CRA classification is based on the product's core functionality, not simply on whether it contains a security feature. Annex III contains important products in Class I and Class II, while Annex IV contains critical products. The classification affects which Article 32 conformity assessment route the manufacturer can use.
The CRA Uses a Separate Classification Layer for Higher-Risk Products
The Cyber Resilience Act applies essential cybersecurity requirements across covered products with digital elements, but it does not treat every product identically at the conformity stage. Articles 7 and 8 create a separate classification layer for products whose cybersecurity function or potential impact justifies stricter assurance. Annex III lists important products and divides them into Class I and Class II. Annex IV lists critical products. The classification does not replace the normal CRA scope analysis. A team first needs to determine that the product is within the Regulation and identify the manufacturer and product boundary. It then asks whether the product's core functionality matches one of the listed important or critical categories. That answer can materially change conformity planning, evidence expectations and the need for third-party involvement.
- Start with CRA scope before classification.
- Use Annex III for important products.
- Use Annex IV for critical products.
- Connect the classification result to Article 32.
Core Functionality Is the Central Classification Test
The key legal concept is core functionality. Article 7 states that a product with digital elements is important when it has the core functionality of a category in Annex III. Article 8 uses the same core-functionality approach for Annex IV critical categories. This prevents classification from being triggered merely because a product contains a security-related component or feature somewhere inside a larger product. The CRA explains that integrating a product with the core functionality of an Annex III category does not by itself make the larger integrating product subject to the stricter important-product conformity procedures. Manufacturers therefore need to identify what the product is principally designed and supplied to do, then compare that function with the applicable technical description rather than classify by a broad marketing label.
- Identify the product boundary.
- Document the product's principal functions.
- Compare those functions with the legal category description.
- Do not classify a larger product solely because it integrates a listed component.
Annex III Divides Important Products Into Class I and Class II
Annex III contains the important-product categories and separates them into two classes. Class I is broad and includes categories such as identity management systems, browsers, password managers, antimalware software, VPN products, network management systems, SIEM systems, boot managers, public key infrastructure software, network interfaces, operating systems, routers and specified security-related chips, as well as certain smart-home, toy and wearable products. Class II is narrower and includes hypervisors and container runtime systems, firewalls and intrusion detection or prevention systems, tamper-resistant microprocessors and tamper-resistant microcontrollers. The class is not a general maturity rating. It is a legal classification that changes the conformity assessment route available under Article 32.
Annex IV Contains the Critical Product Categories
Critical products form a separate category under Article 8 and Annex IV. Annex IV includes hardware devices with security boxes, smart meter gateways within smart metering systems and other devices for advanced security purposes including secure cryptoprocessing, and smartcards or similar devices including secure elements. These categories are deliberately narrow. Their technical descriptions are set out in Commission Implementing Regulation (EU) 2025/2392. Article 8 also creates a mechanism through which the Commission can require specified critical products to obtain a European cybersecurity certificate under an available European cybersecurity certification scheme. Where the certification conditions in Article 8 are not met, Article 32 subjects critical products to the stricter conformity routes that apply to Class II important products.
- Critical products are listed in Annex IV.
- The list is separate from Annex III Class II.
- Technical descriptions are supplied by Implementing Regulation (EU) 2025/2392.
- Critical classification leads to a stricter conformity route.
Commission Implementing Regulation 2025/2392 Defines the Categories in More Detail
The labels in Annexes III and IV are the starting point rather than the entire classification analysis. Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the important and critical product categories. Those descriptions help manufacturers decide whether the product's core functionality actually matches a listed category. The implementing regulation also provides illustrative examples for certain categories, but those examples are not exhaustive. Classification should therefore not be reduced to a product-name search. A product may fall within a category even if its commercial label differs from the examples, while another product carrying similar marketing terminology may fall outside because its core functionality does not meet the technical description.
- Read the CRA category in Annex III or Annex IV.
- Read the corresponding 2025/2392 technical description.
- Compare the description with actual product functionality.
- Document the reasoning used for the classification.
Class I Can Retain Internal Control Only Under Specified Conditions
Class I important products occupy an intermediate position. Article 32 allows the manufacturer to use the normal internal-control route only where the specified conformity conditions are satisfied, including the relevant use of harmonised standards, common specifications or an applicable European cybersecurity certification scheme. If those conditions are not met, or if the relevant standards, specifications or schemes do not exist, the product and the manufacturer's processes must go through one of the stricter procedures described in Article 32, such as EU-type examination followed by conformity to type or a full quality assurance procedure. Classification therefore needs to happen before the manufacturer locks its assessment plan. A late Class I finding can change both evidence strategy and external-assessment scheduling.
- Class I does not always mean mandatory third-party assessment.
- Internal control depends on the Article 32 conditions.
- Standards and certification availability can affect the route.
- Plan the conformity route early in development.
Class II and Critical Products Face Stricter Assessment
For Class II important products, Article 32 requires a stricter route: EU-type examination followed by conformity to type, full quality assurance, or an applicable European cybersecurity certification scheme at the required assurance level where that route is available. Critical products use an Article 8 certification route when the relevant conditions and delegated act apply, and otherwise use the Class II procedures identified by Article 32. In practical terms, the manufacturer should expect third-party participation unless an available and legally applicable certification route replaces it. This is why a product should not be moved casually between the default, Class I, Class II and critical categories. The classification directly affects cost, lead time, evidence review and release planning.
- Class II removes the ordinary Class I conditional internal-control option.
- Critical products are subject to the strictest CRA classification framework.
- Notified-body capacity and certification availability can become planning dependencies.
- Classification should be reviewed before market placement and after material product changes.
A Practical CRA Classification Record Should Be Product Specific
A defensible classification record should identify the exact product and version, the product boundary, principal and security-related functions, the candidate Annex III or Annex IV categories, the applicable 2025/2392 technical descriptions and the conclusion reached for each candidate. The record should also explain why an integrated listed component does or does not determine the classification of the larger product. Once the category is resolved, the manufacturer can map the result to Article 32, identify relevant standards or certification schemes and plan the technical evidence needed for conformity assessment. For portfolios with many related products, classification should be maintained as structured product data rather than a one-time legal memo because changes to functionality, architecture or the Annex lists can alter the analysis.
- Record the product and version.
- Record the core-functionality analysis.
- Record candidate Annex III and Annex IV categories.
- Record the matching 2025/2392 technical description.
- Record the resulting Article 32 conformity route.
- Set a review trigger for material product or legal changes.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.