Class I, class II, critical product: how the CRA classifies your product

The regime that applies to your product does not depend on your revenue but on its category. Four regimes coexist, and the gap between them comes down to one question: do you need a notified body?

Four regimes, not two

The Regulation does not split products into “covered” and “not covered”. It sets a broad principle — every product with digital elements placed on the Union market is in scope — and then designates categories for which the verification requirement steps up.

In practice, your product falls into one of these four cases:

RegimeWhat it meansConformity assessment
Default categoryThe product is in scope but appears in no Annex III or IV list. This covers the vast majority of connected industrial equipment.Self-assessment possible (module A)
Class I (Annex III)Important product: compromising it makes attacks on other systems easier.Self-assessment where harmonised standards are applied in full, otherwise a notified body
Class II (Annex III)Important product at a higher risk level.Notified body
Critical product (Annex IV)A product performing a core security function that other products depend on.Notified body, reinforced assessment, potentially requiring European cybersecurity certification

Whatever the class, the essential requirements of Annex I are the same. What the class changes is how you must demonstrate that you meet them (Art. 32).

Annex III — class I categories

These categories cover products whose compromise opens the way to other systems: security, networking, software foundations, components with security functions.

  • Identity and access management systems
  • Password managers
  • Web browsers
  • Antivirus / endpoint protection
  • Virtual private networks (VPN)
  • Network management systems
  • Physical and virtual network interfaces
  • SIEM systems
  • Boot managers
  • Public key infrastructure / certificates
  • Operating systems
  • Routers, modems (internet connection) and switches
  • Microprocessors with security functions
  • Microcontrollers with security functions
  • ASIC / FPGA circuits with security functions
  • General-purpose smart home assistants
  • Smart home products with security functions (locks, cameras, alarms)
  • Connected toys (tracking / social)
  • Wearable health-tracking devices

Annex III — class II categories

Same logic, at a higher risk level: these products cannot be self-assessed.

  • Hypervisors and container systems
  • Firewalls / IDS / IPS
  • Tamper-resistant microcontrollers
  • Tamper-resistant microprocessors

Annex IV — critical products

Three categories, subject to the strictest regime in the Regulation.

  • Hardware devices with security boxes (HSM)
  • Smart meter gateways
  • Smart cards / secure elements

My product is on none of the lists. What happens?

It falls into the default category: it is within scope, and you may carry out the conformity assessment yourself (module A). This is the most common case for connected industrial equipment, a sensor, a PLC or a gateway that performs no security function within the meaning of Annex III.

Beware the shortcut: “default category” does not mean “nothing to do”. The essential requirements, technical documentation, software bill of materials, vulnerability handling and CE marking apply just the same. Only the verification procedure is lighter.

Products that fall outside the scope

Two families of cases only:

Sector-specific rules (lex specialis)

A product already covered by sector-specific legislation falls under that legislation: medical devices (Regulations 2017/745 and 2017/746), motor vehicles (2019/2144), aviation (2018/1139), marine equipment (Directive 2014/90/EU).

Open-source software outside a commercial activity

Open-source software developed or supplied outside a commercial activity is not subject to the manufacturer's obligations. The Regulation creates a separate, lighter regime for open-source software stewards (Art. 24).

Frequently asked questions

Who decides my product's class?

Nobody assigns it to you. It is for the manufacturer to determine, under its own responsibility, whether its product falls into an Annex III or IV category. That determination must be documented and consistent with the rest of the technical documentation.

Does the class change the technical requirements?

No. The essential requirements of Annex I are identical whatever the class. The class determines which conformity assessment procedure applies (Art. 32): self-assessment or involvement of a notified body.

What is a notified body?

A third-party body designated by a Member State to carry out the conformity assessment procedures set out in the Regulation. Chapter IV, which governs their designation, has applied since 11 June 2026 — worth anticipating if your product falls under class II or Annex IV.

Where can I find the official list of categories?

The categories are set out in Annexes III and IV of Regulation (EU) 2024/2847, available on EUR-Lex. The wordings used on this page are readable paraphrases: the official text prevails.

Source: Regulation (EU) 2024/2847, Annexes III and IV.

Check your product's class

The assessment asks the questions that determine the category, then gives you the class, the applicable assessment procedure and the article the conclusion rests on.

Start the free assessment

Understanding the CRA, topic by topic

FirmVox is a compliance assistance tool. It is not legal advice and does not replace consulting the official text or qualified counsel.

CRA classes: class I, class II and critical products (Annexes III and IV) — FirmVox