---
title: "CRA Product Classification Explained: Default, Important, and Critical"
description: "How the EU Cyber Resilience Act classifies products with digital elements (Default, Important Class I and II, and Critical), with the full Annex III and Annex IV product lists and what each tier means for self-assessment, third-party conformity assessment, and CE marking."
canonical_url: "https://fossa.com/blog/cra-product-classification/"
markdown_url: "https://fossa.com/blog/cra-product-classification.md"
content_type: "blog"
language: "en"
date_published: "2026-08-17"
date_modified: "2026-08-17"
author: "Andy Drukarev"
organization: "FOSSA"
---

# CRA Product Classification Explained: Default, Important, and Critical

> How the EU Cyber Resilience Act classifies products with digital elements (Default, Important Class I and II, and Critical), with the full Annex III and Annex IV product lists and what each tier means for self-assessment, third-party conformity assessment, and CE marking.

The Cyber Resilience Act (CRA)'s requirements will start taking effect next month, in September of 2026. Compliance with the CRA's full set of requirements will then be mandated in December of 2027.

However, the process by which a product with digital elements formally achieves CRA compliance (and the associated CE marking) will vary significantly depending on its *product classification*. Products in the lowest-risk category (such as many smart devices) can achieve compliance via self-assessment, while those in higher tiers will require third-party assessmets. This post explains how the CRA's four product classes work, lists the products the regulation names in Annex III and Annex IV, and walks through how to classify your own product.

> Not sure which class applies to you? The free [CRA Readiness Assessment](https://fossa.com/resources/regulatory-compliance-tools/cra-readiness-assessment.md) walks you through classification and then assesses your readiness against the CRA's essential requirements for that tier.

## Why Classification Is the First Thing to Get Right

The CRA applies to the majority of products with digital elements placed on the EU market, but it does not treat them all the same. The compliance mechanism differs depending on the risk a product carries: a note-taking app and a firewall protecting critical infrastructure face very different paths.

Getting your class wrong can mean either over-engineering compliance or, far more dangerous, self-assessing a product that legally required an independent audit. And because the conformity assessment route affects how much lead time you need before the [December 2027 full-compliance deadline](https://fossa.com/blog/cra-compliance-timeline.md), classification is the natural first step in any CRA program.

## First: Confirm the CRA Applies at All

Classification only matters for products in scope, so start there. The CRA covers products with digital elements, meaning hardware or software (including their remote data processing solutions) made available on the EU market in the course of a commercial activity. However, there are a few exceptions:

- Pure SaaS and cloud services are generally out of scope; they're regulated under NIS2 instead. The exception is a remote data processing solution: cloud functionality designed by (or on behalf of) the manufacturer that the product needs to perform one of its functions. That back-end is in scope as part of the product.
- Products covered by equivalent sectoral rules are carved out. This includes medical devices under the MDR/IVDR, civil aviation equipment, motor vehicles under the type-approval regime, and marine equipment.
- Products developed exclusively for national security or defence are excluded, as are spare parts made to the same specifications as the components they replace.
- Non-commercial open source software is exempt. The regulation also introduces a lighter-touch open source software steward role for the foundations and organizations that sustain OSS used in commercial products, with duties focused on security policy and vulnerability handling. It is important to note that integrating open source into a commercial product makes it your responsibility as the manufacturer, including [SBOM and due-diligence obligations](https://fossa.com/blog/sbom-requirements-cra-cyber-resilience-act.md).

If your product is in scope, it lands in one of four classes.

## The Four CRA Product Classes

### Default Category

The large majority of products with digital elements: business software, web apps, photo editors, games, most smart appliances. Anything that doesn't have the core functionality of a category listed in Annex III or Annex IV falls here. The manufacturer can demonstrate conformity through internal control (self-assessment) against the Annex I essential requirements.

### Important (Class I)

This category includes products where compromise has an elevated security impact, listed in [Annex III](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02024R2847-20241120#anx_III). The categories include:

- Identity management systems and privileged access management software and hardware, including authentication and access control readers
- Standalone and embedded browsers
- Password managers
- Software that searches for, removes, or quarantines malicious software
- Products with the function of a virtual private network (VPN)
- Network management systems
- Security information and event management (SIEM) systems
- Boot managers
- Public key infrastructure and digital certificate issuance software
- Physical and virtual network interfaces
- Operating systems
- Routers, modems intended for the connection to the internet, and switches
- Microprocessors, microcontrollers, and ASICs/FPGAs with security-related functionalities
- Smart home general-purpose virtual assistants
- Smart home products with security functionalities, such as smart door locks, security cameras, baby monitors, and alarm systems
- Internet-connected toys with social interactive features or location-tracking
- Personal wearables used for health monitoring or intended for children

Self-assessment is allowed only if the manufacturer fully applies the relevant harmonised standards, common specifications, or a European cybersecurity certification; otherwise a third-party assessment is required. (An important note: As of this writing, final EU CRA harmonised standards have *not* yet been published in the EU's Official Journal so this path is not currently available. However, drafts [have been published](https://www.etsi.org/newsroom/press-releases/etsi-launches-approval-process-for-17-european-standards-supporting-the-cyber-resilience-act/) and are open for comment.)

