Kilde › Guides › CRA › CRA product categories: the 26 Annex I…

CRA product categories: the 26 Annex III and IV listings and what each tier means

Current to 26 August 2026 · updates land in the changelog.

Regulation (EU) 2024/2847 names 19 Class I and 4 Class II categories in Annex III and 3 critical categories in Annex IV, read here verbatim from the Official Journal text. The tier decides the conformity route; it decides nothing about the Article 14 reporting duty, which has applied to every in-scope product since 11 September 2026. Per-product classification is settled against Implementing Regulation (EU) 2025/2392. One section per category.

Identity Management & PAM Products under the CRA: important Class I, and what applies from 11 September 2026

Yes — identity management and PAM are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 1 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers”

— Annex III, Class I, item 1, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

The item covers the identity stack in both software and hardware form: identity-management platforms, privileged-access-management vaults and session brokers, and — spelled out twice with “including” — the physical layer of authentication and access-control readers, biometric readers among them.

The double “including” is the tell: this is not a software-only category. A door-access biometric terminal sits inside the wording alongside the IAM suite that manages it, so hardware vendors who think of themselves as physical-security companies are in the same item as identity-software vendors.

What the important Class I tier changes — and what it doesn't

Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a identity management and PAM maker should do before 11 September 2026

Are identity management and PAM covered by the EU Cyber Resilience Act?

Yes — Annex III, Class I, item 1 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do identity management and PAM need third-party conformity assessment?

Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).

↑ Back to the category list

Standalone & Embedded Browsers under the CRA: important Class I, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names browsers at Annex III, Class I, item 2 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Standalone and embedded browsers”

— Annex III, Class I, item 2, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

Both distribution modes are named. A browser shipped as its own product is inside the wording, and so is a browser embedded in something else — kiosk shells, in-app browsers, webview-based frames inside larger products.

“Embedded” is the word doing the quiet work: a manufacturer whose product merely contains a browser component is integrating an Annex III item, which pulls the classification question — and the component due-diligence duty in Article 13(5) — into products that never marketed themselves as browsers.

What the important Class I tier changes — and what it doesn't

The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a browsers maker should do before 11 September 2026

Are browsers covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class I, item 2 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do browsers need third-party conformity assessment?

For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.

↑ Back to the category list

Password Managers under the CRA: important Class I, and what applies from 11 September 2026

Password Managers sit squarely on the CRA's lists: Annex III, Class I, item 3 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Password managers”

— Annex III, Class I, item 3, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

Two words, no qualifiers. Consumer vault apps and enterprise credential managers sit in the same item: the listing draws no line by deployment model, user type or price.

Because the item is unqualified, the interesting boundary questions are at the edges of the product itself — browser extensions, secret-sharing features and sync services ship as part of the product with digital elements, and a cloud back-end the product functionally depends on counts as its remote data processing under Article 3(2).

What the important Class I tier changes — and what it doesn't

For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a password managers maker should do before 11 September 2026

Are password managers covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex III, Class I, item 3, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do password managers need third-party conformity assessment?

Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.

↑ Back to the category list

Anti-Malware & Malware-Removal Software under the CRA: important Class I, and what applies from 11 September 2026

Yes — anti-malware software are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 4 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Software that searches for, removes, or quarantines malicious software”

— Annex III, Class I, item 4, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The definition is functional, not nominal: search, remove, or quarantine. Any one of the three functions places a product inside the wording — classic antivirus, removal tooling and quarantine engines all qualify without the product ever calling itself “antivirus”.

The functional wording reaches scan engines licensed as components just as it reaches boxed endpoint suites — and note that network-level intrusion detection and prevention systems are listed separately, one class up (Annex III Class II, item 2).

What the important Class I tier changes — and what it doesn't

Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a anti-malware software maker should do before 11 September 2026

Are anti-malware software covered by the EU Cyber Resilience Act?

Yes — Annex III, Class I, item 4 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do anti-malware software need third-party conformity assessment?

Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).

