CRA product classification

CRA product classes

Last updated · 8 Jun 2026

The EU Cyber Resilience Act puts every product with digital elements into one of four tiers. The tier decides your conformity route - whether you can self-assess or need an independent body to sign off. Search or filter below to find where your product sits. Regulation (EU) 2024/2847, Annexes III & IV

The four tiers

What each tier means

Default

Default

Roughly 90% of products. Not listed in Annex III or IV. Conformity is normally self-assessed (internal control) - you still meet all essential requirements, you just sign off yourself.

Important I

Important - Class I

Annex III, Class I. Security-sensitive products. You may self-assess only if you fully apply the relevant harmonised standards/common specifications; otherwise a third-party (notified body) assessment is required.

Important II

Important - Class II

Annex III, Class II. Higher-risk. A third-party conformity assessment (or full quality-assurance / EU cybersecurity certification route) is required - self-assessment alone is not enough.

Critical

Critical

Annex IV. The highest-risk categories. Subject to the strictest route; the Commission can mandate a European cybersecurity certificate before they can be sold.

Tier definitions come from Regulation (EU) 2024/2847 (Annex III for important products, Annex IV for critical products). The Commission may refine these lists through delegated acts.

Representative list - not a legal substitute for the Annexes

This table covers the main named product categories but is not exhaustive. The definitive lists are Annexes III and IV of Regulation (EU) 2024/2847. Products not listed in Annex III or IV fall into the Default tier. The Commission can add or adjust categories through delegated acts.

23 products shown

CRA product class tiers. Columns: product, category, tier, conformity route and annex.
Product categoryGroupTierConformity routeAnnex
Connected white goods (fridges, washers)Consumer electronicsDefaultSelf-assessment (internal control)-
Hard drives & general storage devicesHardwareDefaultSelf-assessment (internal control)-
Mobile / desktop games & productivity appsApplicationsDefaultSelf-assessment (internal control)-
Photo / video editing softwareTypical of the ~90% of products in the default category.ApplicationsDefaultSelf-assessment (internal control)-
Smart speakers (without security functions)Consumer electronicsDefaultSelf-assessment (internal control)-
Container runtime systemsSystem softwareImportant IHarmonised standards → self-assess, else third-partyAnnex III
Identity & access management systemsIdentity & accessImportant IHarmonised standards → self-assess, else third-partyAnnex III
Internet-connected toys (with tracking / interactivity)Smart home / IoTImportant IHarmonised standards → self-assess, else third-partyAnnex III
Network management / configuration systemsNetwork securityImportant IHarmonised standards → self-assess, else third-partyAnnex III
Operating systems (desktop & mobile)System softwareImportant IHarmonised standards → self-assess, else third-partyAnnex III
Password managersIdentity & accessImportant IHarmonised standards → self-assess, else third-partyAnnex III
Personal wearables for health monitoringSmart home / IoTImportant IHarmonised standards → self-assess, else third-partyAnnex III
Public key infrastructure & certificate issuersIdentity & accessImportant IHarmonised standards → self-assess, else third-partyAnnex III
Smart home security devices (locks, cameras, baby monitors, alarms)Smart home / IoTImportant IHarmonised standards → self-assess, else third-partyAnnex III
VPN software / clientsNetwork securityImportant IHarmonised standards → self-assess, else third-partyAnnex III
Web browsersApplicationsImportant IHarmonised standards → self-assess, else third-partyAnnex III
Firewalls (for industrial / professional use)Network securityImportant IIThird-party assessment (notified body)Annex III
Intrusion detection & prevention systemsNetwork securityImportant IIThird-party assessment (notified body)Annex III
Tamper-resistant microcontrollersHardware securityImportant IIThird-party assessment (notified body)Annex III
Tamper-resistant microprocessorsHardware securityImportant IIThird-party assessment (notified body)Annex III
Hardware security modules (HSMs)Hardware securityCriticalStrictest route; EU cybersecurity certificate may be requiredAnnex IV
Smart meter gatewaysCritical infrastructureCriticalStrictest route; EU cybersecurity certificate may be requiredAnnex IV
Smartcards & secure elementsHardware securityCriticalStrictest route; EU cybersecurity certificate may be requiredAnnex IV

This is guidance, not legal advice. Confirm your product's classification against the official Annexes or with a qualified adviser. Not sure if you are in scope?

Sources

  1. [1]Regulation (EU) 2024/2847 (Cyber Resilience Act) - Annex III (important products) and Annex IV (critical products)retrieved 8 Jun 2026
  2. [2]European Commission - CRA legislative summaryretrieved 8 Jun 2026
  3. [3]European Commission - Cyber Resilience Act policy pageretrieved 8 Jun 2026

The CRA Brief

Stay current on CRA deadlines and guidance

We watch Brussels so you don't. Plain-English CRA updates, free.

No spam. Unsubscribe anytime.