Class I, class II, critical product: how the CRA classifies your product
The regime that applies to your product does not depend on your revenue but on its category. Four regimes coexist, and the gap between them comes down to one question: do you need a notified body?
Four regimes, not two
The Regulation does not split products into “covered” and “not covered”. It sets a broad principle — every product with digital elements placed on the Union market is in scope — and then designates categories for which the verification requirement steps up.
In practice, your product falls into one of these four cases:
| Regime | What it means | Conformity assessment |
|---|---|---|
| Default category | The product is in scope but appears in no Annex III or IV list. This covers the vast majority of connected industrial equipment. | Self-assessment possible (module A) |
| Class I (Annex III) | Important product: compromising it makes attacks on other systems easier. | Self-assessment where harmonised standards are applied in full, otherwise a notified body |
| Class II (Annex III) | Important product at a higher risk level. | Notified body |
| Critical product (Annex IV) | A product performing a core security function that other products depend on. | Notified body, reinforced assessment, potentially requiring European cybersecurity certification |
Whatever the class, the essential requirements of Annex I are the same. What the class changes is how you must demonstrate that you meet them (Art. 32).
Annex III — class I categories
These categories cover products whose compromise opens the way to other systems: security, networking, software foundations, components with security functions.
- Identity and access management systems
- Password managers
- Web browsers
- Antivirus / endpoint protection
- Virtual private networks (VPN)
- Network management systems
- Physical and virtual network interfaces
- SIEM systems
- Boot managers
- Public key infrastructure / certificates
- Operating systems
- Routers, modems (internet connection) and switches
- Microprocessors with security functions
- Microcontrollers with security functions
- ASIC / FPGA circuits with security functions
- General-purpose smart home assistants
- Smart home products with security functions (locks, cameras, alarms)
- Connected toys (tracking / social)
- Wearable health-tracking devices
Annex III — class II categories
Same logic, at a higher risk level: these products cannot be self-assessed.
- Hypervisors and container systems
- Firewalls / IDS / IPS
- Tamper-resistant microcontrollers
- Tamper-resistant microprocessors
Annex IV — critical products
Three categories, subject to the strictest regime in the Regulation.
- Hardware devices with security boxes (HSM)
- Smart meter gateways
- Smart cards / secure elements
My product is on none of the lists. What happens?
It falls into the default category: it is within scope, and you may carry out the conformity assessment yourself (module A). This is the most common case for connected industrial equipment, a sensor, a PLC or a gateway that performs no security function within the meaning of Annex III.
Beware the shortcut: “default category” does not mean “nothing to do”. The essential requirements, technical documentation, software bill of materials, vulnerability handling and CE marking apply just the same. Only the verification procedure is lighter.
Products that fall outside the scope
Two families of cases only:
Sector-specific rules (lex specialis)
A product already covered by sector-specific legislation falls under that legislation: medical devices (Regulations 2017/745 and 2017/746), motor vehicles (2019/2144), aviation (2018/1139), marine equipment (Directive 2014/90/EU).
Open-source software outside a commercial activity
Open-source software developed or supplied outside a commercial activity is not subject to the manufacturer's obligations. The Regulation creates a separate, lighter regime for open-source software stewards (Art. 24).
Frequently asked questions
Who decides my product's class?
Nobody assigns it to you. It is for the manufacturer to determine, under its own responsibility, whether its product falls into an Annex III or IV category. That determination must be documented and consistent with the rest of the technical documentation.
Does the class change the technical requirements?
No. The essential requirements of Annex I are identical whatever the class. The class determines which conformity assessment procedure applies (Art. 32): self-assessment or involvement of a notified body.
What is a notified body?
A third-party body designated by a Member State to carry out the conformity assessment procedures set out in the Regulation. Chapter IV, which governs their designation, has applied since 11 June 2026 — worth anticipating if your product falls under class II or Annex IV.
Where can I find the official list of categories?
The categories are set out in Annexes III and IV of Regulation (EU) 2024/2847, available on EUR-Lex. The wordings used on this page are readable paraphrases: the official text prevails.
Source: Regulation (EU) 2024/2847, Annexes III and IV.