CRA: important and critical products, which conformity assessment?

Default, important class I or II, critical: a product's category under the Cyber Resilience Act decides who assesses its conformity. Annexes III and IV, modules A, B, C and H, notified bodies and the state of play as of 6 October 2026.

· 13 min read
Illustration: three glass boxes of increasing size, the largest in orange

Under the Cyber Resilience Act (CRA), important and critical products are digital products whose core function relates to security or could cause widespread harm: they are listed in Annexes III and IV of the regulation and, depending on their category, must go through a stricter conformity assessment, up to the mandatory involvement of a notified body or a European certificate. All other products fall into the default category and can be self-assessed by their manufacturer. This article, which extends our Cyber Resilience Act guide, explains the categories, the procedures and what you can require from your suppliers.

01

CRA: four product categories, four levels of scrutiny

Regulation (EU) 2024/2847 applies the same essential cybersecurity requirements (Annex I) to every product with digital elements. What changes from one category to the next is how you prove compliance, meaning the conformity assessment procedure set by Article 32. The regulation has four levels:

  • Default products, not listed in any annex: the vast majority, such as mobile apps, video games, smart speakers or memory chips (examples given by the European Commission).
  • Important products, class I (Annex III): 19 categories, from password managers to routers.
  • Important products, class II (Annex III): 4 more sensitive categories, such as firewalls and hypervisors.
  • Critical products (Annex IV): 3 categories, including smartcards.

Article 7 sets the criteria for a category to be listed in Annex III. Meeting one is enough: either the product primarily protects other products, networks or services (authentication, access control, intrusion detection, endpoint or network security), or it performs a function carrying a significant risk of adverse effects because it can disrupt, control or damage many other products, or harm users' health and safety (network management, virtualisation, processing of personal data, for example). For critical products, Article 8 adds the dependency of essential entities under the NIS 2 directive and the risk of disrupting critical supply chains.

02

Important products, class I (CRA Annex III)

Class I covers 19 categories, each technically described by Implementing Regulation (EU) 2025/2392 of 28 November 2025. They fall into four groups:

  • Security products: identity management systems and privileged access management software and hardware (including authentication, access control and biometric readers), password managers, software that searches for, removes or quarantines malware, products with a virtual private network (VPN) function, security information and event management (SIEM) systems, public key infrastructure and digital certificate issuance software.
  • System and network building blocks: standalone and embedded browsers, network management systems, boot managers, physical and virtual network interfaces, operating systems, routers, modems for internet connection and switches.
  • Hardware components: microprocessors, microcontrollers, ASICs and FPGAs with security-related functionalities.
  • Consumer connected devices: smart home general-purpose virtual assistants, smart home products with security functions (door locks, security cameras, baby monitors, alarms), connected toys that talk, film or locate, and health-monitoring wearables not covered by the medical device regulations, or wearables intended for children.

For an organisation, this list has a very concrete consequence: much of your security tooling is class I. Your password manager, VPN, authentication solution, SIEM, antivirus and routers will need to have been assessed under the rules for this class to be placed on the EU market after 11 December 2027.

03

Important products, class II: a third party becomes mandatory

Class II has only four categories, considered riskier:

  • hypervisors and container runtime systems that support virtualised execution of operating systems;
  • firewalls and intrusion detection and prevention systems (IDS and IPS);
  • tamper-resistant microprocessors;
  • tamper-resistant microcontrollers.

What they share: a failure compromises everything that relies on them. A flaw in a hypervisor exposes every virtual machine it hosts; a bypassed firewall opens the whole network behind it. For these products, the manufacturer can never rely on self-assessment alone.

04

The CRA's critical products (Annex IV)

Annex IV covers three categories on which essential entities directly depend:

  • hardware devices with security boxes, such as hardware security modules (HSMs) that protect cryptographic keys;
  • smart meter gateways within smart metering systems, and other devices for advanced security purposes, including secure cryptoprocessing;
  • smartcards or similar devices, including secure elements.

Article 8 allows the Commission to require, through a delegated act, a European cybersecurity certificate at assurance level at least "substantial" for these products, provided a suitable certification scheme exists and after assessing the market impact. Such a scheme already exists for some of them: EUCC, the European scheme based on the Common Criteria, adopted by Implementing Regulation (EU) 2024/482. As long as no delegated act requires certification, critical products follow the same procedures as class II.

05

CRA conformity assessment: modules A, B, C, H and certification

Annex VIII of the CRA reuses the classic "modules" of EU product legislation, already used for CE marking of machinery or radio equipment. Each splits the work differently between the manufacturer and a notified body, a conformity assessment body authorised by a Member State and notified to the Commission.

Module A: internal control

The manufacturer alone assesses the conformity of the product and of its vulnerability handling processes, compiles the technical documentation, draws up the EU declaration of conformity and affixes the CE marking. No third party is involved. This route is open to all default products.

