The Cyber Resilience Act, Regulation (EU) 2024/2847, applies the same essential requirements to every product with digital elements in scope. What differs by product is how you prove you meet them. Article 32 lets most manufacturers assess themselves; for the products listed in Annex III it narrows the options, and for the three categories in Annex IV it points at European certification. So after the scope question, which we have written up separately, the next one is: is my product on either list?

This article gives both lists verbatim. It exists because the lists floating around the web are often the Commission's 2022 proposal, which had 23 class I rows and 15 class II rows, put operating systems, general-purpose microprocessors and public key infrastructure in class II, and numbered everything differently. The final text is shorter and different, and a manufacturer classifying against the proposal will get the answer wrong.

The three tiers, and what each changes

Everything in scope that is on neither list is default. Under Article 32(1) a default product can be assessed by the manufacturer alone under the internal control procedure (module A of Annex VIII), or, if the manufacturer prefers, by any of the third-party routes.

Important, class I (Annex III, 19 categories). Self-assessment stays available only if the manufacturer applies harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial, and applies them in full. Where those do not exist, or are applied only in part, Article 32(2) requires a notified body: EU-type examination followed by conformity to type (modules B and C), or full quality assurance (module H). As of September 2026 no harmonised standard under the CRA has been published in the Official Journal, so today the practical answer for a class I product is a notified body; and no body has yet been notified under the CRA either, so for now there is no route to complete, only a file to prepare.

Important, class II (Annex III, 4 categories). Article 32(3): a notified body under modules B and C or module H, or a European cybersecurity certification scheme at assurance level at least substantial. Self-assessment is not an option.

Critical (Annex IV, 3 categories). Article 32(4): a European cybersecurity certification scheme where the Commission has required one under Article 8(1); otherwise the class II procedures.

Two things the tier does not change. The essential requirements in Annex I are the same for all four tiers. And the Article 14 reporting duty, in force since 11 September 2026, applies identically to a default product and a critical one: 24 hours to the early warning, 72 to the notification, to your member state's CSIRT and ENISA.

Annex III, class I: important products

Reference Wording of the Regulation
Annex III, class I, point 1 Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
Annex III, class I, point 2 Standalone and embedded browsers
Annex III, class I, point 3 Password managers
Annex III, class I, point 4 Software that searches for, removes, or quarantines malicious software
Annex III, class I, point 5 Products with digital elements with the function of virtual private network (VPN)
Annex III, class I, point 6 Network management systems
Annex III, class I, point 7 Security information and event management (SIEM) systems
Annex III, class I, point 8 Boot managers
Annex III, class I, point 9 Public key infrastructure and digital certificate issuance software
Annex III, class I, point 10 Physical and virtual network interfaces
Annex III, class I, point 11 Operating systems
Annex III, class I, point 12 Routers, modems intended for the connection to the internet, and switches
Annex III, class I, point 13 Microprocessors with security-related functionalities
Annex III, class I, point 14 Microcontrollers with security-related functionalities
Annex III, class I, point 15 Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
Annex III, class I, point 16 Smart home general purpose virtual assistants
Annex III, class I, point 17 Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
Annex III, class I, point 18 Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features
Annex III, class I, point 19 Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) 2017/746 do not apply, or personal wearable products that are intended for the use by and for children

Annex III, class II: important products

Reference Wording of the Regulation
Annex III, class II, point 1 Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
Annex III, class II, point 2 Firewalls, intrusion detection and prevention systems
Annex III, class II, point 3 Tamper-resistant microprocessors
Annex III, class II, point 4 Tamper-resistant microcontrollers

Annex IV: critical products

Reference Wording of the Regulation
Annex IV, point 1 Hardware Devices with Security Boxes
Annex IV, point 2 Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessing
Annex IV, point 3 Smartcards or similar devices, including secure elements

Reading the lists

They describe function, not product type. "Products with digital elements with the function of virtual private network" catches a router with a VPN feature, a VPN app and a VPN library. "Microprocessors with security-related functionalities" is narrower than "microprocessors", which the proposal had listed outright. Read the row as a function your product performs, not as a category it is sold in.

Class II is small and specific. Four rows: hypervisors and container runtimes, firewalls and intrusion detection or prevention, tamper-resistant microprocessors, tamper-resistant microcontrollers. Operating systems, which the proposal put in class II, are class I in the final text.

Consumer products are on the list. Smart locks, security cameras, baby monitors and alarm systems, general-purpose smart home assistants, connected toys with social interaction or location tracking, and wearables for health monitoring or for children are all class I. A hardware start-up shipping a camera with an app is an important-product manufacturer.

Open source has its own route. Article 32(5): a free and open-source product in an Annex III category may still use the self-assessment procedure, provided the technical documentation is made public when the product is placed on the market.

Fees must reflect size. Article 32(6) requires conformity assessment fees to take account of the specific interests and needs of microenterprises and small and medium-sized enterprises, including start-ups, and to be reduced proportionately. Ask the notified body about it before accepting a quote.

What to record

The classification is part of the scope determination and goes into the technical file. One line per product: default, or the Annex and point it falls under, with the wording quoted, and the Article 32 route that follows from it. If a product could be read into a row, write down why you concluded it does or does not, because that reasoning is what a market surveillance authority reads first, and for most member states that authority has not yet been named.

The dates: the Article 14 reporting duty applies now. Annex I, the technical file, conformity assessment and CE marking apply from 11 December 2027, and under Article 69 a product already on the market before that date is subject to them only if it is substantially modified afterwards.

Since 21 December 2025 each of the 26 categories has a technical description in Commission Implementing Regulation (EU) 2025/2392, and the Commission's guidance of 27 July 2026 says classification is by core functionality alone: all 26 descriptions verbatim, with the six rules and their examples.

Sources

  • Regulation (EU) 2024/2847, Annex III and Annex IV (wording verbatim, footnote markers removed), Article 32(1) to (6), Article 8(1), Article 14, Article 69, Article 71(2), Annex VIII for the modules. Read from the Official Journal text on EUR-Lex on 11 September 2026.
  • The Commission's 2022 proposal, COM(2022) 454, for the earlier Annex III that some pages still reproduce.

This is not legal advice. The lists are quoted so you can classify against the text rather than against our reading of it.