CRA File / guide, updated 2026-10-05
CRA important and critical products: the full Annex III and IV list
The Cyber Resilience Act (Regulation (EU) 2024/2847) sorts products with digital elements into three tiers. Most products are in the default category. A short list of products with a higher cybersecurity risk is important (Annex III, split into Class I and Class II), and an even shorter list is critical (Annex IV). The tier decides how you prove conformity (Article 32): the higher the tier, the less you can rely on a self-assessment.
Use the product classifier to answer five questions and get the likely tier with article references.
How the tier follows from the product
As a general reading of Article 7(2) and the Commission's descriptions, classification follows the core functionality of the product: a product belongs in a category if that is what it is built to do, and integrating an important component into a larger product does not by itself make the larger product important. The Commission has also published technical descriptions of each category, which are the reference when a product sits on the border; check them for your product.
Annex III, Class I (important products)
- Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
- Standalone and embedded browsers
- Password managers
- Software that searches for, removes, or quarantines malicious software
- Products with digital elements with the function of virtual private network (VPN)
- Network management systems
- Security information and event management (SIEM) systems
- Boot managers
- Public key infrastructure and digital certificate issuance software
- Physical and virtual network interfaces
- Operating systems
- Routers, modems intended for the connection to the internet, and switches
- Microprocessors with security-related functionalities
- Microcontrollers with security-related functionalities
- Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
- Smart home general purpose virtual assistants
- Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
- Internet connected toys covered by Directive 2009/48/EC that have social interactive features (for example speaking or filming) or location tracking features
- Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or 2017/746 do not apply, or personal wearable products that are intended for the use by and for children
Some entries carry scope limits, for example toys covered by Directive 2009/48/EC and wearables to which the medical-device regulations do not apply. The list above is close to the Regulation's wording but shortened in places; check the Regulation and the Commission's technical descriptions for borderline products.
Annex III, Class II (important products)
- Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
- Firewalls, intrusion detection and prevention systems
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Annex IV (critical products)
- Hardware devices with security boxes
- Smart meter gateways within smart metering systems as defined in Article 2, point (23), of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing
- Smartcards or similar devices, including secure elements
What the tier means for conformity assessment (Article 32)
| Tier | Route in short | |---|---| | Default | Internal control (Module A) is available, or any other module. | | Important, Class I | Internal control (Module A) only if harmonised standards, common specifications or a European cybersecurity certification scheme (at least at assurance level substantial) have been applied in full to all requirements; otherwise a third-party assessment (Module B+C) or full quality assurance (Module H). | | Important, Class II | A third-party assessment (Module B+C) or full quality assurance (Module H), or a European cybersecurity certification scheme at least at assurance level substantial (Article 32(3)). | | Critical | A European cybersecurity certification scheme where the Commission has required one by delegated act; otherwise Module B+C or Module H. |
Check the current status of harmonised standards: when none has been cited in the Official Journal for the requirements, a third-party assessment is the practical route for Class I. For free and open-source software the Regulation has a special rule on the procedures when the technical documentation is made public; check Article 32 if that applies to you.
Dates
The reporting duties of Article 14 apply from 11 September 2026, including for products already on the market. The remaining obligations, including conformity assessment, the technical file, the EU declaration of conformity and CE marking, apply from 11 December 2027 (Articles 69 and 71).
Next steps
- Classify your product
- Check your SBOM and create licence notices
- Generate security.txt and a disclosure policy
This page is general information, not legal advice; check the Regulation for your product.
Free tools
- Product classifier: Is your product in scope, and in which category?
- SBOM checker: Check a CycloneDX or SPDX file in your browser.
- security.txt and disclosure policy: The contact file and policy the Regulation expects.
- Repository check: what a GitHub repository already shows.
Information generated from your inputs, with article references to Regulation (EU) 2024/2847. It is not legal advice and does not replace your own assessment; check the references against the Official Journal.