↑ Back to the category list

VPN Products under the CRA: important Class I, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names VPN products at Annex III, Class I, item 5 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Products with digital elements with the function of virtual private network (VPN)”

— Annex III, Class I, item 5, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

The listing keys to the function, not the product name: anything shipping VPN functionality — a consumer VPN client, a site-to-site gateway, a router or firewall with a VPN server — carries this item for that function.

“Products … with the function of” is broader than “VPN products”: a multi-function product that includes VPN capability has an Annex III function on board, so the classification analysis starts from what the product does, not from its marketing category.

What the important Class I tier changes — and what it doesn't

The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a VPN products maker should do before 11 September 2026

Are VPN products covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class I, item 5 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do VPN products need third-party conformity assessment?

For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.

↑ Back to the category list

Network Management Systems under the CRA: important Class I, and what applies from 11 September 2026

Network Management Systems sit squarely on the CRA's lists: Annex III, Class I, item 6 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Network management systems”

— Annex III, Class I, item 6, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The products that configure, monitor and control network estates: NMS platforms, controllers, and configuration-management products for networks.

Annex III splits the networking world into three separate items — the systems that manage networks (this one), the interfaces networks run through (item 10), and the routers, modems and switches themselves (item 12). A vendor spanning them holds several classification analyses, not one.

What the important Class I tier changes — and what it doesn't

For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a network management systems maker should do before 11 September 2026

Are network management systems covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex III, Class I, item 6, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do network management systems need third-party conformity assessment?

Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.

↑ Back to the category list

SIEM Systems under the CRA: important Class I, and what applies from 11 September 2026

Yes — SIEM systems are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 7 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Security information and event management (SIEM) systems”

— Annex III, Class I, item 7, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

SIEM is listed by name: platforms that collect, correlate and manage security events and logs, sold as products.

The SaaS boundary matters more here than in most categories. A pure cloud service sits under NIS2 rather than the CRA — but the CRA reaches the shipped product plus any remote data processing it functionally depends on that is developed by or for the manufacturer (Article 3(2)), which describes a lot of modern SIEM architecture.

What the important Class I tier changes — and what it doesn't

Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a SIEM systems maker should do before 11 September 2026

Are SIEM systems covered by the EU Cyber Resilience Act?

Yes — Annex III, Class I, item 7 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do SIEM systems need third-party conformity assessment?

Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).

↑ Back to the category list

Boot Managers under the CRA: important Class I, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names boot managers at Annex III, Class I, item 8 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Boot managers”

— Annex III, Class I, item 8, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The software that controls what a system runs at start: bootloaders and boot managers, whether sold standalone or shipped as components.

Boot-stage code usually ships inside a larger device rather than in a box of its own — so the practical weight of this item often lands on integrating manufacturers through component due diligence (Article 13(5)) rather than on a standalone “boot manager vendor”.

What the important Class I tier changes — and what it doesn't

The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a boot managers maker should do before 11 September 2026

Are boot managers covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class I, item 8 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do boot managers need third-party conformity assessment?

For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.

↑ Back to the category list

PKI & Certificate-Issuance Software under the CRA: important Class I, and what applies from 11 September 2026

PKI & Certificate-Issuance Software sit squarely on the CRA's lists: Annex III, Class I, item 9 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Public key infrastructure and digital certificate issuance software”

— Annex III, Class I, item 9, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

The machinery of digital trust: certificate-authority software, certificate-lifecycle platforms and issuance tooling.

Read this item next to Annex IV: the software that issues certificates is Class I, while the hardened hardware the keys live in — security boxes, smartcards, secure elements — sits on the critical list. One PKI deployment can touch both annexes through different products.

What the important Class I tier changes — and what it doesn't

For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a PKI and certificate-issuance software maker should do before 11 September 2026

Are PKI and certificate-issuance software covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex III, Class I, item 9, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do PKI and certificate-issuance software need third-party conformity assessment?

Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.

