ambolt

CRA File / guide, updated 2026-10-05

CRA important and critical products: the full Annex III and IV list

The Cyber Resilience Act (Regulation (EU) 2024/2847) sorts products with digital elements into three tiers. Most products are in the default category. A short list of products with a higher cybersecurity risk is important (Annex III, split into Class I and Class II), and an even shorter list is critical (Annex IV). The tier decides how you prove conformity (Article 32): the higher the tier, the less you can rely on a self-assessment.

Use the product classifier to answer five questions and get the likely tier with article references.

How the tier follows from the product

As a general reading of Article 7(2) and the Commission's descriptions, classification follows the core functionality of the product: a product belongs in a category if that is what it is built to do, and integrating an important component into a larger product does not by itself make the larger product important. The Commission has also published technical descriptions of each category, which are the reference when a product sits on the border; check them for your product.

Annex III, Class I (important products)

  1. Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
  2. Standalone and embedded browsers
  3. Password managers
  4. Software that searches for, removes, or quarantines malicious software
  5. Products with digital elements with the function of virtual private network (VPN)
  6. Network management systems
  7. Security information and event management (SIEM) systems
  8. Boot managers
  9. Public key infrastructure and digital certificate issuance software
  10. Physical and virtual network interfaces
  11. Operating systems
  12. Routers, modems intended for the connection to the internet, and switches
  13. Microprocessors with security-related functionalities
  14. Microcontrollers with security-related functionalities
  15. Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
  16. Smart home general purpose virtual assistants
  17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
  18. Internet connected toys covered by Directive 2009/48/EC that have social interactive features (for example speaking or filming) or location tracking features
  19. Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or 2017/746 do not apply, or personal wearable products that are intended for the use by and for children

Some entries carry scope limits, for example toys covered by Directive 2009/48/EC and wearables to which the medical-device regulations do not apply. The list above is close to the Regulation's wording but shortened in places; check the Regulation and the Commission's technical descriptions for borderline products.

Annex III, Class II (important products)

  1. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
  2. Firewalls, intrusion detection and prevention systems
  3. Tamper-resistant microprocessors
  4. Tamper-resistant microcontrollers

Annex IV (critical products)

  1. Hardware devices with security boxes
  2. Smart meter gateways within smart metering systems as defined in Article 2, point (23), of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing
  3. Smartcards or similar devices, including secure elements

What the tier means for conformity assessment (Article 32)

| Tier | Route in short | |---|---| | Default | Internal control (Module A) is available, or any other module. | | Important, Class I | Internal control (Module A) only if harmonised standards, common specifications or a European cybersecurity certification scheme (at least at assurance level substantial) have been applied in full to all requirements; otherwise a third-party assessment (Module B+C) or full quality assurance (Module H). | | Important, Class II | A third-party assessment (Module B+C) or full quality assurance (Module H), or a European cybersecurity certification scheme at least at assurance level substantial (Article 32(3)). | | Critical | A European cybersecurity certification scheme where the Commission has required one by delegated act; otherwise Module B+C or Module H. |

Check the current status of harmonised standards: when none has been cited in the Official Journal for the requirements, a third-party assessment is the practical route for Class I. For free and open-source software the Regulation has a special rule on the procedures when the technical documentation is made public; check Article 32 if that applies to you.

Dates

The reporting duties of Article 14 apply from 11 September 2026, including for products already on the market. The remaining obligations, including conformity assessment, the technical file, the EU declaration of conformity and CE marking, apply from 11 December 2027 (Articles 69 and 71).

Next steps

This page is general information, not legal advice; check the Regulation for your product.

Free tools

Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.