CRA product classes: default, Important I and II, critical
Your product class decides whether you can self-assess or need a notified body. The annexes split on function, not sector — and two of the splits catch people out.
Once you know the Cyber Resilience Act applies to your product, the next question decides most of your budget: which class is it in?
The class does not change the essential cybersecurity requirements. Every product with digital elements has to meet those. What the class changes is who gets to say you met them — you, on your own, or a notified body you pay and wait for.
That is the difference between a conformity assessment you can run internally and one that needs a third party booked months in advance.
The four classes
The Regulation names two lists and leaves everything else in a residual category.
| Class | Where it is defined | Roughly |
|---|---|---|
| Default | Not named in either annex | Most products |
| Important, Class I | Annex III, Class I | Security-adjacent software and devices |
| Important, Class II | Annex III, Class II | Products others depend on for isolation or defence |
| Critical | Annex IV | A short list of high-assurance hardware |
Most products sit in the default category. That is not a loophole — it is the design. The annexes exist to name the products whose compromise reaches beyond their own users.
What decides your class
Function, not sector. The annexes do not ask what industry you sell into. They ask what the product does. A logistics company and a hospital shipping the same identity and access management product are in the same class, and a hospital shipping a scheduling tool is in the default category alongside every other line-of-business application.
This catches people who expect regulation to follow their market. It does not. It follows the security role the product plays for whoever runs it.
Annex III, Class I — the security-adjacent list
Identity and privileged access management, including authentication and access control readers and biometric readers (points 1). Browsers and password managers (points 2–3). Software that searches for, removes or quarantines malicious software (point 4). VPNs, network management systems and SIEM (points 5–7). Boot managers, public key infrastructure and certificate issuance software (points 8–9). Network interfaces, routers, modems and switches, physical and virtual (points 10 and 12). Operating systems (point 11). Microprocessors, microcontrollers, ASICs and FPGAs with security-related functionality (points 13–15). Smart home assistants and smart home products with a security function — door locks, cameras, baby monitors, alarm systems (points 16–17). Connected toys with social interactive or location-tracking features, and wearables that monitor health or are made for children (points 18–19).
Annex III, Class II — the heavier list
Three entries, and they are short because they are consequential.
Hypervisors and container runtimes that support virtualised execution of operating systems and similar environments (point 1). Firewalls, intrusion detection and prevention systems (point 2). Tamper-resistant microprocessors and microcontrollers (points 3–4).
Annex IV — critical
Hardware devices with security boxes (point 1). Smart meter gateways and other devices for advanced security purposes, including secure cryptoprocessing (point 2). Smartcards, secure elements and similar devices (point 3).
Two splits people get wrong
These are the ones worth reading twice, because both put neighbouring products in different classes with very different costs.
Chips: security-related versus tamper-resistant. A microprocessor or microcontroller with security-related functionality is Class I. A tamper-resistant one is Class II. The words are close and the consequence is not: Class I leaves a self-assessment route open under conditions, Class II removes it entirely.
Virtualisation: the OS versus what runs it. An operating system is Class I. A hypervisor or container runtime — something that supports virtualised execution of operating systems — is Class II. If you ship both, you are in the heavier class for the part that virtualises.
What the class actually costs you
This is Article 32, and it is where the class turns into calendar time and invoices. The module letters are Annex VIII’s: module A is internal control, module B+C is EU-type examination followed by conformity to type, module H is full quality assurance.
Default category — Article 32(1)
You choose the route: internal control on your own (module A), EU-type examination followed by conformity to type, full quality assurance, or a European cybersecurity certification scheme where one applies.
Internal control means no notified body. It does not mean no work — the essential requirements still have to be met and documented, and a market surveillance authority can ask to see that documentation.
Important, Class I — Article 32(2)
You can still self-assess by internal control, but only if you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least “substantial” — in full. Apply them only in part, or where none exists yet, and you must go through EU-type examination or full quality assurance instead.
That condition is doing a lot of work right now, because the harmonised standards are still being written. If you are Class I, plan for the heavier route and treat a usable standard arriving in time as the upside case, not the plan.
Important, Class II — Article 32(3)
Internal control is not an option. You must use EU-type examination followed by conformity to type, full quality assurance, or a European cybersecurity certification scheme at assurance level at least “substantial”.
That means a notified body and a longer lead time. Notified bodies have to be designated and then have capacity, and every Class II manufacturer in the Union is queueing for the same ones. Start scoping it now, not in 2027.
Critical — Article 32(4)
Where the Commission has made a European cybersecurity certification scheme mandatory for your product type, that is the route. Where it has not, you fall back to the Class II procedures. Either way this is a notified-body conversation to start immediately.
If you are an SME, the fees are not the full sticker price
Article 32(6) requires that the specific interests and needs of microenterprises and SMEs, including start-ups, be taken into account when conformity assessment fees are set, and that those fees be reduced proportionately.
It does not change which route applies. A Class II product still needs a notified body whoever makes it. But the cost of that route is not meant to be the same for a twelve-person company as for a multinational, and it is worth saying so when you ask for a quote.
What to do with this
- Find your product in the annexes by function. If two entries look close — the chip split, the virtualisation split — read both and pick the heavier one until you can rule it out.
- If you land in Class II or critical, start the notified-body conversation now. Lead time, not the assessment itself, is what makes this a 2026 problem rather than a 2027 one.
- If you land in Class I, plan for the heavier route. The self-assessment door is open only if a harmonised standard exists and you apply it in full.
- If you land in the default category, do not relax. You still have to meet and document the essential requirements — and you still have the Article 14 reporting duty from 11 September 2026, fifteen months before any of this conformity work is due.
The full Regulation applies on 11 December 2027. Conformity assessment is the part with a queue in front of it.
If you are not sure which class you are in
The free CRA readiness scan asks the classification question directly, using the same annex points quoted above, and tells you which conformity routes Article 32 leaves open for your answer. It takes about two minutes and needs no account.