### Important (Class II)

This classification covers products where security exploits could create more significant risk. The regulation names four categories:

- Hypervisors and container runtime systems that support the virtualized execution of operating systems and similar environments
- Firewalls, intrusion detection systems, and intrusion prevention systems
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers

Products in this class always require a third-party conformity assessment by a notified body. Harmonised standards don't unlock self-assessment at this tier.

### Critical

These are products with systemic importance to the EU, listed in [Annex IV](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A02024R2847-20241120#anx_IV):

- Hardware devices with security boxes
- Smart meter gateways within smart metering systems, and other devices for advanced security purposes including secure cryptoprocessing
- Smartcards or similar devices, including secure elements

In addition to third-party assessment, the Commission can require these to hold a European cybersecurity certificate under an adopted certification scheme at assurance level "substantial" or higher.

Note that none of these lists are permanently set in stone: the Commission publishes technical descriptions for the Annex III and IV categories and can update the lists via delegated acts, so it's worth re-checking your classification as implementation guidance evolves.

## How to Classify Your Product, Step by Step

In practice, classification comes down to four questions:

1. Is it in the CRA's scope? A product with digital elements, placed on the EU market commercially, not carved out by a sectoral regulation (see above).
2. Does its core functionality match an Annex IV category? If yes, it's Critical. The test is the product's intended purpose and core functionality, not whether it merely contains a matching component. (You can reference the ["technical description of the categories"](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32025R2392&qid=1764577062755) publication on the EU's official site for more in-depth detail on how your specific is categorized.)
3. Does its core functionality match an Annex III category? If yes, it's Important, at the class the annex assigns (Class I or Class II).
4. Otherwise, it's Default.

We should also mention a subtlety (contained in Article 7 of the CRA text) on the importance of integration direction. Product classification is ultimately determined by the core classification of the final product rather than any individual integrated component. For example, embedded a "Critical" component into a "Important - Class I" product doesn't necessarily mean the full product should be then categorised as "Critical."

If you have questions on any topic covered in this post, or if you'd like to learn more about FOSSA's automated solutions for CRA compliance, we encourage you to [get in touch with our team](https://fossa.com/blog/cra-product-classification/fossa.com/request-demo/).

  The free CRA Readiness Assessment walks you through product classification and then scores your readiness against the Annex I requirements for that tier, with a downloadable executive report and a prioritized 30/60/90-day remediation plan.

## CRA Product Classification FAQ

### What are the CRA product classifications?

The Cyber Resilience Act sorts products with digital elements into four tiers by risk: Default (the majority of products), Important Class I, Important Class II, and Critical. The tier determines the conformity assessment route a manufacturer must follow before affixing the CE marking.

### What is the difference between Important Class I and Class II?

Important Class I products, such as password managers, VPNs, routers, and operating systems, can be self-assessed, but only if the manufacturer fully applies the relevant harmonized standards; otherwise a third-party assessment is required. Important Class II products, such as firewalls, intrusion detection/prevention systems, and hypervisors, always require a third-party conformity assessment by a notified body.

### Which CRA products need a third-party conformity assessment?

Important Class II and Critical products require third-party involvement. Important Class II products need assessment by a notified body. Critical products may additionally be required to obtain a European cybersecurity certificate under an adopted certification scheme. Default and (standards-compliant) Important Class I products can be self-assessed.

### Where are the CRA important and critical products listed?

The categories of Important products are set out in Annex III of Regulation (EU) 2024/2847, and Critical products in Annex IV. The Commission can update these lists via delegated acts, so manufacturers should track changes as the regulation is implemented.

### Does the CRA apply to SaaS and cloud services?

Generally no. Pure SaaS and cloud services fall under NIS2 rather than the CRA. The exception is "remote data processing solutions": cloud functionality designed by or on behalf of the manufacturer that a product with digital elements needs to perform one of its functions is in scope as part of that product.

### What if my product isn't listed in Annex III or Annex IV?

If a product with digital elements does not have the core functionality of any category listed in Annex III or Annex IV, it falls into the Default category. It must still meet all of the CRA's Annex I essential requirements, but the manufacturer can demonstrate conformity through self-assessment.

*This post is directional guidance for planning, not legal advice; consult qualified counsel for a formal conformity determination. Primary sources: [Regulation (EU) 2024/2847 (EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2024/2847/oj), the [European Commission's CRA policy page](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act), and [ENISA](https://www.enisa.europa.eu/).*

## Related resources

- [EU CRA Compliance Timeline: Key Dates and Deadlines](https://fossa.com/blog/cra-compliance-timeline.md): The EU Cyber Resilience Act compliance timeline explained: entry into force in December 2024, the September 11, 2026 vulnerability reporting deadline, and full conformity with CE marking by December 11, 2027, plus what to prioritize at each stage.
- [SBOM Requirements in the EU’s CRA (Cyber Resilience Act)](https://fossa.com/blog/sbom-requirements-cra-cyber-resilience-act.md): An overview of the Cyber Resilience Act (CRA) and its implications for SBOM requirements, diving into its standards and comparisons to global initiatives.

## Source

Canonical page: https://fossa.com/blog/cra-product-classification/
