Annex III, Class II (1)
Hypervisors and container runtime systems
Hypervisors & container runtimes are important product, class ii under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. Isolation between tenants and workloads is the security promise of modern infrastructure; an escape breaks every boundary at once. Class II therefore requires third-party conformity assessment.
Updated 2026-09-12 · Operational guidance, not legal advice.
- Classification
- Important product — Class II
- Conformity route
- Third-party assessment required
- Reference
- Annex III, Class II (1) · Art. 32(3)
What the annex says
Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments.
Paraphrase of Annex III, Class II (1); the Official Journal text governs.
Typical products in this category
- Type-1 and type-2 hypervisors
- Container runtimes and orchestration components that execute workloads
- Virtualisation platforms placed on the market as products
Where the boundary runs
Products that merely run inside a container are not runtimes. Cloud services that use a hypervisor internally are services, not products, unless the hypervisor itself is placed on the market.
The test is core functionality (Article 7). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.
Conformity assessment
Third-party assessment required. EU-type examination (Module B) with conformity to type (Module C), or full quality assurance (Module H), involving a notified body; alternatively a European cybersecurity certificate at assurance level 'substantial' or higher where a scheme exists. (Art. 32(3))
What to prepare operationally
- Third-party assessment (Module B + C or Module H) applies regardless of standards used; plan notified-body engagement early.
- Isolation-escape vulnerabilities are severe by nature; the reportability review should be pre-decided in the runbook.
- Provide VEX statements aggressively — customers ask about every kernel CVE.
- Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.
Frequently asked
- Is every hypervisors & container runtimes product an important product — class ii?
- Only where the listed function is the product's core functionality (Article 7). Products that merely run inside a container are not runtimes. Cloud services that use a hypervisor internally are services, not products, unless the hypervisor itself is placed on the market.
- What changes compared with a default product?
- EU-type examination (Module B) with conformity to type (Module C), or full quality assurance (Module H), involving a notified body; alternatively a European cybersecurity certificate at assurance level 'substantial' or higher where a scheme exists. The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
- From when?
- Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.