↑ Back to the category list

Physical & Virtual Network Interfaces under the CRA: important Class I, and what applies from 11 September 2026

Yes — network interfaces are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 10 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Physical and virtual network interfaces”

— Annex III, Class I, item 10, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

Both the silicon and the software abstraction are listed: physical network interface hardware and its virtual counterparts.

This is a component category by nature — interfaces mostly ship inside other products. The classification question therefore lands twice: on the interface's own manufacturer, and on every integrating manufacturer through the third-party-component due-diligence duty in Article 13(5).

What the important Class I tier changes — and what it doesn't

Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a network interfaces maker should do before 11 September 2026

Are network interfaces covered by the EU Cyber Resilience Act?

Yes — Annex III, Class I, item 10 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do network interfaces need third-party conformity assessment?

Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).

↑ Back to the category list

Operating Systems under the CRA: important Class I, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names operating systems at Annex III, Class I, item 11 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Operating systems”

— Annex III, Class I, item 11, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

Unqualified, like password managers: desktop, server, mobile and embedded operating systems all sit inside two words.

By install base this is the heaviest item in Class I — and it puts an embedded RTOS sold into device makers in the same listing as a general-purpose desktop OS. For OS vendors the practical scoping question is usually commercial FOSS boundaries: non-commercial open source is out of scope, and qualifying open-source stewards get the light-touch regime of Article 3(14).

What the important Class I tier changes — and what it doesn't

The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a operating systems maker should do before 11 September 2026

Are operating systems covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class I, item 11 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do operating systems need third-party conformity assessment?

For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.

↑ Back to the category list

Routers, Modems & Switches under the CRA: important Class I, and what applies from 11 September 2026

Routers, Modems & Switches sit squarely on the CRA's lists: Annex III, Class I, item 12 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Routers, modems intended for the connection to the internet, and switches”

— Annex III, Class I, item 12, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The classic network edge, listed as a trio: routers, internet-facing modems, and switches.

On the item's own grammar the “intended for the connection to the internet” qualifier attaches to modems; routers and switches are listed without it. Where a borderline product lands is exactly the kind of call the binding technical descriptions in Implementing Regulation (EU) 2025/2392 exist to settle — classify against that text, not against the annex line alone.

What the important Class I tier changes — and what it doesn't

For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a routers, modems and switches maker should do before 11 September 2026

Are routers, modems and switches covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex III, Class I, item 12, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do routers, modems and switches need third-party conformity assessment?

Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.

↑ Back to the category list

Microprocessors With Security Functionality under the CRA: important Class I, and what applies from 11 September 2026

Yes — security-function microprocessors are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 13 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Microprocessors with security-related functionalities”

— Annex III, Class I, item 13, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

Not every microprocessor — the qualifier does the work. Processors carrying security-related functionality are listed; general-purpose parts without it are not on the annex.

The same silicon family can land on three tiers: unlisted (no security functionality), Class I (this item), or Class II if the part is tamper-resistant (Annex III Class II, item 3). A product-line decision like adding tamper resistance is also a conformity-route decision.

What the important Class I tier changes — and what it doesn't

Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a security-function microprocessors maker should do before 11 September 2026

Are security-function microprocessors covered by the EU Cyber Resilience Act?

Yes — Annex III, Class I, item 13 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do security-function microprocessors need third-party conformity assessment?

Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).

↑ Back to the category list

Microcontrollers With Security Functionality under the CRA: important Class I, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names security-function microcontrollers at Annex III, Class I, item 14 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Microcontrollers with security-related functionalities”

— Annex III, Class I, item 14, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The MCU mirror of item 13: microcontrollers with security-related functionality are listed; commodity MCUs without it are not.

For IoT device makers the component choice moves the analysis: a general MCU keeps the component off the annex, a secure MCU is Class I, and a tamper-resistant MCU is Class II (Annex III Class II, item 4). The device's own classification is a separate question from its components'.

What the important Class I tier changes — and what it doesn't

The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a security-function microcontrollers maker should do before 11 September 2026

Are security-function microcontrollers covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class I, item 14 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do security-function microcontrollers need third-party conformity assessment?

For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.

