Classification does not change the existence of the CRA essential cybersecurity requirements in Annex I. It changes how the manufacturer must demonstrate conformity with them. The difference can determine whether manufacturer self-assessment is available, whether a notified body is needed, whether certification can be used and how early conformity planning must begin.
Classification Changes the Proof Route, Not Whether Cybersecurity Matters
The CRA applies essential cybersecurity requirements to products with digital elements within its scope. Product classification does not mean that default-category products have no cybersecurity duties while important or critical products do. The distinction primarily changes how the manufacturer demonstrates conformity with the applicable Annex I requirements. Article 32 provides a general conformity framework and then imposes more restrictive routes for products whose core functionality places them in Annex III or Annex IV. This is why classification should be treated as an early compliance decision rather than a label added at the end of product development. The result can change assessment strategy, use of standards, notified-body involvement, certification planning, project cost and the amount of lead time needed before market placement.
- Annex I cybersecurity requirements remain central.
- Classification primarily changes the conformity assessment route.
- Important and critical categories receive stricter treatment.
- The decision should be made before release planning is fixed.
Default CRA Products Can Use Module A Internal Control
Article 32(1) provides the general conformity assessment procedures available for products with digital elements. One of these is the internal control procedure based on Module A in Annex VIII. For products that do not have the core functionality of an Annex III important-product category or an Annex IV critical-product category, manufacturer self-assessment can therefore remain available without the special restrictions that Article 32 places on important products. The manufacturer still needs to perform the conformity assessment, prepare the required technical documentation, demonstrate that the applicable essential cybersecurity requirements are met, draw up the EU declaration of conformity and satisfy the other CRA obligations. Default classification is therefore not an exemption from compliance. It changes who can perform the conformity assessment and which procedure can be used.
- Module A is the internal-control procedure.
- Default-category products can generally use manufacturer self-assessment.
- Technical documentation is still required.
- The EU declaration of conformity is still required.
Class I Makes Self-Assessment Conditional
Annex III Class I creates an intermediate conformity position. Article 32(2) provides that where the manufacturer has not applied, or has applied only in part, the relevant harmonised standards, common specifications or qualifying European cybersecurity certification schemes, or where those mechanisms do not exist, the product and the manufacturer's processes must undergo one of the stricter procedures for the relevant essential cybersecurity requirements. This means Class I does not create an unconditional right to Module A self-assessment. The manufacturer needs to understand which technical specifications cover the product and requirements and whether they have been applied in the manner necessary to rely on the self-assessment route.
- Class I is not unconditional self-assessment.
- Harmonised standards can affect the available route.
- Common specifications can affect the available route.
- Applicable cybersecurity certification can also be relevant.
A Class I Product Can Move Into Third-Party Assessment
Where the conditions in Article 32(2) for relying on the Class I self-assessment route are not met, the manufacturer must use either EU-type examination under Module B followed by conformity to EU-type under Module C, or conformity assessment based on full quality assurance under Module H. This can introduce a notified body into the product release process. The practical consequence is that Class I classification should trigger an immediate standards-coverage review. Waiting until technical documentation is nearly complete can reveal too late that the project needs third-party assessment. Manufacturers should therefore record both the Class I category and the conformity-route reasoning rather than treating the class itself as a complete assessment decision.
Class II Removes the Ordinary Module A Route
Class II products receive stricter treatment under Article 32(3). The manufacturer must demonstrate conformity through EU-type examination under Module B followed by Module C, full quality assurance under Module H, or, where available and applicable, a European cybersecurity certification scheme pursuant to Article 27(9) at assurance level at least substantial. The ordinary Module A route is not one of the Class II procedures. This is why a classification change from Class I to Class II can materially affect a project even if the product's technical architecture has not otherwise changed. Third-party conformity planning, evidence readiness and potentially certification become structural release dependencies.
- Class II does not use the ordinary Module A route.
- Module B followed by Module C is available.
- Module H is available.
- Applicable cybersecurity certification can provide another route.
Module B and Module C Split Type Examination From Production Conformity
One of the stricter routes combines Module B and Module C. Module B is the EU-type examination procedure. A notified body examines the technical design of the product and verifies and attests that the technical design meets the applicable requirements. Module C then addresses conformity to the approved EU type based on internal production control. The combination separates examination of the product type from the manufacturer's responsibility to ensure that products placed on the market conform to that approved type. This makes configuration control, version management and the relationship between assessed design and released product especially important. Significant changes can require the manufacturer to determine whether existing assessment evidence remains sufficient.
- Module B is EU-type examination.
- A notified body assesses the technical design.
- Module C addresses conformity to the approved type.
- Product changes need controlled assessment.
Module H Uses Full Quality Assurance
Article 32 also permits the full quality assurance procedure based on Module H for the relevant product categories. Instead of focusing only on an individual type examination, Module H evaluates the manufacturer's quality system for design, development, production, final inspection and testing within the CRA conformity framework. This route can be attractive for manufacturers with mature product-development and quality processes, but it still requires the applicable external conformity assessment. The choice between Module B plus C and Module H should therefore be considered as part of compliance architecture rather than as a clerical decision made after development is complete.
- Module H is based on full quality assurance.
- It evaluates the manufacturer's quality system.
- Design and development processes are relevant.
- Production, inspection and testing processes are relevant.
Critical Products Have a Separate Article 8 Framework
Products whose core functionality matches Annex IV are critical products rather than Class II important products. Article 8 creates a specific mechanism under which the Commission can require products in Annex IV categories to obtain a European cybersecurity certificate under an applicable European cybersecurity certification scheme at assurance level at least substantial. The required assurance level must be proportionate to the cybersecurity risk. Where the Article 8 certification conditions and corresponding measures do not apply, the CRA routes Annex IV products through the stricter conformity procedures associated with Article 32. Manufacturers should therefore record Annex IV classification separately from Class II even where the immediate conformity procedures can overlap.
