Independent information resource Product security · EU CRA
CRA product classification / 07

How the CRA Treats Password Managers

Understand how password managers are classified under the Cyber Resilience Act, which password-storage and management products fall within Annex III Class I, and how classification affects conformity assessment.

IN BRIEF

The CRA treats password managers as Annex III Class I products when password storage and management form the product's core functionality. The category covers local, remote, browser-extension, enterprise and hardware implementations and can include generation, sharing and application-integration functions.

01 / 09

Password Managers Are Listed in Annex III Class I

Password managers are expressly listed in Annex III Class I. As with the other important-product categories, the relevant question is whether the supplied product has the core functionality of a password manager. A manufacturer should not classify a product solely because it handles a password somewhere in its workflow. Most applications authenticate users or transmit credentials without being password managers. The Class I category is aimed at products whose defining function includes storing and managing passwords for later use. That distinction should be made at the product-boundary level. A standalone password manager, browser extension or dedicated hardware product can present a straightforward case, while multifunction security suites and browsers with built-in credential features require a more careful core-functionality analysis.

  • Password managers are Annex III Class I.
  • Password management must be core functionality.
  • Ordinary password use does not make every application a password manager.
  • Multifunction products require product-boundary analysis.
02 / 09

The Category Centres on Password Storage

Commission Implementing Regulation (EU) 2025/2392 describes password managers as products with digital elements that store passwords. The storage can take place locally on a device or on a remote server. This makes the category technologically neutral with respect to where the password vault resides. A desktop application using local encrypted storage and a product synchronising a vault through remote infrastructure can both require analysis against the same Class I category. Manufacturers should document the storage architecture, encryption boundary, local and remote components and the supplied product boundary. Remote storage does not itself remove the product from the category, although the relationship between software, remote processing and CRA product scope still needs to be analysed correctly.

  • Local password storage is included.
  • Remote-server password storage is included.
  • Storage architecture does not by itself determine whether the category applies.
  • Document the supplied product and remote dependencies.
03 / 09

Password Generation and Sharing Can Be Part of the Category

The technical description recognises that password managers commonly do more than retain credentials. It identifies activities such as generation of passwords and password sharing as functions associated with the category. A product can therefore create strong passwords, retain them and make selected credentials available to authorised users or teams while remaining within the password-manager concept. Enterprise products may combine vaulting, generation, organisational sharing, access policies and auditing. The manufacturer should identify which capabilities are part of the password-management core and which are secondary features. The presence of collaboration or administrative controls does not remove a product from the category when its defining purpose remains password storage and management.

  • Password generation can be included.
  • Password sharing can be included.
  • Enterprise collaboration features can coexist with password-manager functionality.
  • Focus on the defining credential-management purpose.
04 / 09

Integration With Applications Is Expressly Recognised

The implementing regulation also recognises integration with local or third-party applications for the usage of passwords. This reflects common password-manager behaviour such as autofill, application integration, browser integration and use of stored credentials in external services. Integration should be distinguished from the separate question of whether the password manager is itself integrated into a larger product. A standalone password-manager extension can be a product in its own right, while a browser that includes a built-in credential vault needs a host-product core-functionality analysis. The manufacturer should therefore document both directions of integration: how the password manager uses credentials with other applications and whether password management itself is a separate product or one function inside a broader product.

05 / 09

The Official Examples Cover Several Password-Manager Forms

Commission Implementing Regulation (EU) 2025/2392 gives several non-exhaustive examples. These include local password managers, password managers provided as browser extensions, enterprise password managers and hardware-based password managers. The examples confirm that Class I status is not tied to one delivery model or device type. Software installed locally, browser-based extensions, enterprise products and dedicated hardware can all fit the technical description. Because the examples are not exhaustive, a manufacturer should not assume that a newer delivery model falls outside the category merely because it is not named. The classification should still be based on whether the product's core functionality meets the technical description.

  • Local password managers are examples.
  • Browser-extension password managers are examples.
  • Enterprise password managers are examples.
  • Hardware-based password managers are examples.
06 / 09

A Built-In Password Feature Does Not Automatically Reclassify the Host Product

Browsers, security suites, operating systems and other products can contain password-storage capabilities. Article 7 prevents automatic important-product reclassification merely because a product with the core functionality of a listed category is integrated into another product. A browser with a password-management feature therefore needs to be classified according to the core functionality of the browser as a product, while a separately supplied password-manager extension can have its own Class I classification. The same reasoning applies to business platforms that store application credentials as one small part of a broader workflow. The classification record should explain the host product's core functionality, identify any separately supplied password-management component and avoid using one embedded feature as a substitute for the complete product analysis.

  • Built-in password storage does not automatically control host classification.
  • Separately supplied extensions can require their own analysis.
  • Identify host-product and component boundaries.
  • Document the role of the password-management feature.
07 / 09

Password Managers Should Be Distinguished From PAM Products

Password managers and privileged access management products can overlap operationally, but the CRA lists them under different aspects of Annex III. Password managers are category 3, while identity management systems and privileged access management software and hardware appear in category 1. A password manager primarily stores and manages passwords, while a PAM product can control and monitor privileged access rights to IT or OT systems and sensitive information. Some enterprise security products may perform both roles. In that case, the manufacturer should identify all plausible categories and determine which functions form the product's core functionality. A multifunction product should not be forced into one category merely because one marketing label is more familiar.

  • Password managers have their own Class I category.
  • PAM appears within the identity-management category.
  • Multifunction products can require screening against both.
  • Use technical functionality rather than marketing terminology.
08 / 09

Class I Conformity Rules Apply to Password-Manager Products

A password manager that falls within Annex III Class I is subject to the Class I conformity framework in Article 32(2). Internal control can remain available where the applicable conditions are met, including the relevant use of harmonised standards, common specifications or an applicable European cybersecurity certification scheme. Where those conditions are not met, a stricter assessment route is required. This means the product classification should feed directly into standards mapping, security evidence and release planning. Password managers can handle highly sensitive credential data, so the product's cybersecurity risk assessment and Annex I controls should also reflect vault protection, authentication, confidentiality, integrity, secure updates, vulnerability handling and the security of remote dependencies where applicable.

  • Password managers in the category are Class I.
  • Class I internal control is conditional.
  • A stricter assessment route may be required.
  • Classification should be linked to the product security evidence.
09 / 09

Document the Password-Manager Boundary and Delivery Model

A practical classification record should identify the password-manager product, version, delivery model, storage architecture and core credential-management functions. It should state whether passwords are stored locally, remotely or through both models and identify generation, sharing, autofill or external-application integration functions. Where the password manager is embedded inside another product, the record should explain whether it is separately supplied and why it does or does not determine the host-product classification. The record can then reference Annex III Class I category 3, Commission Implementing Regulation (EU) 2025/2392, the cybersecurity risk assessment and the selected Article 32 route. Product architecture or delivery-model changes should trigger review.

  • Record the product and version.
  • Record local and remote storage architecture.
  • Record generation, sharing and integration functions.
  • Distinguish standalone and integrated implementations.
  • Record the Article 32 route.
  • Review after material product changes.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.