↑ Back to the category list

ASICs & FPGAs With Security Functionality under the CRA: important Class I, and what applies from 11 September 2026

ASICs & FPGAs With Security Functionality sit squarely on the CRA's lists: Annex III, Class I, item 15 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities”

— Annex III, Class I, item 15, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

Application-specific and programmable silicon join the list when carrying security-related functionality — the same qualifier pattern as the microprocessor and microcontroller items.

An FPGA as such is not listed; an FPGA shipped with security functionality is. For programmable parts the question of what the manufacturer ships versus what the customer programs onto it is a classification-worksheet question, keyed to the binding technical descriptions.

What the important Class I tier changes — and what it doesn't

For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a security-function ASICs and FPGAs maker should do before 11 September 2026

Are security-function ASICs and FPGAs covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex III, Class I, item 15, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do security-function ASICs and FPGAs need third-party conformity assessment?

Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.

↑ Back to the category list

Smart Home Virtual Assistants under the CRA: important Class I, and what applies from 11 September 2026

Yes — smart home virtual assistants are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 16 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Smart home general purpose virtual assistants”

— Annex III, Class I, item 16, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The hub-like, “do anything” assistants for the home: the item is aimed at general-purpose assistant products, typically smart speakers and displays.

“General purpose” is the qualifier to read carefully: a single-purpose voice interface inside one appliance is a different analysis from a general-purpose assistant that controls the home. Where that line falls for a given product is settled by the binding technical descriptions, not by the marketing name.

What the important Class I tier changes — and what it doesn't

Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a smart home virtual assistants maker should do before 11 September 2026

Are smart home virtual assistants covered by the EU Cyber Resilience Act?

Yes — Annex III, Class I, item 16 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do smart home virtual assistants need third-party conformity assessment?

Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).

↑ Back to the category list

Smart Locks, Cameras, Baby Monitors & Alarms under the CRA: important Class I, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names smart-home security products at Annex III, Class I, item 17 of Regulation (EU) 2024/2847, in the important Class I tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems”

— Annex III, Class I, item 17, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

The item names its own examples: smart door locks, security cameras, baby monitors and alarm systems — smart-home products whose function is security.

“With security functionalities” is the gate: a smart bulb is not in this item; a camera is. Baby monitors being named explicitly matters — consumer-electronics makers rarely think of a nursery product as “important” in the regulatory sense, but the annex does.

What the important Class I tier changes — and what it doesn't

The conformity consequence of Class I (Article 32): the self-assessment route exists only for products applying relevant harmonised standards, common specifications or certification. Because no CRA harmonised standard had been cited in the Official Journal at our verification date, that route is closed in practice for now — the first citation, currently expected around 30 October 2026, opens it.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a smart-home security products maker should do before 11 September 2026

Are smart-home security products covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class I, item 17 of Regulation (EU) 2024/2847, in the important Class I tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do smart-home security products need third-party conformity assessment?

For now, effectively yes. Class I self-assessment depends on applying harmonised standards, common specifications or certification (Article 32), and no CRA harmonised standard had been cited in the Official Journal at our verification date. The first citation, expected around 30 October 2026, reopens the self-route.

↑ Back to the category list

Internet-Connected Toys under the CRA: important Class I, and what applies from 11 September 2026

Internet-Connected Toys sit squarely on the CRA's lists: Annex III, Class I, item 18 of Regulation (EU) 2024/2847, making them important Class I products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features”

— Annex III, Class I, item 18, Regulation (EU) 2024/2847. The directive referenced in the item is the Toy Safety Directive 2009/48/EC. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

Three cumulative gates: the product is a toy under the Toy Safety Directive (2009/48/EC); it is internet connected; and it has either social-interactive features — the annex's own examples are speaking or filming — or location tracking.

A connected toy without those features falls outside this item (while possibly still being an in-scope product with digital elements at the default tier). Add a microphone, a camera or a GPS tracker and the toy is Class I. The feature list on the box is the classification input.