- Critical products are listed in Annex IV.
- Article 8 creates a cybersecurity certification mechanism.
- The required assurance level is at least substantial where that mechanism applies.
- Critical classification should not be recorded as Class II.
Classification Determines When a Notified Body Becomes a Project Dependency
The European Commission describes the conformity system in practical terms: most default-category products can use self-assessment, some Class I products require notified-body assessment depending on how conformity is demonstrated, and Class II and critical products are subject to stricter assessment. A notified body is a conformity assessment body that has been assessed, designated and formally notified for the relevant CRA activities. Once third-party assessment becomes necessary, the manufacturer must account for body availability, technical competence, evidence submission, assessment findings and scheduling. Classification therefore affects more than legal wording. It can change the critical path for product launch.
- Default products normally permit self-assessment.
- Class I can require a notified body.
- Class II uses stricter procedures.
- Assessment capacity and scheduling can affect launch timing.
Classification Changes the Value of Harmonised Standards
Harmonised standards can matter across the CRA, but they have a particularly important conformity consequence for Class I products because Article 32(2) connects use of relevant harmonised standards and other recognised specifications to the available assessment route. A manufacturer should therefore map the product's applicable essential cybersecurity requirements against the standards and specifications it intends to use. The exercise should identify whether the relevant requirements are fully covered, whether only part of a standard is being applied and whether additional assessment is needed. Standards mapping should be tied to the exact product version and classification so that the compliance team can explain why the selected conformity procedure is legally available.
- Standards mapping can affect Class I self-assessment.
- Partial application can change the route.
- Coverage should be mapped to relevant Annex I requirements.
- The reasoning should be preserved in the technical documentation.
Classification Does Not Replace the Cybersecurity Risk Assessment
Product classification and the cybersecurity risk assessment serve different purposes. Classification determines whether the product belongs to the default category, Class I, Class II or an Annex IV critical category and therefore helps determine the conformity procedure. The cybersecurity risk assessment determines which cybersecurity risks are associated with the specific product and how the manufacturer addresses the essential cybersecurity requirements throughout planning, design, development, production, delivery and maintenance. A Class I product can have severe product-specific risks, while a default-category product can also require substantial security controls. The legal class should therefore never be used as a substitute for product-specific security analysis.
- Classification selects the conformity framework.
- Risk assessment analyses product-specific cybersecurity risks.
- The two processes should inform each other.
- Neither process replaces the other.
Classification Affects Technical Documentation Planning
Annex VII requires technical documentation before the product is placed on the market. Classification affects how that documentation will be used during conformity assessment. Under manufacturer self-assessment, the manufacturer develops and retains the evidence supporting its own conformity conclusion. Under a notified-body procedure, the documentation and supporting evidence also need to support external examination of the product or the manufacturer's quality system. The classification record itself should therefore become part of the compliance evidence chain. It should identify the product, version, product boundary, core functionality, matching Annex category and selected Article 32 procedure, with references to the technical descriptions used to reach the decision.
- Technical documentation is required before market placement.
- Third-party routes increase external evidence scrutiny.
- The classification record should be reproducible.
- The selected Article 32 procedure should be documented.
The Conformity Route Comes Before the EU Declaration and CE Marking
The conformity assessment is not an isolated administrative exercise. The manufacturer must first determine and demonstrate conformity using the applicable procedure. Where compliance has been demonstrated, the manufacturer draws up the EU declaration of conformity under Article 28 and the relevant Annex provisions and follows the CRA rules for CE marking. Classification therefore influences the evidence path that has to be completed before those final market-access steps. A product team that waits until declaration or marking preparation to resolve classification risks discovering that the required conformity procedure has not yet been performed.
- Classification comes before final conformity demonstration.
- Conformity assessment precedes the EU declaration of conformity.
- CE marking depends on the applicable conformity process being completed.
- Classification should be resolved well before market placement.
A Product Change Can Trigger a New Classification Review
Classification should be maintained through product change control. A product can gain new functionality that causes its core functionality to match an Annex III or Annex IV category, or a significant redesign can change which function defines the product. The legal lists can also change because Article 7 empowers the Commission to amend Annex III, including adding categories, moving categories between Class I and Class II or removing categories. A product that was correctly classified when development began can therefore require a different conformity route later. Manufacturers should define review triggers for major functional releases, product-boundary changes, relevant delegated acts, Annex amendments and changes to applicable technical descriptions.
- Major new functionality can change classification.
- Annex III can be amended.
- A category can move from Class I to Class II.
- Classification review should be part of change control.
The Practical Decision Sequence Is Scope, Classification, Then Conformity Route
A practical CRA workflow begins by confirming that the supplied product is within scope and defining the product boundary. The manufacturer then identifies core functionality and screens the product against Annex III and Annex IV using the applicable technical descriptions. If there is no listed-category match, the product remains in the default conformity category. A Class I match triggers the Article 32(2) standards and conformity analysis. A Class II match triggers Article 32(3). An Annex IV match triggers the critical-product framework under Article 8 and Article 32(4). The selected route should then drive assessment planning, technical evidence, documentation and release controls. This sequence prevents a common mistake: choosing a conformity procedure before the legal product classification has been established.
- Confirm CRA scope.
- Define the product boundary.
- Identify core functionality.
- Screen Annex III and Annex IV.
- Map the result to Article 32.
- Plan evidence and assessment around that route.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.