Independent information resource Product security · EU CRA
CRA product classification / 10

How the CRA Treats VPN Products

Understand how VPN products are classified under the Cyber Resilience Act, which VPN clients, servers and gateways fall within Annex III Class I, and how VPN product classification differs from a VPN interface.

IN BRIEF

The CRA places VPN products in Annex III Class I. The technical description focuses on establishing an encrypted logical tunnel and explicitly includes VPN clients, VPN servers and VPN gateways. VPN interfaces also appear separately as an example within the Class I network-interface category, so product boundaries matter.

01 / 09

VPN Products Are Annex III Class I

Products with digital elements with the function of virtual private network are listed in Annex III Class I. A manufacturer should first confirm the product is within CRA scope and then determine whether establishing a VPN is the supplied product's core functionality. A dedicated VPN client, server or gateway can present a straightforward case. A router, operating system, browser, security suite or remote-access platform that contains VPN capability requires a separate host-product analysis. Article 7 prevents automatic reclassification simply because an important-product function is integrated into a larger product. The classification record should therefore state what is actually supplied and whether VPN operation defines that product.

  • VPN products are Class I.
  • Core functionality determines classification.
  • VPN capability inside another product does not automatically determine host classification.
  • The supplied product boundary should be documented.
02 / 09

The Technical Description Centres on an Encrypted Logical Tunnel

Commission Implementing Regulation (EU) 2025/2392 describes the category as products with digital elements that establish an encrypted logical tunnel constructed from the system resources of a physical or virtual network. The encrypted tunnel is therefore central to the category. A manufacturer should document how the tunnel is established, which network resources participate, what endpoints or networks are connected and whether the product controls creation and operation of that protected logical communication path. The existence of encryption somewhere in a product is not enough. Many products encrypt communications without creating a virtual private network. The classification should focus on the networking function described in the implementing regulation.

  • An encrypted logical tunnel is central.
  • The underlying network can be physical.
  • The underlying network can be virtual.
  • Ordinary encrypted communication is not automatically a VPN product.
03 / 09

VPN Clients Are Expressly Included

VPN clients are expressly identified as an example of products within the category. A VPN client can establish the user or device side of an encrypted logical tunnel to a VPN server or gateway. Client products can take different forms, including dedicated applications, enterprise endpoint software or separately supplied networking components. The fact that a VPN client runs on another operating system does not remove it from the category where it is itself a product with digital elements and VPN functionality is its core functionality. Manufacturers should document supported tunnel functions, authentication relationships, configuration handling, update mechanisms and dependencies because compromise of the client can undermine the confidentiality or integrity expected from the private network connection.

  • VPN clients are an explicit example.
  • Client software can be a product in its own right.
  • Running on another operating system does not prevent Class I classification.
  • Tunnel configuration and authentication should be part of the security analysis.
04 / 09

VPN Servers and Gateways Are Also Included

The implementing regulation also expressly includes VPN servers and VPN gateways. These products can terminate, establish, broker or control encrypted tunnels for remote users, sites or networks. A VPN gateway can be delivered as a dedicated appliance, software product or virtual product, depending on the architecture. The manufacturer should identify whether VPN gateway functionality constitutes the core purpose of the supplied product or is integrated into a broader network appliance. This distinction can become important where the same hardware also performs routing, firewalling or other security functions. The CRA classification should follow the product's core functionality rather than whichever individual security feature appears most prominent in one deployment.

05 / 09

A VPN Product Is Different From a VPN Interface

Commission Implementing Regulation (EU) 2025/2392 creates an important distinction between the VPN product category and the network-interface category. Annex III Class I category 10 covers physical and virtual network interfaces, and the examples of virtual interfaces include VPN interfaces. A VPN interface can expose or emulate a network-interface API and connect a device directly or indirectly to a network, while the VPN product category focuses on establishing the encrypted logical tunnel itself. A complete VPN application can contain a VPN interface as one component. Manufacturers should avoid treating the presence of a virtual VPN interface as proof that the whole product belongs only to category 10. The product's overall core functionality needs to be assessed.

  • VPN products are category 5.
  • VPN interfaces can fall within category 10.
  • One VPN product can contain a virtual network interface.
  • Classify the complete supplied product by core functionality.
06 / 09

VPN Functionality Integrated Into a Router Needs Product-Level Analysis

Many routers include VPN server, client or gateway functionality. That does not automatically make the router a category 5 VPN product. Article 7 requires the core functionality of the supplied product to be considered, and the implementing regulation recognises that products often incorporate functions belonging to other important-product categories. A conventional router principally establishes and controls data flow between different networks using routing mechanisms. If VPN operation is an additional capability, the router can remain within the router category. A dedicated VPN gateway whose principal purpose is establishing protected tunnels can instead fit the VPN category. Manufacturers of multifunction appliances should document the intended purpose, feature architecture and product positioning supporting the conclusion.

  • Routers can include VPN functions.
  • Integrated VPN functionality does not automatically control classification.
  • Dedicated VPN gateways can fit category 5.
  • Document the product's principal networking function.
07 / 09

VPN Security Evidence Should Follow the Tunnel Architecture

A VPN classification record should feed into the wider Annex I cybersecurity risk assessment. The manufacturer should examine tunnel establishment, authentication, key and credential handling, cryptographic configuration, administrative interfaces, update mechanisms, default settings, remote services and failure behaviour. The CRA category does not prescribe a single VPN protocol or cryptographic architecture, but the product still has to meet the applicable essential cybersecurity requirements. The technical documentation should connect the chosen security controls to the actual VPN implementation and the identified risks rather than treat Class I status as a substitute for the underlying product-security analysis.

  • Document tunnel establishment.
  • Document authentication and credential handling.
  • Assess cryptographic configuration and defaults.
  • Connect security controls to the Annex I risk assessment.
08 / 09

Class I Conformity Rules Apply to Qualifying VPN Products

A VPN product that falls within Annex III category 5 is a Class I important product. Article 32(2) therefore governs the conformity route. Internal control can remain available where the applicable conditions involving harmonised standards, common specifications or an applicable European cybersecurity certification scheme are satisfied. Where those conditions are not met, the product and the manufacturer's processes move to a stricter conformity procedure. The manufacturer should therefore resolve the VPN classification early enough to identify standards coverage and determine whether notified-body involvement may be required. Product-security evidence, testing and technical documentation can then be prepared around the actual conformity route.

  • VPN products in category 5 are Class I.
  • Internal control is conditional.
  • Standards coverage can affect the route.
  • Notified-body involvement may become necessary.
09 / 09

Maintain a VPN-Specific Classification Record

The classification record should identify the product and version, whether it is a VPN client, server, gateway or multifunction product, the encrypted logical tunnel it establishes and the physical or virtual network resources from which that tunnel is constructed. It should distinguish VPN interfaces from the wider VPN product and identify other integrated networking functions such as routing or firewalling. Once Class I status is established, the record should state the selected Article 32 route and link to the cybersecurity risk assessment and technical documentation. Significant changes to tunnel architecture, delivery model or the relationship between VPN and other network functions should trigger classification review.

  • Record whether the product is a client, server or gateway.
  • Record the encrypted-tunnel architecture.
  • Distinguish VPN products from VPN interfaces.
  • Document routing or firewall integration where relevant.
  • Record the Article 32 route.
  • Review after major architecture changes.
REFERENCE DESK

Official sources

Read the full legal text and Commission material for precise wording, qualifications and updates.

Editorial review: 26 September 2026. Regulatory material can change; follow the official sources for current guidance.