What the important Class I tier changes — and what it doesn't

For conformity assessment, Class I means conditional self-assessment (Article 32): available when relevant harmonised standards, common specifications or certification are applied, and not otherwise. With zero harmonised standards cited in the Official Journal as of our verification date, a Class I product today should budget for a third party and treat the expected first citation (~30 October 2026) as upside — route details here.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a connected toys maker should do before 11 September 2026

Are connected toys covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex III, Class I, item 18, placing it in the important Class I tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do connected toys need third-party conformity assessment?

Today, in practice, yes: the Class I self-assessment route only exists once relevant harmonised standards (or common specifications or certification) are available to apply, and none had been cited in the Official Journal at our verification date. Budget for a notified body; treat the ~30 Oct 2026 citation as upside.

↑ Back to the category list

Health Wearables & Children's Wearables under the CRA: important Class I, and what applies from 11 September 2026

Yes — health and children's wearables are on the EU Cyber Resilience Act's lists. Annex III, Class I, item 19 of Regulation (EU) 2024/2847 places this category in the important Class I tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children”

— Annex III, Class I, item 19, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

Two branches. First: wearables with a health-monitoring purpose that are not medical devices — the consumer fitness band or wellness ring that sits outside the MDR and IVDR. Second: wearables intended for use by and for children, with no health qualifier at all.

The children's branch is broader than most readers expect — it is not limited to health products. A kids' smartwatch is inside the wording regardless of health features. And a wearable that is a regulated medical device is out of this item precisely because the MDR/IVDR applies instead.

What the important Class I tier changes — and what it doesn't

Class I decides the conformity route (Article 32): self-assessment is available only when applying relevant harmonised standards, common specifications or certification; otherwise a third-party route applies. As of our verification date no harmonised standard under the CRA had been cited in the Official Journal, so Class I products currently have no practical self-assessment path; the first citation (currently expected around 30 October 2026) switches it on.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a health and children's wearables maker should do before 11 September 2026

Are health and children's wearables covered by the EU Cyber Resilience Act?

Yes — Annex III, Class I, item 19 of Regulation (EU) 2024/2847 lists the category, making these products important Class I products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do health and children's wearables need third-party conformity assessment?

Under Article 32, Class I products can self-assess only when applying relevant harmonised standards, common specifications or certification. With none cited in the Official Journal at our verification date, the practical route is third-party until the first citation lands (expected ~30 Oct 2026).

↑ Back to the category list

Hypervisors & Container Runtimes under the CRA: important Class II, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names hypervisors and container runtimes at Annex III, Class II, item 1 of Regulation (EU) 2024/2847, in the important Class II tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments”

— Annex III, Class II, item 1, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The virtualisation layer itself: hypervisors and container runtimes that support virtualised execution of operating systems and similar environments.

The wording is about the runtime layer, not everything containerised: the container runtime is Class II; an application shipped in a container is its own, separate classification analysis. Orchestration and tooling around the runtime need the worksheet treatment against the binding technical descriptions.

What the important Class II tier changes — and what it doesn't

The Class II consequence is simple and expensive (Article 32): third-party conformity assessment, always. No harmonised standard changes it; a notified body is part of the path to market. The conformity guide maps all four routes.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a hypervisors and container runtimes maker should do before 11 September 2026

Are hypervisors and container runtimes covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class II, item 1 of Regulation (EU) 2024/2847, in the important Class II tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do hypervisors and container runtimes need third-party conformity assessment?

Always. Article 32 gives Class II no self-assessment route: a notified body is part of the path to market whether or not harmonised standards exist.

↑ Back to the category list

Firewalls & Intrusion Detection/Prevention Systems under the CRA: important Class II, and what applies from 11 September 2026

Firewalls & Intrusion Detection/Prevention Systems sit squarely on the CRA's lists: Annex III, Class II, item 2 of Regulation (EU) 2024/2847, making them important Class II products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Firewalls, intrusion detection and prevention systems”

— Annex III, Class II, item 2, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

Perimeter and inline network security: firewalls and intrusion detection and prevention systems, hardware or software.

