Skip to content

CRA product categories explained

CRA conformity assessment: which products are important or critical under Annex III/IV, and when self-assessment suffices or a notified body is needed.

Hendrik-Hauke Rux6 min readDeutsche Fassung

The Cyber Resilience Act distinguishes default products, important products (Annex III, class I and II) and critical products (Annex IV). The category determines the conformity assessment procedure: default products may be self-assessed, class II requires a notified body, and class I sits in between – depending on whether harmonised standards are applied.

Rules on conformity assessment bodies have applied since 11 June 2026, so notified bodies can now be notified – if you need assessment capacity before the end of 2027, start early. Our CRA overview covers the basics.

Default products

Most products with digital elements are on neither list. Internal control (module A) suffices: the manufacturer self-assesses, prepares technical documentation, issues the EU declaration of conformity and affixes the CE mark. Self-assessment does not mean fewer requirements – Annex I applies in full.

Important products: class I and II

Annex III lists products whose core functionality is security-relevant. The core functionality is decisive: integrating an Annex III component does not in itself make a product important.

ClassExamples (excerpt)
Class IIdentity and access management, browsers, password managers, anti-malware, VPNs, network management, SIEM, boot managers, PKI software, operating systems, routers and modems, microcontrollers and microprocessors with security functions, smart home security products, connected wearables and toys
Class IIHypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and microcontrollers

Critical products

Annex IV lists hardware devices with security boxes, smart meter gateways and other devices for advanced security purposes including secure cryptoprocessors, as well as smartcards and similar devices. The Commission may require European cybersecurity certification for them; until it does, the class II procedures apply.

The procedures: modules A, B+C and H

Category → conformity assessment (Art. 32 CRA)

Default product
Module A (self-assessment)
Important, class I
Module A only with harmonised standards, else B+C or H
Important, class II
B+C, H or EU certification
Critical (Annex IV)
EU certification if required, else as class II
Source: EUR-Lex, Regulation (EU) 2024/2847, Art. 32
  • Module A – internal control: self-assessment by the manufacturer.
  • Module B + C – EU-type examination plus conformity to type: a notified body examines the type; the manufacturer ensures production conforms.
  • Module H – full quality assurance: a notified body assesses and monitors your quality system for design, production and vulnerability handling.

The role of harmonised standards

For class I products, self-assessment is only allowed if the manufacturer fully applies harmonised standards, common specifications or European cybersecurity certification. CRA standards are in development (standardisation request M/606) and not yet published in the Official Journal. For class I products, plan both routes: track the standards and check in parallel whether you need a notified body.

Machinery: controllers, gateways, firmware

  • Machine controller with remote maintenance: usually a default product – unless its core functionality is one of the listed security functions.
  • Industrial gateway or router: routers are class I; a gateway whose core function is a firewall can be class II.
  • Purchased components: microcontrollers with security functions are class I – that concerns the component maker. As integrator you must select and document the component with due diligence.
  • Firmware updates: whatever the category, you need a secure update mechanism.

The Commission is mandated to specify the technical descriptions of the categories in an implementing act. Check borderline cases against the current text and document your classification – it is part of the technical documentation.

Classification in five steps

  1. Describe the core functionality: what is the product's main purpose from the user's view? One sentence is enough.
  2. Match against Annex III and IV: does the core functionality correspond to a listed category?
  3. Check borderline cases: compare with the Commission's technical descriptions once available.
  4. Derive the procedure: module A, B+C, H or certification – and check whether standards allow self-assessment.
  5. Document the decision: include reasoning, sources and date in the technical documentation.

Examples from machinery and IoT

ProductLikely categoryReasoning
Machine tool control softwareDefaultCore function is machine control, not a listed security function
Cellular router for remote plant accessImportant, class IRouters are listed in Annex III
Industrial firewall for network segmentationImportant, class IIFirewalls are listed in class II
Smart meter gatewayCriticalListed in Annex IV

The table shows typical tendencies but does not replace a case-by-case check. The concrete core functionality always decides, not the catalogue name.

What a notified body means for your plan

If you need a notified body, the path to CE marking gets longer: you have to find a body notified for the CRA, submit documents and answer questions. Since all manufacturers of class II products face the same bottleneck before December 2027, early contact makes sense. Keep your technical documentation structured so an external review is possible without lengthy preparation.

Common classification mistakes

  • Marketing terms instead of core functionality: a 'secure gateway' is not automatically a firewall.
  • Confusing components with the end product: an integrated class I component does not make the machine class I.
  • Undocumented classification: without reasoning the decision is hard to defend in a market surveillance check.

Classification with Nuowei

In Nuowei's onboarding (beta, launch November 2026) you assign each product to a category and get the matching obligations for the CRA checklist. The classification remains your decision – Nuowei helps document it traceably.

Not for default products. Yes for class II. For class I only if you do not fully apply harmonised standards, common specifications or EU certification.

Not automatically. The core functionality of the product itself is decisive.

The rules on conformity assessment bodies have applied since 11 June 2026; bodies can be notified from then on.

Sources

Join the waitlist

We launch in November. Be the first to get access.