Kilde › Guides › CRA › CRA product categories: the 26 Annex I…
Current to 26 August 2026 · updates land in the changelog.
Regulation (EU) 2024/2847 names 19 Class I and 4 Class II categories in Annex III and 3 critical categories in Annex IV, read here verbatim from the Official Journal text. The tier decides the conformity route; it decides nothing about the Article 14 reporting duty, which has applied to every in-scope product since 11 September 2026. Per-product classification is settled against Implementing Regulation (EU) 2025/2392. One section per category.
Yes — identity management and PAM are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 1 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers”
— Annex III, Class I, item 1, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
The item covers the identity stack in both software and hardware form: identity-management platforms, privileged-access-management vaults and session brokers, and — spelled out twice with “including” — the physical layer of authentication and access-control readers, biometric readers among them.
The double “including” is the tell: this is not a software-only category. A door-access biometric terminal sits inside the wording alongside the IAM suite that manages it, so hardware vendors who think of themselves as physical-security companies are in the same item as identity-software vendors.
Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class I, item 1 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).
Short answer: yes, listed. The CRA names browsers at Annex III, Class I, item 2 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Standalone and embedded browsers”
— Annex III, Class I, item 2, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Both distribution modes are named. A browser shipped as its own product is inside the wording, and so is a browser embedded in something else — kiosk shells, in-app browsers, webview-based frames inside larger products.
“Embedded” is the word doing the quiet work: a manufacturer whose product merely contains a browser component is integrating an Annex III item, which pulls the classification question — and the component due-diligence duty in Article 13(5) — into products that never marketed themselves as browsers.
The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class I, item 2 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.
Password Managers sit squarely on the CRA's lists: Annex III, Class I, item 3 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Password managers”
— Annex III, Class I, item 3, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
Two words, no qualifiers. Consumer vault apps and enterprise credential managers sit in the same item: the listing draws no line by deployment model, user type or price.
Because the item is unqualified, the interesting boundary questions are at the edges of the product itself — browser extensions, secret-sharing features and sync services ship as part of the product with digital elements, and a cloud back-end the product functionally depends on counts as its remote data processing under Article 3(2).
For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex III, Class I, item 3, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.
Yes — anti-malware software are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 4 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Software that searches for, removes, or quarantines malicious software”
— Annex III, Class I, item 4, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The definition is functional, not nominal: search, remove, or quarantine. Any one of the three functions places a product inside the wording — classic antivirus, removal tooling and quarantine engines all qualify without the product ever calling itself “antivirus”.
The functional wording reaches scan engines licensed as components just as it reaches boxed endpoint suites — and note that network-level intrusion detection and prevention systems are listed separately, one class up (Annex III Class II, item 2).
Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class I, item 4 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).
Short answer: yes, listed. The CRA names VPN products at Annex III, Class I, item 5 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Products with digital elements with the function of virtual private network (VPN)”
— Annex III, Class I, item 5, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
The listing keys to the function, not the product name: anything shipping VPN functionality — a consumer VPN client, a site-to-site gateway, a router or firewall with a VPN server — carries this item for that function.
“Products … with the function of” is broader than “VPN products”: a multi-function product that includes VPN capability has an Annex III function on board, so the classification analysis starts from what the product does, not from its marketing category.
The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class I, item 5 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.
Network Management Systems sit squarely on the CRA's lists: Annex III, Class I, item 6 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Network management systems”
— Annex III, Class I, item 6, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The products that configure, monitor and control network estates: NMS platforms, controllers, and configuration-management products for networks.
Annex III splits the networking world into three separate items — the systems that manage networks (this one), the interfaces networks run through (item 10), and the routers, modems and switches themselves (item 12). A vendor spanning them holds several classification analyses, not one.
For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex III, Class I, item 6, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.
Yes — SIEM systems are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 7 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Security information and event management (SIEM) systems”
— Annex III, Class I, item 7, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
SIEM is listed by name: platforms that collect, correlate and manage security events and logs, sold as products.
The SaaS boundary matters more here than in most categories. A pure cloud service sits under NIS2 rather than the CRA — but the CRA reaches the shipped product plus any remote data processing it functionally depends on that is developed by or for the manufacturer (Article 3(2)), which describes a lot of modern SIEM architecture.
Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class I, item 7 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).
Short answer: yes, listed. The CRA names boot managers at Annex III, Class I, item 8 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Boot managers”
— Annex III, Class I, item 8, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The software that controls what a system runs at start: bootloaders and boot managers, whether sold standalone or shipped as components.