Note the tier split inside the security-product family: endpoint anti-malware is Class I (item 4), SIEM is Class I (item 7), but firewalls and IDS/IPS sit in Class II — where third-party conformity assessment is always mandatory. How a security product is positioned functionally decides whether a notified body is avoidable.

What the important Class II tier changes — and what it doesn't

Class II is the stricter of the two “important” tiers (Article 32): conformity assessment is always third-party. A notified body is not avoidable, harmonised standards or not. Details on all four routes are in the conformity guide.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a firewalls and IDS/IPS maker should do before 11 September 2026

Are firewalls and IDS/IPS covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex III, Class II, item 2, placing it in the important Class II tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do firewalls and IDS/IPS need third-party conformity assessment?

Yes — Class II conformity assessment is always third-party under Article 32; a notified body is required regardless of standards.

↑ Back to the category list

Tamper-Resistant Microprocessors under the CRA: important Class II, and what applies from 11 September 2026

Yes — tamper-resistant microprocessors are on the EU Cyber Resilience Act's lists. Annex III, Class II, item 3 of Regulation (EU) 2024/2847 places this category in the important Class II tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Tamper-resistant microprocessors”

— Annex III, Class II, item 3, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The hardened sibling of Class I item 13: tamper resistance moves a security microprocessor up a class.

For chip vendors the same product family can straddle the boundary — the tamper-resistance property itself changes the conformity route from “third party until standards land” (Class I today) to “third party, always” (Class II). The claim on the datasheet is a regulatory input.

What the important Class II tier changes — and what it doesn't

The Class II consequence is simple and expensive (Article 32): third-party conformity assessment, always. No harmonised standard changes it; a notified body is part of the path to market. The conformity guide maps all four routes.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a tamper-resistant microprocessors maker should do before 11 September 2026

Are tamper-resistant microprocessors covered by the EU Cyber Resilience Act?

Yes — Annex III, Class II, item 3 of Regulation (EU) 2024/2847 lists the category, making these products important Class II products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do tamper-resistant microprocessors need third-party conformity assessment?

Always. Article 32 gives Class II no self-assessment route: a notified body is part of the path to market whether or not harmonised standards exist.

↑ Back to the category list

Tamper-Resistant Microcontrollers under the CRA: important Class II, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names tamper-resistant microcontrollers at Annex III, Class II, item 4 of Regulation (EU) 2024/2847, in the important Class II tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Tamper-resistant microcontrollers”

— Annex III, Class II, item 4, Regulation (EU) 2024/2847. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

The MCU counterpart of item 3: tamper-resistant microcontrollers sit in Class II, above their merely security-functional siblings in Class I.

Device makers integrating one inherit a Class II component in the bill of materials — the device's own class is a separate analysis, but component due diligence under Article 13(5) applies either way.

What the important Class II tier changes — and what it doesn't

Class II is the stricter of the two “important” tiers (Article 32): conformity assessment is always third-party. A notified body is not avoidable, harmonised standards or not. Details on all four routes are in the conformity guide.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a tamper-resistant microcontrollers maker should do before 11 September 2026

Are tamper-resistant microcontrollers covered by the EU Cyber Resilience Act?

They are: the category appears at Annex III, Class II, item 4 of Regulation (EU) 2024/2847, in the important Class II tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do tamper-resistant microcontrollers need third-party conformity assessment?

Yes — Class II conformity assessment is always third-party under Article 32; a notified body is required regardless of standards.

↑ Back to the category list

Hardware Devices With Security Boxes under the CRA: critical, and what applies from 11 September 2026

Hardware Devices With Security Boxes sit squarely on the CRA's lists: Annex IV, item 1 of Regulation (EU) 2024/2847, making them critical products. Below: the wording itself, the conformity consequences, and the one duty classification never touches, the reporting clocks arriving 11 September 2026.

The listing, verbatim

“Hardware Devices with Security Boxes”

— Annex IV, item 1, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

The tamper-protected hardware tier: devices built around a hardened security enclosure — the “security box” concept familiar from HSM-class hardware.

