Annex III, Class I (1)
Identity management systems and privileged access management software
Identity & access management are important product, class i under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. These products decide who gets in. A compromised identity system is the fastest route to every other system in an organisation, which is why the co-legislators placed authentication and access control at the top of Class I.
Updated 2026-09-12 · Operational guidance, not legal advice.
- Classification
- Important product — Class I
- Conformity route
- Self-assessment only with fully applied standards
- Reference
- Annex III, Class I (1) · Art. 32(2)
What the annex says
Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers.
Paraphrase of Annex III, Class I (1); the Official Journal text governs.
Typical products in this category
- Single sign-on and identity providers
- Privileged access management (PAM) vaults and session brokers
- Badge, PIN and biometric access-control readers
- Directory services and federation gateways
Where the boundary runs
An application with a login page is not an identity management system; the category targets products whose core functionality is managing identities, credentials or access decisions for other systems. An embedded biometric reader on a door controller is in scope; a fingerprint sensor inside a phone is judged as part of the phone.
The test is core functionality (Article 7). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.
Conformity assessment
Self-assessment only with fully applied standards. Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). (Art. 32(2))
What to prepare operationally
- Document how credentials and secrets are stored, rotated and revoked; this is the first question a notified body asks.
- Keep an SBOM for the management plane and for firmware on readers — both ship as part of the product.
- Define the support period per hardware generation; access readers routinely run for ten years.
- Prepare the Article 14 runbook: exploited authentication bypasses are almost always reportable.
- Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.
Frequently asked
- Is every identity & access management product an important product — class i?
- Only where the listed function is the product's core functionality (Article 7). An application with a login page is not an identity management system; the category targets products whose core functionality is managing identities, credentials or access decisions for other systems. An embedded biometric reader on a door controller is in scope; a fingerprint sensor inside a phone is judged as part of the phone.
- What changes compared with a default product?
- Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
- From when?
- Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.