CRA product classification: default, important (Class I / II) and critical
Under the Cyber Resilience Act every product with digital elements meets the same essential requirements, but the route to demonstrating conformity depends on classification: default products may self-assess, important products in Annex III face stricter routes by class, and critical products in Annex IV may be required to hold a European cybersecurity certificate.
By the Vellaci teamPublished Updated 5 min readOperational guidance, not legal advice
Key facts
- Default product
- Not listed in Annex III or IV; self-assessment (Module A) available (Art. 32(1))
- Important — Class I
- 19 categories; self-assessment only with fully applied harmonised standards, else third party (Art. 32(2))
- Important — Class II
- 4 categories; third-party assessment always (Art. 32(3))
- Critical
- 3 categories; European certification may be mandated by delegated act (Art. 8)
- Test
- Core functionality of the product, not incidental features (Art. 7(1))
The categories
Most products with digital elements are default products. Products whose core functionality is listed in Annex III are important products: Class I (identity and access management, browsers, password managers, anti-malware, VPNs, network management, SIEM, boot managers, PKI, network interfaces, operating systems, routers and switches, secure microprocessors and microcontrollers, security ASICs and FPGAs, smart-home assistants, smart-home security devices, connected toys, health and children's wearables) or Class II (hypervisors and container runtimes, firewalls and intrusion detection or prevention systems, tamper-resistant microprocessors and microcontrollers). Annex IV lists critical products: hardware devices with security boxes, smart meter gateways and other advanced-security devices, and smartcards or similar devices including secure elements. Each category has its own page under CRA product categories on this site.
Core functionality
Classification depends on the product's core functionality. A product that incidentally contains a listed function is not automatically important: an operating system that ships a VPN client is an operating system; a project tool with a login page is not an identity management system; a router with a basic packet filter is a router, not a firewall. Conversely, a product marketed for a listed function is in the category even if it does other things. This judgement should be documented with reasoning and an approver, because it determines the conformity route and market surveillance authorities can challenge it.
Conformity routes
Article 32 and Annex VIII provide three procedures: internal control (Module A), EU-type examination followed by conformity to type based on internal production control (Modules B and C), and conformity based on full quality assurance (Module H). A European cybersecurity certificate under the Cybersecurity Act can substitute in defined cases.
| Classification | Available procedures | Notified body involved? |
|---|---|---|
| Default | Module A, or B + C, or H, at the manufacturer's choice | Only if B + C or H is chosen |
| Important — Class I | Module A only if harmonised standards, common specifications or a European scheme are applied in full; otherwise B + C or H | Yes, unless standards are fully applied |
| Important — Class II | B + C or H; or a European certificate at assurance level 'substantial' or higher | Yes |
| Critical | As Class II until a delegated act mandates a European certificate at 'substantial' or higher | Yes |
Edge cases worth documenting
- A device that embeds a listed component (a NIC, a bootloader, a secure element) is classified by its own core function; the component's manufacturer carries the obligations for the component as a product.
- Remote data processing that a product depends on is part of the product and is classified with it.
- Products under sector rules — medical devices, aviation, vehicles, marine — are excluded from the CRA in whole or in part; check Article 2 before classifying.
- Children's wearables and health wearables outside the medical device regulations are Class I; medical wearables are not CRA products.
- Industrial products are not a separate class; a PLC is classified by its function (often default), a safety-relevant firewall for OT is Class II.
How to document the decision
- List the listed functions the product provides and state for each whether it is core or incidental, with a sentence of reasoning.
- Name the resulting classification and the Annex reference.
- Name the conformity route you intend to follow and, for Class I self-assessment, the harmonised standards or specifications you will apply in full.
- Record the approver, the date and the rule version; store it on the product and in the technical documentation.
- Re-assess on substantial modification or when the Commission amends the annexes.
Worked example
A manufacturer sells an industrial gateway that routes traffic between a plant network and the cloud, offers a built-in stateful firewall and runs a Linux-based operating system it maintains. Three listed functions appear: router (Class I), firewall (Class II) and operating system (Class I). The product is marketed and bought as a secure gateway whose firewall is central to its value, so the firewall is core functionality and the product is an important product, Class II — third-party conformity assessment applies. Had the firewall been a basic, optional packet filter on a device sold as a router, the outcome would have been Class I, and with harmonised standards applied in full, self-assessment. The written reasoning is what makes either answer defensible.
How Vellaci handles it
Vellaci asks which listed functions the product provides and whether they are core, shows its reasoning with Annex references, and lets an authorised user approve or override with a rationale. The decision, reasoning, approver and rule version are stored on the product and in the audit log, and the conformity route is shown in the readiness framework.
Frequently asked questions
- When do we have to be classified?
- Conformity assessment and CE marking apply from 11 December 2027, so the classification must be settled well before that to plan notified-body capacity. Reporting under Article 14 (in force since 11 September 2026) does not depend on classification.
- Can the Commission change the lists?
- Yes, by delegated act, including adding or removing categories and specifying definitions. Track the amendments and version your classification rules.
- What if we disagree with a market surveillance authority?
- The documented reasoning is your position. Well-argued core-functionality assessments with an approver and date are exactly what authorities expect to see; undocumented ones are indefensible.