The annex line is five words; the weight of what counts sits almost entirely in the binding technical descriptions of Implementing Regulation (EU) 2025/2392. If your product is anywhere near this wording, classification is a worksheet exercise against that text, not a judgement call off the annex.

What the critical tier changes — and what it doesn't

For the Annex IV tier, Article 32 points at European cybersecurity certification where a delegated act mandates it — that enabling act was pending at our verification date and sits on our tracker. Anywhere near this list, classification is a worksheet exercise against Implementing Regulation (EU) 2025/2392, not a judgement call off the annex wording.

Keep the two questions separate: class decides who checks your conformity work; it decides nothing about the reporting duty, which lands on every in-scope manufacturer on 11 September 2026, installed base included, whenever an actively exploited vulnerability or severe incident surfaces.

Product types the wording typically catches

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a hardware devices with security boxes maker should do before 11 September 2026

Are hardware devices with security boxes covered by the EU Cyber Resilience Act?

Yes. The CRA lists the category at Annex IV, item 1, placing it in the critical tier; whether a given product actually falls inside is a worksheet question against Implementing Regulation (EU) 2025/2392.

Do hardware devices with security boxes need third-party conformity assessment?

The critical tier points at European cybersecurity certification where a delegated act mandates it (Article 32); that act was pending at our verification date. Run the classification worksheet against Implementing Regulation (EU) 2025/2392 before drawing route conclusions.

↑ Back to the category list

Smart Meter Gateways & Advanced-Security Devices under the CRA: critical, and what applies from 11 September 2026

Yes — smart meter gateways and advanced-security devices are on the EU Cyber Resilience Act's lists. Annex IV, item 2 of Regulation (EU) 2024/2847 places this category in the critical tier. What that changes, and what it does not change about the reporting duty that starts 11 September 2026, is below.

The listing, verbatim

“Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessing”

— Annex IV, item 2, Regulation (EU) 2024/2847. The definition referenced in the item comes from the electricity-market directive (EU) 2019/944. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392; classify against that text, not the annex line alone.

Reading the item's wording

Two halves: smart meter gateways as defined in the electricity-market directive (2019/944), and a broader catch — “other devices for advanced security purposes, including for secure cryptoprocessing”.

The second half reaches beyond energy: purpose-based wording like “advanced security purposes” is exactly where the binding technical descriptions decide who is in. A security-hardware vendor with no connection to metering can still be inside this item's second limb.

What the critical tier changes — and what it doesn't

Critical products sit above the Annex III classes: they can be required, by delegated act, to obtain European cybersecurity certification (Article 32; the enabling act is on the Commission's slate and tracked in our changelog). Classification here warrants the full worksheet treatment against Implementing Regulation (EU) 2025/2392 rather than a read of the annex line alone.

What classification does not change: the Article 14 reporting duty. From 11 September 2026, every in-scope manufacturer, default tier or critical, runs the same 24-hour/72-hour/final-report clocks for actively exploited vulnerabilities and severe incidents, and by Article 69(3) that covers products already in the field.

Products typically inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a smart meter gateways and advanced-security devices maker should do before 11 September 2026

Are smart meter gateways and advanced-security devices covered by the EU Cyber Resilience Act?

Yes — Annex IV, item 2 of Regulation (EU) 2024/2847 lists the category, making these products critical products. Whether a specific product falls inside the category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Do smart meter gateways and advanced-security devices need third-party conformity assessment?

Critical products can be required by delegated act to obtain European cybersecurity certification under Article 32; the enabling act was pending at our verification date. Classification and route here warrant the full worksheet against Implementing Regulation (EU) 2025/2392.

↑ Back to the category list

Smartcards & Secure Elements under the CRA: critical, and what applies from 11 September 2026

Short answer: yes, listed. The CRA names smartcards and secure elements at Annex IV, item 3 of Regulation (EU) 2024/2847, in the critical tier. This page covers what the listing means, what the tier changes for conformity, and why the 11 September 2026 reporting duty applies either way.