Modules B and C: EU-type examination

A notified body examines the product's technical design and the manufacturer's vulnerability handling processes (module B). If they meet the requirements, it issues an EU-type examination certificate. The manufacturer then ensures each unit produced conforms to that type (module C).

Module H: full quality assurance

The manufacturer has its quality system, covering design, development, production and vulnerability handling, approved by a notified body, which then monitors it over time. In this case the CE marking is followed by the notified body's identification number (Article 30).

European cybersecurity certification

A product certified under a scheme adopted pursuant to Regulation (EU) 2019/881 (the Cybersecurity Act) may benefit from a presumption of conformity, under conditions the Commission sets by delegated act (Article 27). The Commission's published timeline plans such an act for EUCC in the fourth quarter of 2026.

Which procedure for which category?

Article 32 combines these tools by category. The staircase below sums it up: the higher you go, the more unavoidable a third party becomes.

Four-step staircase diagram. Default (apps, games, speakers): self-assessment by the manufacturer, module A. Important class I (browsers, VPNs, SIEM, routers, operating systems): module A if harmonised standards are applied, otherwise modules B and C or H with a notified body. Important class II (firewalls, IDS and IPS, hypervisors): third party required, modules B and C, H or certification at substantial level. Critical (smartcards, hardware security boxes, smart meter gateways): European certification if a delegated act requires it, otherwise as class II.
The product's category sets the conformity assessment procedure (CRA Article 32). Video labels in French.
CRA categories and conformity assessment procedures (Article 32)
CategoryExamplesPossible proceduresThird party required?
DefaultApps, games, smart speakersModule A, or B and C, or H, or European certificationNo
Important, class I (Annex III)Password managers, VPNs, SIEM, operating systems, routersModule A if harmonised standards, common specifications or certification at level at least "substantial" are fully applied; otherwise B and C, or HOnly without standards or certification
Important, class II (Annex III)Firewalls, IDS and IPS, hypervisors, tamper-resistant microcontrollersB and C, or H, or certification at level at least "substantial"Yes
Critical (Annex IV)HSMs, smart meter gateways, smartcardsEuropean certification if a delegated act requires it; otherwise as class IIYes

Two adjustments complete the picture. Free and open-source software in Annex III categories may use the procedures open to default products, including self-assessment, if its technical documentation is made public (Article 32(5)). And notified bodies' fees must be reduced for microenterprises and SMEs, in proportion to their needs (Article 32(6)).

06

How a manufacturer determines its product's category

Classification is done product by product, with four questions:

  1. Is the product within the CRA's scope? The regulation notably excludes medical and in vitro diagnostic devices (Regulations 2017/745 and 2017/746), type-approved vehicles, marine equipment, civil aviation, and products developed exclusively for national security or defence. A purely online service is covered only if it is a "remote data processing solution" needed for a product to work. Our CRA guide covers the scope in detail.
  2. What is its core functionality? Only the product's central function counts: Article 7 states that integrating an important product into another does not make the latter important. A TV with an embedded browser does not become a browser; a firewall sold as such is class II.
  3. Does it match a technical description? Implementing Regulation 2025/2392, in force since 21 December 2025, describes each category in Annexes III and IV. It is the reference for borderline cases.
  4. Which standards will I be able to apply? For a class I product, the existence of a harmonised standard covering all requirements decides between self-assessment and a notified body. Given the timeline (see next section), plan for both scenarios.

The Commission's guidelines of 27 July 2026 also point out that a substantial modification of a product already on the market, meaning one that changes its risk profile, requires a new conformity assessment, whereas a security update generally does not. The category should therefore be reviewed whenever the product's function changes.

07

Important and critical products: state of play on 6 October 2026

Manufacturers' obligations apply in full on 11 December 2027. The rules on notified bodies have applied since 11 June 2026, and the duty to report actively exploited vulnerabilities since 11 September 2026 (see our article on vulnerability reporting). Here is what is settled and what is still in progress.

What is settled

  • Technical descriptions of the categories: Implementing Regulation 2025/2392, adopted on 28 November 2025 and published in the Official Journal on 1 December 2025, fulfils Article 7(4), which set a deadline of 11 December 2025.
  • The Commission's first guidelines: non-binding communication C(2026) 5252 of 27 July 2026 covers scope, remote data processing solutions, open source, substantial modification, support period and reporting. It does not provide a list of classification cases.
  • The standardisation request: CEN, CENELEC and ETSI accepted the Commission's request M/606 on 3 April 2025, covering horizontal standards (for all products) and vertical ones (one per important or critical product category).

