Annex III, Class I (1)

Identity management systems and privileged access management software

Identity & access management are important product, class i under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. These products decide who gets in. A compromised identity system is the fastest route to every other system in an organisation, which is why the co-legislators placed authentication and access control at the top of Class I.

Updated 2026-09-12 · Operational guidance, not legal advice.

Classification
Important product — Class I
Conformity route
Self-assessment only with fully applied standards
Reference
Annex III, Class I (1) · Art. 32(2)

What the annex says

Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers.

Paraphrase of Annex III, Class I (1); the Official Journal text governs.

Typical products in this category

  • Single sign-on and identity providers
  • Privileged access management (PAM) vaults and session brokers
  • Badge, PIN and biometric access-control readers
  • Directory services and federation gateways

Where the boundary runs

An application with a login page is not an identity management system; the category targets products whose core functionality is managing identities, credentials or access decisions for other systems. An embedded biometric reader on a door controller is in scope; a fingerprint sensor inside a phone is judged as part of the phone.

The test is core functionality (Article 7). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.

Conformity assessment

Self-assessment only with fully applied standards. Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). (Art. 32(2))

What to prepare operationally

  1. Document how credentials and secrets are stored, rotated and revoked; this is the first question a notified body asks.
  2. Keep an SBOM for the management plane and for firmware on readers — both ship as part of the product.
  3. Define the support period per hardware generation; access readers routinely run for ten years.
  4. Prepare the Article 14 runbook: exploited authentication bypasses are almost always reportable.
  5. Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.

Frequently asked

Is every identity & access management product an important product — class i?
Only where the listed function is the product's core functionality (Article 7). An application with a login page is not an identity management system; the category targets products whose core functionality is managing identities, credentials or access decisions for other systems. An embedded biometric reader on a door controller is in scope; a fingerprint sensor inside a phone is judged as part of the phone.
What changes compared with a default product?
Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
From when?
Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.

Other important product — class i categories

Classify it in Vellaci — with reasoning on record.

The onboarding classifier asks which listed functions your product provides and whether they are core, cites the annex, and stores the approved decision on the product.