CRA product categories explained
CRA conformity assessment: which products are important or critical under Annex III/IV, and when self-assessment suffices or a notified body is needed.
Hendrik-Hauke Rux6 min readDeutsche Fassung
The Cyber Resilience Act distinguishes default products, important products (Annex III, class I and II) and critical products (Annex IV). The category determines the conformity assessment procedure: default products may be self-assessed, class II requires a notified body, and class I sits in between – depending on whether harmonised standards are applied.
Rules on conformity assessment bodies have applied since 11 June 2026, so notified bodies can now be notified – if you need assessment capacity before the end of 2027, start early. Our CRA overview covers the basics.
Default products
Most products with digital elements are on neither list. Internal control (module A) suffices: the manufacturer self-assesses, prepares technical documentation, issues the EU declaration of conformity and affixes the CE mark. Self-assessment does not mean fewer requirements – Annex I applies in full.
Important products: class I and II
Annex III lists products whose core functionality is security-relevant. The core functionality is decisive: integrating an Annex III component does not in itself make a product important.
| Class | Examples (excerpt) |
|---|---|
| Class I | Identity and access management, browsers, password managers, anti-malware, VPNs, network management, SIEM, boot managers, PKI software, operating systems, routers and modems, microcontrollers and microprocessors with security functions, smart home security products, connected wearables and toys |
| Class II | Hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors and microcontrollers |
Critical products
Annex IV lists hardware devices with security boxes, smart meter gateways and other devices for advanced security purposes including secure cryptoprocessors, as well as smartcards and similar devices. The Commission may require European cybersecurity certification for them; until it does, the class II procedures apply.
The procedures: modules A, B+C and H
Category → conformity assessment (Art. 32 CRA)
- Default product
- Module A (self-assessment)
- Important, class I
- Module A only with harmonised standards, else B+C or H
- Important, class II
- B+C, H or EU certification
- Critical (Annex IV)
- EU certification if required, else as class II
- Module A – internal control: self-assessment by the manufacturer.
- Module B + C – EU-type examination plus conformity to type: a notified body examines the type; the manufacturer ensures production conforms.
- Module H – full quality assurance: a notified body assesses and monitors your quality system for design, production and vulnerability handling.
The role of harmonised standards
For class I products, self-assessment is only allowed if the manufacturer fully applies harmonised standards, common specifications or European cybersecurity certification. CRA standards are in development (standardisation request M/606) and not yet published in the Official Journal. For class I products, plan both routes: track the standards and check in parallel whether you need a notified body.
Machinery: controllers, gateways, firmware
- Machine controller with remote maintenance: usually a default product – unless its core functionality is one of the listed security functions.
- Industrial gateway or router: routers are class I; a gateway whose core function is a firewall can be class II.
- Purchased components: microcontrollers with security functions are class I – that concerns the component maker. As integrator you must select and document the component with due diligence.
- Firmware updates: whatever the category, you need a secure update mechanism.
The Commission is mandated to specify the technical descriptions of the categories in an implementing act. Check borderline cases against the current text and document your classification – it is part of the technical documentation.
Classification in five steps
- Describe the core functionality: what is the product's main purpose from the user's view? One sentence is enough.
- Match against Annex III and IV: does the core functionality correspond to a listed category?
- Check borderline cases: compare with the Commission's technical descriptions once available.
- Derive the procedure: module A, B+C, H or certification – and check whether standards allow self-assessment.
- Document the decision: include reasoning, sources and date in the technical documentation.
Examples from machinery and IoT
| Product | Likely category | Reasoning |
|---|---|---|
| Machine tool control software | Default | Core function is machine control, not a listed security function |
| Cellular router for remote plant access | Important, class I | Routers are listed in Annex III |
| Industrial firewall for network segmentation | Important, class II | Firewalls are listed in class II |
| Smart meter gateway | Critical | Listed in Annex IV |
The table shows typical tendencies but does not replace a case-by-case check. The concrete core functionality always decides, not the catalogue name.
What a notified body means for your plan
If you need a notified body, the path to CE marking gets longer: you have to find a body notified for the CRA, submit documents and answer questions. Since all manufacturers of class II products face the same bottleneck before December 2027, early contact makes sense. Keep your technical documentation structured so an external review is possible without lengthy preparation.
Common classification mistakes
- Marketing terms instead of core functionality: a 'secure gateway' is not automatically a firewall.
- Confusing components with the end product: an integrated class I component does not make the machine class I.
- Undocumented classification: without reasoning the decision is hard to defend in a market surveillance check.
Classification with Nuowei
In Nuowei's onboarding (beta, launch November 2026) you assign each product to a category and get the matching obligations for the CRA checklist. The classification remains your decision – Nuowei helps document it traceably.
Not for default products. Yes for class II. For class I only if you do not fully apply harmonised standards, common specifications or EU certification.
Not automatically. The core functionality of the product itself is decisive.
The rules on conformity assessment bodies have applied since 11 June 2026; bodies can be notified from then on.