The CRA places firewalls in Annex III Class II together with intrusion detection and prevention systems. The category covers products whose core function is protecting connected networks or systems by monitoring and restricting traffic. Because firewalls are Class II, the ordinary Class I conditional self-assessment path is not available.
Firewalls Are Annex III Class II Important Products
Firewalls appear in Annex III Class II together with intrusion detection and prevention systems. This is a materially different classification from many other cybersecurity products in Annex III Class I. A manufacturer should first confirm that the product falls within CRA scope and then determine whether firewall functionality is the product's core functionality. A standalone firewall appliance, virtual firewall or dedicated application firewall can present a direct classification case. A router, operating system, cloud platform or security suite that includes firewall capability requires a separate host-product analysis. Article 7 makes clear that integrating a listed important product does not by itself impose that product's conformity classification on the larger product.
- Firewalls are Class II.
- Class II is part of Annex III.
- Core functionality determines classification.
- An integrated firewall feature does not automatically classify the host product as a firewall.
The Technical Description Focuses on Traffic Protection
Commission Implementing Regulation (EU) 2025/2392 describes firewalls as products with digital elements that protect a connected network or system from unauthorised access by monitoring and restricting data communication traffic to and from that network or system. The description therefore combines a protective purpose with the ability to inspect or monitor traffic and restrict communications according to rules or security decisions. A manufacturer should identify what traffic the product observes, what communications it can permit or block, which network or application boundary it protects and whether that protective filtering function defines the supplied product. The presence of generic network filtering in another product should not be treated as a substitute for the full core-functionality analysis.
- Protection against unauthorised access is central.
- Traffic monitoring is part of the description.
- Traffic restriction is part of the description.
- The protected network or system boundary should be documented.
Network Firewalls Are Included
The implementing regulation expressly identifies network firewalls as products included in the category. Network firewalls can control communications between networks, segments, devices or other network zones using rules based on addresses, protocols, ports, connection state or other traffic characteristics. Their implementation can be physical, virtual or software-based. The CRA category is not limited to a particular deployment format. The classification question is whether protecting a connected network or system through monitoring and restricting traffic is the product's core functionality. Manufacturers should identify management interfaces, policy engines, filtering mechanisms and the consequences of firewall compromise as part of the classification record and cybersecurity risk assessment.
- Network firewalls are expressly included.
- Physical and virtual implementation can be relevant.
- Firewall policy and filtering behaviour should be documented.
- Compromise of the firewall should be reflected in the risk assessment.
Application Firewalls and Web Application Firewalls Can Be Included
The technical description also expressly includes application firewalls. Web application firewalls are identified as an example. These products can inspect and restrict application-layer communications in order to protect applications or services from unauthorised or malicious traffic. A WAF therefore does not fall outside the firewall category merely because it operates at the application layer rather than as a conventional network perimeter firewall. The manufacturer should document the traffic the product processes, the protected application or service, the policies or detection mechanisms used to restrict communications and whether firewall protection constitutes the product's core functionality. A broader application-delivery platform containing optional WAF functionality still requires a separate product-boundary analysis.
Filters and Anti-Spam Gateways Are Also Named Examples
Commission Implementing Regulation (EU) 2025/2392 identifies filters and anti-spam gateways among the examples of application firewalls. That does not mean every content filter or messaging tool is automatically a Class II firewall. The product still needs to meet the technical description and have the relevant protective traffic-control function as its core functionality. For an anti-spam gateway, the manufacturer should examine whether the product protects the connected system by monitoring and restricting communication traffic rather than merely categorising messages for convenience. Similar care is needed with web filters, secure email gateways and multifunction network-security platforms. The classification record should describe the protective traffic-control role rather than rely only on a commercial category name.
- Filters are included as examples.
- Anti-spam gateways are included as examples.
- Examples do not replace the core-functionality test.
- Multifunction security products require careful boundary analysis.
Firewalls Are Different From Intrusion Detection Systems
Firewalls share Annex III Class II category 2 with intrusion detection and intrusion prevention systems, but the technical descriptions distinguish the functions. A firewall protects a connected network or system by monitoring and restricting traffic. An intrusion detection system monitors traffic after it has entered the network environment and identifies suspicious activity or attempted, ongoing or completed intrusions. An intrusion prevention system combines detection with an active response to intrusion. A multifunction security product can implement all three capabilities. Where that occurs, the manufacturer should document each relevant function and determine the product's core functionality rather than assume that all Class II network-security products have identical technical characteristics.
- Firewalls monitor and restrict communications.
- IDS products detect suspicious activity and intrusions.
- IPS products detect and actively respond.
- All three are within the same Class II Annex III category.
A Router With Firewall Functionality Is Not Automatically a Class II Firewall
The core-functionality rule is particularly important for routers. Commission Implementing Regulation (EU) 2025/2392 specifically explains that products often incorporate components having the functionality of another important or critical category and gives a router integrating firewall functionality as an example. That integration does not by itself prevent the product from retaining the core functionality of a router. Manufacturers should therefore avoid treating every security-capable router as a Class II firewall. The product's defining function must be assessed. A router principally establishes and controls data flow between networks, while a firewall principally protects a connected network or system by monitoring and restricting traffic. Some products may require closer analysis where both functions are substantial.
- Router and firewall are separate CRA categories.
- Integrated firewall functionality does not automatically control router classification.
- Identify the product's defining function.
- Document multifunction products carefully.
Class II Requires a Stricter Conformity Assessment Route
Because firewalls are Class II, Article 32(3) governs the conformity assessment route. The manufacturer can use EU-type examination under module B followed by conformity to EU-type under module C, conformity assessment based on full quality assurance under module H, or an applicable European cybersecurity certification scheme at the required assurance level where that route is available. The ordinary conditional internal-control pathway available to Class I products does not apply to Class II firewalls. This makes notified-body or certification planning an early product-development dependency. Security testing, technical documentation and cybersecurity risk evidence should be prepared with the selected conformity route in mind rather than assembled only when market placement is approaching.
- Firewalls use the Class II Article 32(3) framework.
- Module B plus Module C is one route.
- Module H is another route.
- An applicable cybersecurity certification scheme can also be relevant.
Maintain a Firewall-Specific Classification Record
A firewall classification record should identify the exact product and version, protected network or system boundary, traffic-monitoring functions, traffic-restriction functions, deployment model and any application-layer filtering capabilities. It should state whether the product is a network firewall, application firewall or another product matching the technical description. Where firewall functionality is embedded into a router, operating system or broader platform, the record should explain why firewall functionality does or does not constitute the host product's core functionality. The Class II conclusion can then be connected to the Article 32 procedure, notified-body planning, technical documentation and product-security evidence. Significant changes in product purpose or filtering architecture should trigger classification review.
- Record the product and version.
- Record the protected network or system.
- Record traffic monitoring and restriction functions.
- Document integrated firewall functionality separately.
- Record the Article 32(3) route.
- Review after material functionality changes.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.