Independent information resource Product security · EU CRA
CRA readiness, templates, tools and software / 04

CRA Product Classification Checklist

A practical CRA product classification checklist for assessing important class I, important class II and critical products using Articles 7 and 8, Annexes III and IV and Commission Implementing Regulation (EU) 2025/2392.

IN BRIEF

Do not classify from the product's marketing label alone. Identify its core functionality, compare that functionality with the official category descriptions, document near matches and exclusions, record the selected category and connect the result to conformity assessment. A checklist can structure this analysis but should not hide uncertainty behind an automatic score.

01 / 10

Confirm CRA Scope Before Classification

Classification is not the same as scope. First establish that the item is an in-scope product with digital elements. Only then assess whether Articles 7 or 8 place the product in an important or critical category. A classification checklist should therefore begin with the product's existing scope record rather than repeat the entire scope analysis.

02 / 10

Identify the Product's Core Functionality

Articles 7 and 8 use the core functionality of the product to determine whether it falls into an important or critical category. Record the functions that define why the product exists and distinguish them from secondary or incidental features. Commission Implementing Regulation (EU) 2025/2392 confirms that core functionality is central to applying the technical category descriptions.

03 / 10

Compare Against Annex III Class I

Check whether the product's core functionality matches a class I category in Annex III and the corresponding technical description in Implementing Regulation 2025/2392. Examples include identity-management systems, browsers, password managers, malware-detection software, VPN products, network-management systems and operating systems. Record the exact category and the facts supporting or rejecting the match.

04 / 10

Compare Against Annex III Class II

Class II contains a smaller set of important products with higher conformity-assessment consequences, including hypervisors and container runtime systems supporting virtualised execution, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and tamper-resistant microcontrollers. The checklist should document why the product does or does not satisfy the official technical description.

05 / 10

Check Annex IV Critical Product Categories

Annex IV identifies critical products with digital elements, including hardware devices with security boxes, certain advanced-security devices and smartcards or similar devices. Use the technical descriptions in Implementing Regulation 2025/2392 instead of relying only on the short category heading.

06 / 10

Do Not Classify the Finished Product Merely Because It Contains an Important Component

Article 7 states that integrating a product with digital elements that has the core functionality of an Annex III category does not by itself make the finished product subject to the important-product conformity procedures. The checklist should therefore distinguish the product being classified from components integrated into it.

07 / 10

Document Near Matches and Uncertainty

Where a product resembles a listed category but the technical description is not clearly satisfied, record the competing interpretations and the product facts that create uncertainty. A readiness tool should flag the issue for review rather than forcing a yes-or-no answer based only on keywords.

08 / 10

Connect Classification to Article 32

Classification matters because important and critical categories can be subject to conformity-assessment procedures that are stricter than those available to other products. The classification record should therefore link directly to the conformity-route decision under Article 32 so that the selected assessment procedure can be traced back to the product category.

09 / 10

Retain the Technical Description Used

Record the version of the legal category description used for the decision. Annexes III and IV can be amended under the CRA, and implementing descriptions can also evolve. A future reviewer should be able to see which legal text and technical description supported the classification at the time.

10 / 10

Review Classification When Core Functionality Changes

A product can change materially over time. Reassess classification when new core functionality is added, when a product is substantially redesigned, when an official category description changes or when the Commission amends Annex III or Annex IV. Version the classification decision alongside the product record.

REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.