What is still in progress

  • Harmonised standards: none is yet cited in the EU Official Journal for the CRA. In early July 2026 the Commission published a draft amendment to the standardisation request that would push the 2026 deadlines back by two months (to 31 October for the first horizontal standards, 31 December for product-specific ones); according to a status update of 6 October 2026, it had still not been published in the Official Journal, and the first parts of the EN 40000 series (vocabulary and principles) passed formal approval at CEN-CENELEC, and ETSI published seventeen draft product standards in August 2026, still under public enquiry.
  • Notified bodies: at the end of July 2026, the Commission's conformity assessment page still announced the NANDO list of CRA notified bodies “once available”. The Commission's timeline aims for enough bodies by 11 December 2026, and ENISA has published technical competence requirements for them.
  • Certification: the delegated act granting presumption of conformity through EUCC is announced for Q4 2026. To our knowledge, no delegated act making certification mandatory for critical products had been adopted.
  • French authorities: ANSSI states that the national frequency agency (ANFR) will handle market surveillance and that ANSSI will be the notifying authority for conformity assessment bodies, accredited by COFRAC. Their designation goes through the EU law adaptation bill (DDADUE), adopted by the Senate on 18 February 2026 and still before the National Assembly according to the legislative file consulted on 6 October 2026.
  • The "Digital Omnibus" package: presented by the Commission on 19 November 2025, it proposes a single entry point for incident reporting, built on the CRA reporting platform. As proposed, it changes neither the product categories nor the conformity assessment procedures.

In practice: a class I manufacturer cannot yet know whether a harmonised standard enabling self-assessment will be available in time. The safest course is to prepare the technical documentation now as if a notified body were going to review it, and to book a slot with a body early, since demand is likely to peak in 2027.

08

What buyers can ask their suppliers for

The CRA targets manufacturers, but its effects are felt by their customers. For an organisation buying digital products, and especially for NIS 2 entities that must manage the security of their supply chain, the CRA category becomes a supplier assessment criterion.

The EU declaration of conformity

From 11 December 2027, every product placed on the EU market must come with an EU declaration of conformity (Article 28 and Annex V), or a simplified version giving the address where it can be read. It states, among other things, the product identification, the manufacturer, the harmonised standards, common specifications or certifications applied and, where relevant, the notified body's name and number, the procedure followed and the certificate issued. For a class II product, a declaration without a notified body or certificate should raise a flag.

Questions to ask now

  • Which category does the supplier claim for its product, based on what analysis of core functionality?
  • Which procedure does it plan, with which notified body and on what timeline?
  • What support period does it commit to for security updates?
  • How does it handle and report vulnerabilities, and does it have a coordinated disclosure policy?
  • Can it provide the product's software bill of materials (SBOM), or at least commit to informing you when a component is affected?

These questions belong in your vendor security questionnaire, in the clauses of your security assurance plan and, more broadly, in your third-party risk management. Medical devices, excluded from the CRA, remain governed by their own regulations, so healthcare organisations will need to keep the two frameworks apart in procurement.

To centralise these answers and monitor suppliers over time, see our vendor risk management module.

Summary

01

The category decides the third party

Default products are self-assessed. Class I products can be self-assessed only with harmonised standards or certification. Class II and critical products need a notified body or a European certificate.

02

Core functionality is what counts

A product is important or critical if its core functionality matches a category in Annex III or IV, described in detail by Implementing Regulation 2025/2392. Integrating an important component is not enough.

03

Pieces still missing

As of 6 October 2026, no harmonised standard is cited in the Official Journal and notified bodies are only starting to be designated. Manufacturers of class I or II products need to plan ahead.

Frequently asked questions

What is an important product under the CRA?

It is a product with digital elements whose core functionality matches one of the categories in Annex III of Regulation (EU) 2024/2847: identity management, browsers, password managers, VPNs, SIEM, operating systems, routers, firewalls, hypervisors and so on. The annex splits them into class I (19 categories) and class II (4 categories), the latter requiring third-party assessment.

What is the difference between class I and class II?

A class I product can be self-assessed by its manufacturer (module A) if it fully applies harmonised standards, common specifications or a European certification scheme at assurance level at least 'substantial'. Otherwise it goes through a notified body. A class II product always needs a notified body (modules B and C, or H) or a European certificate at level at least 'substantial'.

What are the CRA's critical products?

Annex IV lists three categories: hardware devices with security boxes (such as hardware security modules, HSMs), smart meter gateways and other devices for advanced security purposes, and smartcards or similar devices including secure elements. The Commission may require European certification for them through a delegated act; failing that, they follow the class II procedures.

What are modules A, B, C and H?

They are the conformity assessment procedures described in Annex VIII of the CRA. Module A is internal control by the manufacturer. Module B is EU-type examination by a notified body, followed by module C (conformity to type in production). Module H is full quality assurance: the notified body approves and monitors the manufacturer's quality system.

Have CRA notified bodies been designated yet?

The rules on notified bodies have applied since 11 June 2026. At the end of July 2026, the Commission still said that the list of CRA notified bodies in its NANDO database would be published “once available”. The Commission's timeline aims for a sufficient number of notified bodies by 11 December 2026.

What should I ask a supplier to check a product's CRA conformity?

From 11 December 2027, the EU declaration of conformity, which states the standards applied and, where relevant, the notified body, the procedure followed and the certificate. Also ask for the category claimed and its rationale, the support period, the vulnerability reporting arrangements and the SBOM if the supplier agrees to share it.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.