Boot-stage code usually ships inside a larger device rather than in a box of its own — so the practical weight of this item often lands on integrating manufacturers through component due diligence (Article 13(5)) rather than on a standalone “boot manager vendor”.
The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class I, item 8 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.
PKI & Certificate-Issuance Software sit squarely on the CRA's lists: Annex III, Class I, item 9 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Public key infrastructure and digital certificate issuance software”
— Annex III, Class I, item 9, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
The machinery of digital trust: certificate-authority software, certificate-lifecycle platforms and issuance tooling.
Read this item next to Annex IV: the software that issues certificates is Class I, while the hardened hardware the keys live in — security boxes, smartcards, secure elements — sits on the critical list. One PKI deployment can touch both annexes through different products.
For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex III, Class I, item 9, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.
Yes — network interfaces are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 10 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Physical and virtual network interfaces”
— Annex III, Class I, item 10, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Both the silicon and the software abstraction are listed: physical network interface hardware and its virtual counterparts.
This is a component category by nature — interfaces mostly ship inside other products. The classification question therefore lands twice: on the interface's own manufacturer, and on every integrating manufacturer through the third-party-component due-diligence duty in Article 13(5).
Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class I, item 10 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).
Short answer: yes, listed. The CRA names operating systems at Annex III, Class I, item 11 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Operating systems”
— Annex III, Class I, item 11, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
Unqualified, like password managers: desktop, server, mobile and embedded operating systems all sit inside two words.
By install base this is the heaviest item in Class I — and it puts an embedded RTOS sold into device makers in the same listing as a general-purpose desktop OS. For OS vendors the practical scoping question is usually commercial FOSS boundaries: non-commercial open source is out of scope, and qualifying open-source stewards get the light-touch regime of Article 3(14).
The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class I, item 11 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.
Routers, Modems & Switches sit squarely on the CRA's lists: Annex III, Class I, item 12 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Routers, modems intended for the connection to the internet, and switches”
— Annex III, Class I, item 12, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The classic network edge, listed as a trio: routers, internet-facing modems, and switches.
On the item's own grammar the “intended for the connection to the internet” qualifier attaches to modems; routers and switches are listed without it. Where a borderline product lands is exactly the kind of call the binding technical descriptions in Implementing Regulation (EU) 2025/2392 exist to settle — classify against that text, not against the annex line alone.
For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex III, Class I, item 12, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.
Yes — security-function microprocessors are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 13 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Microprocessors with security-related functionalities”
— Annex III, Class I, item 13, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
Not every microprocessor — the qualifier does the work. Processors carrying security-related functionality are listed; general-purpose parts without it are not on the annex.
The same silicon family can land on three tiers: unlisted (no security functionality), Class I (this item), or Class II if the part is tamper-resistant (Annex III Class II, item 3). A product-line decision like adding tamper resistance is also a conformity-route decision.
Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class I, item 13 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).
Short answer: yes, listed. The CRA names security-function microcontrollers at Annex III, Class I, item 14 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Microcontrollers with security-related functionalities”
— Annex III, Class I, item 14, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The MCU mirror of item 13: microcontrollers with security-related functionality are listed; commodity MCUs without it are not.
For IoT device makers the component choice moves the analysis: a general MCU keeps the component off the annex, a secure MCU is Class I, and a tamper-resistant MCU is Class II (Annex III Class II, item 4). The device's own classification is a separate question from its components'.
The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class I, item 14 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.
ASICs & FPGAs With Security Functionality sit squarely on the CRA's lists: Annex III, Class I, item 15 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities”
— Annex III, Class I, item 15, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
Application-specific and programmable silicon join the list when carrying security-related functionality — the same qualifier pattern as the microprocessor and microcontroller items.
An FPGA as such is not listed; an FPGA shipped with security functionality is. For programmable parts the question of what the manufacturer ships versus what the customer programs onto it is a classification-worksheet question, keyed to the binding technical descriptions.
For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex III, Class I, item 15, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.
Yes — smart home virtual assistants are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 16 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Smart home general purpose virtual assistants”
— Annex III, Class I, item 16, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The hub-like, “do anything” assistants for the home: the item is aimed at general-purpose assistant products, typically smart speakers and displays.
“General purpose” is the qualifier to read carefully: a single-purpose voice interface inside one appliance is a different analysis from a general-purpose assistant that controls the home. Where that line falls for a given product is settled by the binding technical descriptions, not by the marketing name.
Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class I, item 16 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).
Short answer: yes, listed. The CRA names smart-home security products at Annex III, Class I, item 17 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems”
— Annex III, Class I, item 17, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
The item names its own examples: smart door locks, security cameras, baby monitors and alarm systems — smart-home products whose function is security.
