Cyber Resilience Act

Important and critical product categories under the CRA.

Annex III lists product categories whose core functionality makes them important — Class I or Class II — and Annex IV lists critical categories that may become subject to mandatory European certification. The classification decides the conformity assessment route; it does not change the essential requirements or the Article 14 reporting duty, which apply to every product with digital elements.

Important product — Class I

Self-assessment only with fully applied standards · Art. 32(2)

  • Annex III, Class I (1)

    Identity & access management

    Single sign-on and identity providers · Privileged access management (PAM) vaults and session brokers

  • Annex III, Class I (2)

    Browsers

    Desktop and mobile web browsers · Embedded browser engines in kiosks, infotainment and set-top boxes

  • Annex III, Class I (3)

    Password managers

    Consumer and enterprise password vaults · Browser-integrated credential managers shipped as separate products

  • Annex III, Class I (4)

    Anti-malware

    Endpoint protection and EDR agents · Mail and file gateway scanners

  • Annex III, Class I (5)

    VPN products

    Remote-access VPN gateways and clients · Site-to-site VPN appliances

  • Annex III, Class I (6)

    Network management systems

    Network monitoring and configuration platforms · Wireless LAN controllers

  • Annex III, Class I (7)

    SIEM

    Log collection, correlation and alerting platforms · Security data lakes marketed as SIEM

  • Annex III, Class I (8)

    Boot managers

    UEFI boot loaders and shims · Embedded bootloaders shipped as products

  • Annex III, Class I (9)

    PKI & certificate issuance

    Certificate authority software · Certificate lifecycle management platforms

  • Annex III, Class I (10)

    Network interfaces

    Network interface cards with firmware · SmartNICs and DPUs

  • Annex III, Class I (11)

    Operating systems

    Desktop, server and mobile operating systems · Embedded and real-time operating systems shipped commercially

  • Annex III, Class I (12)

    Routers, modems & switches

    Consumer and SME routers and gateways · DSL, cable and fibre modems

  • Annex III, Class I (13)–(14)

    Secure MPUs & MCUs

    MCUs with hardware crypto accelerators, secure boot or trusted execution · Application processors with TrustZone-class isolation

  • Annex III, Class I (15)

    Security ASICs & FPGAs

    Crypto accelerators · Programmable logic used for secure boot or key storage

  • Annex III, Class I (16)

    Smart home assistants

    Voice assistants and smart speakers · Home hubs whose core function is a general-purpose assistant

  • Annex III, Class I (17)

    Smart locks, cameras & alarms

    Smart door locks · Security and doorbell cameras

  • Annex III, Class I (18)

    Connected toys

    Toys with microphones, cameras or chat features · GPS-enabled toys and trackers marketed as toys

  • Annex III, Class I (19)

    Health & children's wearables

    Fitness and sleep trackers · Smartwatches marketed for wellbeing metrics

Important product — Class II

Third-party assessment required · Art. 32(3)

  • Annex III, Class II (1)

    Hypervisors & container runtimes

    Type-1 and type-2 hypervisors · Container runtimes and orchestration components that execute workloads

  • Annex III, Class II (2)

    Firewalls, IDS & IPS

    Network firewalls and next-generation firewalls · Web application firewalls delivered as products

  • Annex III, Class II (3)

    Tamper-resistant MPUs

    Processors with physical tamper detection and response · Security co-processors for payment and identity terminals

  • Annex III, Class II (4)

    Tamper-resistant MCUs

    Secure MCUs with active shielding and tamper response · Authentication ICs for accessories and consumables

Critical product

European certification may become mandatory · Art. 8, Art. 32(4)

  • Annex IV (1)

    Hardware security boxes

    Hardware security modules (HSMs) · Payment terminals with secure enclosures

  • Annex IV (2)

    Smart meter gateways

    Smart meter gateways in energy metering systems · Secure cryptoprocessing devices for utilities and infrastructure

  • Annex IV (3)

    Smartcards & secure elements

    Payment and identity smartcards · Embedded secure elements in phones and IoT devices

FAQ

Classification questions.

My product is not on either list. Is it out of scope?
No. Almost every software or connected hardware product placed on the EU market is a product with digital elements and must meet the essential requirements, handle vulnerabilities and report under Article 14. Not being listed means it is a default product, which may use self-assessment (internal control) for conformity — the obligations themselves remain.
What does 'core functionality' mean in practice?
The listed function must be what the product is for, not a feature it happens to include. An operating system that ships a VPN client is classified as an operating system (Class I on its own account), not as a VPN product; a project-management tool with a login screen is not an identity management system. Document the judgement with reasoning and an approver — it determines the conformity route and can be challenged.
Can the lists change?
Yes. The Commission may amend Annex III and Annex IV by delegated act to add or remove categories and to specify definitions. Vellaci tracks the lists and versions its classification rules; a product's stored classification records which rule version produced it.
When do these obligations apply?
Reporting obligations under Article 14 have applied to all manufacturers since 11 September 2026. Conformity assessment, CE marking and the full set of obligations apply from 11 December 2027; provisions on notified bodies apply from 11 June 2026 so that third-party assessors exist in time.

Classify your products with reasoning and an approver.

Vellaci's onboarding walks through the Annex III and IV functions, records the rationale and stores the decision on the product.