The listing, verbatim

“Smartcards or similar devices, including secure elements”

— Annex IV, item 3, Regulation (EU) 2024/2847. The annex line is the headline, not the test: per-product classification runs against the binding technical descriptions in Implementing Regulation (EU) 2025/2392.

Reading the item's wording

Smartcards and similar devices, with secure elements named explicitly — the small hardened components that carry keys and credentials.

Secure elements ship inside phones, wearables and payment hardware, so this is a critical-list category whose customers are mostly other manufacturers: the integrating product's maker inherits component due diligence under Article 13(5) while the element's own maker holds the Annex IV listing.

What the critical tier changes — and what it doesn't

For the Annex IV tier, Article 32 points at European cybersecurity certification where a delegated act mandates it — that enabling act was pending at our verification date and sits on our tracker. Anywhere near this list, classification is a worksheet exercise against Implementing Regulation (EU) 2025/2392, not a judgement call off the annex wording.

One thing the tier never touches: reporting. The Article 14 clocks (24 hours to an early warning, 72 to a notification, then the final report) run identically for every class from 11 September 2026, on the same two triggers, and Article 69(3) extends them to the installed base.

What tends to fall inside the wording

[ILLUSTRATIVE — reading the category onto product types is our own, non-binding orientation; per-product classification runs against Implementing Regulation (EU) 2025/2392.]

The dates this category runs on

11 September 2026In force. The Article 14 reporting duty has applied since this date: 24-hour early warning → 72-hour notification → final report — covering the whole in-scope installed base, whatever its class.
~30 October 2026First harmonised standards expected to be cited in the OJ (estimate; has slipped once) — the event that opens the Class I self-assessment route.
11 December 2026Conformity-assessment-body chapter applies.
11 December 2027Full application: essential requirements, conformity assessment and CE marking, technical documentation, support-period duties.

What a smartcards and secure elements maker should do before 11 September 2026

Are smartcards and secure elements covered by the EU Cyber Resilience Act?

They are: the category appears at Annex IV, item 3 of Regulation (EU) 2024/2847, in the critical tier. Per-product classification is settled against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, not the annex line alone.

Do smartcards and secure elements need third-party conformity assessment?

The critical tier points at European cybersecurity certification where a delegated act mandates it (Article 32); that act was pending at our verification date. Run the classification worksheet against Implementing Regulation (EU) 2025/2392 before drawing route conclusions.

↑ Back to the category list

Quick answers

Does the class change the reporting duty?
No. Article 14's 24-hour early warning and 72-hour notification apply to every in-scope product regardless of class, and per Article 69(3) to products already on the market.
What does Class I versus Class II change?
The conformity-assessment route from 11 December 2027: Class I may self-assess once relevant harmonised standards are cited; Class II always needs a notified body; critical products may be required to obtain European cybersecurity certification.
Where is the binding technical description of each category?
Implementing Regulation (EU) 2025/2392; the Annex III/IV lines name the category, the implementing act draws its boundary.
Be reporting-ready before 11 September 2026.

The CRA Reporting-Ready Pack: the staged 24h / 72h / final-report runbook and templates, vulnerability-vs-incident triage worksheet, CSIRT-routing and main-establishment worksheet, platform registration runbook, CVD policy and evidence log — built from the regulation and the ENISA platform guides, with pinpoint citations.

Get the pack — US$390 Free 4-page sample (PDF)

Instant download · 14-day unconditional refund · single-organisation licence · full product page

General information only — not legal advice, and never a conformity assessment. Whether a specific product falls in a listed category is decided against the binding technical descriptions in Implementing Regulation (EU) 2025/2392, and reporting-platform mechanics are ENISA-published material marked subject to change. Sources are Regulation (EU) 2024/2847 (CELEX 32024R2847; Annex III/IV item texts read verbatim from EUR-Lex) and our audited kit research. © 2026 Kilde.

Built by Kilde's founder, a practising attorney admitted to a US state bar (not an EU or Hong Kong admission). About · Verification log · Refunds · Terms · Privacy · esau@trykilde.com