Independent information resource Product security · EU CRA
CRA product classification / 08

How the CRA Treats Network Management Systems

Understand how network management systems are classified under the Cyber Resilience Act, which monitoring and configuration functions fall within Annex III Class I, and how classification affects conformity assessment.

IN BRIEF

The CRA treats qualifying network management systems as Annex III Class I products. The technical description combines monitoring with control of network operations and configuration, helping distinguish network management systems from tools that merely observe traffic or collect security events.

01 / 09

Network Management Systems Are Annex III Class I Products

Network management systems appear in Annex III Class I. Classification still depends on core functionality, so the presence of administrative or network-monitoring features does not automatically place every infrastructure product into this category. The manufacturer should identify whether managing connected network elements is a defining purpose of the supplied product. This can include centralised products that supervise and control devices across an enterprise, telecommunications environment or other connected network. A router, endpoint application, SIEM platform or general infrastructure tool needs its own classification analysis even if it exposes network-management functions. The network management category should therefore be applied from the product boundary and technical description rather than from the broad fact that a product interacts with a network.

  • Network management systems are Class I.
  • Core functionality determines whether the category applies.
  • Interacting with a network is not enough.
  • The supplied product and its management purpose should be documented.
02 / 09

The Technical Description Focuses on Managing Connected Network Elements

Commission Implementing Regulation (EU) 2025/2392 describes network management systems as products with digital elements that manage connected network elements. The description gives examples of managed elements including servers, routers, switches, workstations, printers and mobile devices. The important point is that the product manages those elements rather than simply existing on the same network. Manufacturers should map the types of network elements the product discovers, inventories, supervises or controls and identify which functions are central to the product's intended purpose. The category can therefore apply across different technical environments where a product serves as a management plane for network-connected infrastructure.

  • Servers can be managed network elements.
  • Routers and switches can be managed network elements.
  • Workstations and printers can be managed network elements.
  • Mobile devices can also be managed network elements.
03 / 09

The Description Combines Monitoring With Operational Control

The 2025 technical description states that the systems manage connected network elements by monitoring them and controlling their network operations and configuration. This wording is useful for distinguishing full network management from passive observation. A product that only displays traffic statistics or receives telemetry without controlling network operations or configuration may require a different classification analysis. Conversely, a system that monitors the state of network devices and can change configuration, policies, interfaces, routing or other network operations is closer to the described category. Manufacturers should document both sides of the function: what the product observes and what it is capable of controlling. The classification should reflect the complete product functionality rather than one isolated monitoring screen.

  • Monitoring is part of the technical description.
  • Control of network operations is also relevant.
  • Control of configuration is expressly relevant.
  • Passive observation alone should not be assumed to equal network management.
04 / 09

End-to-End Network Management Systems Are Expressly Included

The implementing regulation states that the category includes, but is not limited to, end-to-end management systems. An end-to-end platform can manage multiple network elements, domains or device types from a central management layer. Such products may perform discovery, topology management, configuration, status monitoring, policy deployment, fault handling or other functions across network infrastructure. The exact feature set can vary, so classification should still be based on the technical description rather than a fixed checklist. Where the product's core function is to provide comprehensive management and control over connected network elements, the Class I category is likely to be directly relevant. The manufacturer should record which elements are controlled and which operations can be changed through the platform.

05 / 09

Dedicated Configuration Management Systems Can Also Be Included

A network management product does not need to provide every possible end-to-end function. The technical description expressly includes dedicated configuration management systems. A product focused on configuring network devices, maintaining network configuration state, enforcing desired settings or centrally controlling configuration changes can therefore fit the category where those activities constitute its core functionality. The phrase should not be extended automatically to every general software-configuration or endpoint-administration tool. The relevant context is management of connected network elements and their network operations and configuration. Manufacturers of automation and configuration platforms should identify which resources the product manages and whether its defining function is network management rather than general application deployment, infrastructure provisioning or device administration.

  • Dedicated configuration-management systems can be included.
  • The managed objects should be connected network elements.
  • General software configuration is not automatically network management.
  • Document the operational scope of configuration control.
06 / 09

Software-Defined Networking Controllers Are an Explicit Example

Controllers for software-defined networking are expressly identified as an example of dedicated configuration-management systems within the network management category. An SDN controller can provide centralised control over network behaviour by managing forwarding, policies, topology or other network functions through programmable interfaces. That central control role aligns closely with the CRA's rationale for treating certain network management products as important from a cybersecurity perspective. A compromise of the management plane can affect many dependent network elements at once. Manufacturers of SDN products should therefore assess the exact controller product boundary, its management interfaces, privileges, supported network elements and the security consequences of configuration changes as part of both classification and the cybersecurity risk assessment.

  • SDN controllers are an explicit example.
  • Centralised network control can create broad security impact.
  • Management privileges should be part of the risk assessment.
  • The controller should be classified as the supplied product.
07 / 09

Network Management Should Be Distinguished From SIEM

Network management and security information and event management can both collect information from many systems, but they are separate Annex III Class I categories. Network management systems manage connected network elements by monitoring and controlling their network operations and configuration. SIEM systems collect data from multiple sources, analyse and correlate that data and present it as actionable information for security purposes such as threat detection, incident detection, forensic analysis or compliance. A product can contain both sets of functions, particularly in large enterprise platforms. In that case, the manufacturer should screen both categories and determine the product's core functionality rather than using the presence of logs or dashboards as the deciding factor.

  • Network management focuses on managing network elements.
  • SIEM focuses on collecting, analysing and correlating security data.
  • The two categories can coexist in multifunction platforms.
  • Core functionality remains the classification test.
08 / 09

Class I Conformity Rules Apply to Qualifying Network Management Systems

A network management system that falls within Annex III category 6 is a Class I important product. Article 32(2) therefore determines the conformity route. Internal control can remain available where the applicable conditions involving harmonised standards, common specifications or European cybersecurity certification are met. Where the conditions are not met, the manufacturer must use one of the stricter conformity procedures. The Commission specifically identifies network management systems as an example of important products for which the standards and third-party-assessment framework matters. Manufacturers should resolve classification and standards coverage early because external assessment can affect development schedules, documentation readiness and market-placement timing.

  • Qualifying network management systems are Class I.
  • Class I internal control is conditional.
  • A notified body may be required.
  • Standards mapping should happen early.
09 / 09

Network Management Classification Should Capture Control Scope

A classification record should identify the product and version, managed network elements, monitoring capabilities, control capabilities and configuration functions. It should describe whether the product is end-to-end management, dedicated network configuration management, an SDN controller or another product matching the technical description. The manufacturer should also record adjacent functions such as SIEM, endpoint administration or infrastructure automation where they create classification questions. Once Class I status is established, the record can point to the cybersecurity risk assessment, privileged management interfaces, Annex I controls, technical documentation and selected Article 32 procedure. Changes that materially expand which network elements or operations the product controls should trigger classification and risk review.

  • Record the managed network elements.
  • Record monitoring and control capabilities.
  • Record network-configuration functions.
  • Screen adjacent categories such as SIEM where relevant.
  • Record the Article 32 route.
  • Review after major management-scope changes.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.