14)
Secure MPUs & MCUs
MCUs with hardware crypto accelerators, secure boot or trusted execution · Application processors with TrustZone-class isolation
- Annex III, Class I (15)
Security ASICs & FPGAs
Crypto accelerators · Programmable logic used for secure boot or key storage
- Annex III, Class I (16)
Smart home assistants
Voice assistants and smart speakers · Home hubs whose core function is a general-purpose assistant
- Annex III, Class I (17)
Smart locks, cameras & alarms
Smart door locks · Security and doorbell cameras
- Annex III, Class I (18)
Connected toys
Toys with microphones, cameras or chat features · GPS-enabled toys and trackers marketed as toys
- Annex III, Class I (19)
Health & children's wearables
Fitness and sleep trackers · Smartwatches marketed for wellbeing metrics
Important product — Class II
Third-party assessment required · Art. 32(3)
- Annex III, Class II (1)
Hypervisors & container runtimes
Type-1 and type-2 hypervisors · Container runtimes and orchestration components that execute workloads
- Annex III, Class II (2)
Firewalls, IDS & IPS
Network firewalls and next-generation firewalls · Web application firewalls delivered as products
- Annex III, Class II (3)
Tamper-resistant MPUs
Processors with physical tamper detection and response · Security co-processors for payment and identity terminals
- Annex III, Class II (4)
Tamper-resistant MCUs
Secure MCUs with active shielding and tamper response · Authentication ICs for accessories and consumables
Critical product
European certification may become mandatory · Art. 8, Art. 32(4)
- Annex IV (1)
Hardware security boxes
Hardware security modules (HSMs) · Payment terminals with secure enclosures
- Annex IV (2)
Smart meter gateways
Smart meter gateways in energy metering systems · Secure cryptoprocessing devices for utilities and infrastructure
- Annex IV (3)
Smartcards & secure elements
Payment and identity smartcards · Embedded secure elements in phones and IoT devices
FAQ
Classification questions.
- My product is not on either list. Is it out of scope?
- No. Almost every software or connected hardware product placed on the EU market is a product with digital elements and must meet the essential requirements, handle vulnerabilities and report under Article 14. Not being listed means it is a default product, which may use self-assessment (internal control) for conformity — the obligations themselves remain.
- What does 'core functionality' mean in practice?
- The listed function must be what the product is for, not a feature it happens to include. An operating system that ships a VPN client is classified as an operating system (Class I on its own account), not as a VPN product; a project-management tool with a login screen is not an identity management system. Document the judgement with reasoning and an approver — it determines the conformity route and can be challenged.
- Can the lists change?
- Yes. The Commission may amend Annex III and Annex IV by delegated act to add or remove categories and to specify definitions. Vellaci tracks the lists and versions its classification rules; a product's stored classification records which rule version produced it.
- When do these obligations apply?
- Reporting obligations under Article 14 have applied to all manufacturers since 11 September 2026. Conformity assessment, CE marking and the full set of obligations apply from 11 December 2027; provisions on notified bodies apply from 11 June 2026 so that third-party assessors exist in time.
Read next
- Guide
CRA product classification: default, important (Class I / II) and critical
How Annex III and Annex IV categories work, the core-functionality test, what changes for conformity assessment under Article 32, edge cases, and how to document a classification decision that will survive scrutiny.
- Guide
CRA conformity assessment: Modules A, B + C and H, notified bodies and CE marking
The conformity assessment procedures of Article 32 and Annex VIII explained by product class, how harmonised standards give a presumption of conformity, when a notified body is needed, and what the declaration of conformity and CE marking require.
- Guide
CRA technical documentation: what Annex VII requires and how to keep it current
The contents of the technical documentation under Article 31 and Annex VII — product description, design and vulnerability-handling processes, risk assessment, support period, standards, test reports, declaration and SBOM — with a structure you can maintain per product for ten years.
- Docs
Product registry
Products, versions, lifecycle, classification, exposure context.
Classify your products with reasoning and an approver.
Vellaci's onboarding walks through the Annex III and IV functions, records the rationale and stores the decision on the product.