“With security functionalities” is the gate: a smart bulb is not in this item; a camera is. Baby monitors being named explicitly matters — consumer-electronics makers rarely think of a nursery product as “important” in the regulatory sense, but the annex does.
The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class I, item 17 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.
Internet-Connected Toys sit squarely on the CRA's lists: Annex III, Class I, item 18 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features”
— Annex III, Class I, item 18, Regulation (EU) 2024/2847. The directive referenced in the item is the Toy Safety Directive 2009/48/EC. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Three cumulative gates: the product is a toy under the Toy Safety Directive (2009/48/EC); it is internet connected; and it has either social-interactive features — the annex's own examples are speaking or filming — or location tracking.
A connected toy without those features falls outside this item (while possibly still being an in-scope product with digital elements at the default tier). Add a microphone, a camera or a GPS tracker and the toy is Class I. The feature list on the box is the classification input.
For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex III, Class I, item 18, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.
Yes — health and children's wearables are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 19 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children”
— Annex III, Class I, item 19, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
Two branches. First: wearables with a health-monitoring purpose that are not medical devices — the consumer fitness band or wellness ring that sits outside the MDR and IVDR. Second: wearables intended for use by and for children, with no health qualifier at all.
The children's branch is broader than most readers expect — it is not limited to health products. A kids' smartwatch is inside the wording regardless of health features. And a wearable that is a regulated medical device is out of this item precisely because the MDR/IVDR applies instead.
Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class I, item 19 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).
Short answer: yes, listed. The CRA names hypervisors and container runtimes at Annex III, Class II, item 1 of Regulation (EU) 2024/2847, in the important Class II tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments”
— Annex III, Class II, item 1, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The virtualisation layer itself: hypervisors and container runtimes that support virtualised execution of operating systems and similar environments.
The wording is about the runtime layer, not everything containerised: the container runtime is Class II; an application shipped in a container is its own, separate classification analysis. Orchestration and tooling around the runtime need the worksheet treatment against the binding technical descriptions.
The Class II consequence is simple and expensive (Article 32): third-party conformity assessment, always. No harmonised standard changes it; a notified body is part of the path to market. The conformity guide maps all four routes.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class II, item 1 of Regulation (EU) 2024/2847, in the important Class II tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
Always. Article 32 gives Class II no self-assessment route: a notified body is part of the path to market whether or not harmonised standards exist.
Firewalls & Intrusion Detection/Prevention Systems sit squarely on the CRA's lists: Annex III, Class II, item 2 of Regulation (EU) 2024/2847, making them important Class II products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Firewalls, intrusion detection and prevention systems”
— Annex III, Class II, item 2, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
Perimeter and inline network security: firewalls and intrusion detection and prevention systems, hardware or software.
Note the tier split inside the security-product family: endpoint anti-malware is Class I (item 4), SIEM is Class I (item 7), but firewalls and IDS/IPS sit in Class II — where third-party conformity assessment is always mandatory. How a security product is positioned functionally decides whether a notified body is avoidable.
Class II is the stricter of the two “important” tiers (Article 32): conformity assessment is always third-party. A notified body is not avoidable, harmonised standards or not. Details on all four routes are in the conformity guide.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex III, Class II, item 2, placing it in the important Class II tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
Yes — Class II conformity assessment is always third-party under Article 32; a notified body is required regardless of standards.
Yes — tamper-resistant microprocessors are on the EU Cyber Resilience Act's lists. Annex III, Class II, item 3 of Regulation (EU) 2024/2847 places this category in the important Class II tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Tamper-resistant microprocessors”
— Annex III, Class II, item 3, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The hardened sibling of Class I item 13: tamper resistance moves a security microprocessor up a class.
For chip vendors the same product family can straddle the boundary — the tamper-resistance property itself changes the conformity route from “third party until standards land” (Class I today) to “third party, always” (Class II). The claim on the datasheet is a regulatory input.
The Class II consequence is simple and expensive (Article 32): third-party conformity assessment, always. No harmonised standard changes it; a notified body is part of the path to market. The conformity guide maps all four routes.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex III, Class II, item 3 of Regulation (EU) 2024/2847 lists the category, making these products important Class II products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Always. Article 32 gives Class II no self-assessment route: a notified body is part of the path to market whether or not harmonised standards exist.
Short answer: yes, listed. The CRA names tamper-resistant microcontrollers at Annex III, Class II, item 4 of Regulation (EU) 2024/2847, in the important Class II tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Tamper-resistant microcontrollers”
— Annex III, Class II, item 4, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
The MCU counterpart of item 3: tamper-resistant microcontrollers sit in Class II, above their merely security-functional siblings in Class I.
