Annex III, Class II (1)

Hypervisors and container runtime systems

Hypervisors & container runtimes are important product, class ii under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. Isolation between tenants and workloads is the security promise of modern infrastructure; an escape breaks every boundary at once. Class II therefore requires third-party conformity assessment.

Updated 2026-09-12 · Operational guidance, not legal advice.

Classification
Important product — Class II
Conformity route
Third-party assessment required
Reference
Annex III, Class II (1) · Art. 32(3)

What the annex says

Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments.

Paraphrase of Annex III, Class II (1); the Official Journal text governs.

Typical products in this category

  • Type-1 and type-2 hypervisors
  • Container runtimes and orchestration components that execute workloads
  • Virtualisation platforms placed on the market as products

Where the boundary runs

Products that merely run inside a container are not runtimes. Cloud services that use a hypervisor internally are services, not products, unless the hypervisor itself is placed on the market.

The test is core functionality (Article 7). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.

Conformity assessment

Third-party assessment required. EU-type examination (Module B) with conformity to type (Module C), or full quality assurance (Module H), involving a notified body; alternatively a European cybersecurity certificate at assurance level 'substantial' or higher where a scheme exists. (Art. 32(3))

What to prepare operationally

  1. Third-party assessment (Module B + C or Module H) applies regardless of standards used; plan notified-body engagement early.
  2. Isolation-escape vulnerabilities are severe by nature; the reportability review should be pre-decided in the runbook.
  3. Provide VEX statements aggressively — customers ask about every kernel CVE.
  4. Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.

Frequently asked

Is every hypervisors & container runtimes product an important product — class ii?
Only where the listed function is the product's core functionality (Article 7). Products that merely run inside a container are not runtimes. Cloud services that use a hypervisor internally are services, not products, unless the hypervisor itself is placed on the market.
What changes compared with a default product?
EU-type examination (Module B) with conformity to type (Module C), or full quality assurance (Module H), involving a notified body; alternatively a European cybersecurity certificate at assurance level 'substantial' or higher where a scheme exists. The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
From when?
Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.

Other important product — class ii categories

Classify it in Vellaci — with reasoning on record.

The onboarding classifier asks which listed functions your product provides and whether they are core, cites the annex, and stores the approved decision on the product.