Annex III, Class I (5)
Products with digital elements with the function of virtual private network (VPN)
VPN products are important product, class i under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. VPN gateways sit on the network edge, terminate encrypted traffic and are reachable from the internet. Exploited VPN appliance vulnerabilities have been the initial access vector in a large share of recent intrusion campaigns.
Updated 2026-09-12 · Operational guidance, not legal advice.
- Classification
- Important product — Class I
- Conformity route
- Self-assessment only with fully applied standards
- Reference
- Annex III, Class I (5) · Art. 32(2)
What the annex says
Products with digital elements with the function of virtual private network (VPN).
Paraphrase of Annex III, Class I (5); the Official Journal text governs.
Typical products in this category
- Remote-access VPN gateways and clients
- Site-to-site VPN appliances
- SD-WAN products whose core function is encrypted tunnelling
Where the boundary runs
A product that supports a VPN protocol as one of many features (a router, an operating system) is classified by its core function, not by the VPN feature. Managed VPN services delivered purely as a service are outside the CRA's product scope unless a product is placed on the market.
The test is core functionality (Article 7). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.
Conformity assessment
Self-assessment only with fully applied standards. Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). (Art. 32(2))
What to prepare operationally
- Expect appliance CVEs to appear in exploitation catalogues within days; the reportability review must be rehearsed.
- Maintain SBOMs for the appliance OS and management interface, not only the tunnelling stack.
- Publish security advisories and a clear end-of-support date per hardware generation.
- Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.
Frequently asked
- Is every vpn products product an important product — class i?
- Only where the listed function is the product's core functionality (Article 7). A product that supports a VPN protocol as one of many features (a router, an operating system) is classified by its core function, not by the VPN feature. Managed VPN services delivered purely as a service are outside the CRA's product scope unless a product is placed on the market.
- What changes compared with a default product?
- Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
- From when?
- Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.