Device makers integrating one inherit a Class II component in the bill of materials — the device's own class is a separate analysis, but component due diligence under Article 13(5) applies either way.
Class II is the stricter of the two “important” tiers (Article 32): conformity assessment is always third-party. A notified body is not avoidable, harmonised standards or not. Details on all four routes are in the conformity guide.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex III, Class II, item 4 of Regulation (EU) 2024/2847, in the important Class II tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
Yes — Class II conformity assessment is always third-party under Article 32; a notified body is required regardless of standards.
Hardware Devices With Security Boxes sit squarely on the CRA's lists: Annex IV, item 1 of Regulation (EU) 2024/2847, making them critical products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.
“Hardware Devices with Security Boxes”
— Annex IV, item 1, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
The tamper-protected hardware tier: devices built around a hardened security enclosure — the “security box” concept familiar from HSM-class hardware.
The annex line is five words; the weight of what counts sits almost entirely in the binding technical descriptions of Implementing Regulation (EU) 2025/2392. If your product is anywhere near this wording, classification is a worksheet exercise against that text, not a judgement call off the annex.
For the Annex IV tier, Article 32 points at European cybersecurity certification where a delegated act mandates it — that enabling act was pending at our verification date and sits on our tracker. Anywhere near this list, classification is a worksheet exercise against Implementing Regulation (EU) 2025/2392, not a judgement call off the annex wording.
Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes. The CRA lists the category at Annex IV, item 1, placing it in the critical tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.
The critical tier points at European cybersecurity certification where a delegated act mandates it (Article 32); that act was pending at our verification date. Run the classification worksheet against Implementing Regulation (EU) 2025/2392 before drawing route conclusions.
Yes — smart meter gateways and advanced-security devices are on the EU Cyber Resilience Act's lists. Annex IV, item 2 of Regulation (EU) 2024/2847 places this category in the critical tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.
“Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessing”
— Annex IV, item 2, Regulation (EU) 2024/2847. The definition referenced in the item comes from the electricity-market directive (EU) 2019/944. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.
Two halves: smart meter gateways as defined in the electricity-market directive (2019/944), and a broader catch — “other devices for advanced security purposes, including for secure cryptoprocessing”.
The second half reaches beyond energy: purpose-based wording like “advanced security purposes” is exactly where the binding technical descriptions decide who is in. A security-hardware vendor with no connection to metering can still be inside this item's second limb.
Critical products sit above the Annex III classes: they can be required, by delegated act, to obtain European cybersecurity certification (Article 32; the enabling act is on the Commission's slate and tracked in our changelog). Classification here warrants the full worksheet treatment against Implementing Regulation (EU) 2025/2392 rather than a read of the annex line alone.
What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
Yes — Annex IV, item 2 of Regulation (EU) 2024/2847 lists the category, making these products critical products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Critical products can be required by delegated act to obtain European cybersecurity certification under Article 32; the enabling act was pending at our verification date. Classification and route here warrant the full worksheet against Implementing Regulation (EU) 2025/2392.
Short answer: yes, listed. The CRA names smartcards and secure elements at Annex IV, item 3 of Regulation (EU) 2024/2847, in the critical tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.
“Smartcards or similar devices, including secure elements”
— Annex IV, item 3, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.
Smartcards and similar devices, with secure elements named explicitly — the small hardened components that carry keys and credentials.
Secure elements ship inside phones, wearables and payment hardware, so this is a critical-list category whose customers are mostly other manufacturers: the integrating product's maker inherits component due diligence under Article 13(5) while the element's own maker holds the Annex IV listing.
For the Annex IV tier, Article 32 points at European cybersecurity certification where a delegated act mandates it — that enabling act was pending at our verification date and sits on our tracker. Anywhere near this list, classification is a worksheet exercise against Implementing Regulation (EU) 2025/2392, not a judgement call off the annex wording.
One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.
[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]
| 11 September 2026 | In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class. |
|---|---|
| ~30 October 2026 | First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route. |
| 11 December 2026 | Conformity-assessment-body chapter applies. |
| 11 December 2027 | Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties. |
They are: the category appears at Annex IV, item 3 of Regulation (EU) 2024/2847, in the critical tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.
The critical tier points at European cybersecurity certification where a delegated act mandates it (Article 32); that act was pending at our verification date. Run the classification worksheet against Implementing Regulation (EU) 2025/2392 before drawing route conclusions.
The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.
Get the pack — US$390 Free 4-page sample (PDF)Instant download · 14-day unconditional refund · single-organisation licence · full product page
General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.
Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com