Important and critical products under the CRA
Check these lists before you plan anything else. Whether your product appears in Annex III or Annex IV determines whether you can self-assess or must involve a notified body — and that single fact drives your cost, your timeline and whether December 2027 is comfortable or impossible.
Annex III Class I — important products
Module A self-assessment remains available only where harmonised standards, common specifications or a European cybersecurity certification scheme covering the relevant essential requirements are applied in full. Otherwise: Module B+C or Module H.
- Identity management systems and privileged access management software and hardware, including authentication and access control readers, biometric readers
- Standalone and embedded browsers
- Password managers
- Software that searches for, removes or quarantines malicious software
- Products with a virtual private network (VPN) function
- Network management systems
- Security information and event management (SIEM) systems
- Boot managers
- Public key infrastructure and digital certificate issuance software
- Physical and virtual network interfaces
- Operating systems
- Routers, modems intended for connection to the internet, and switches
- Microprocessors with security-related functionalities
- Microcontrollers with security-related functionalities
- Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
- Smart home general purpose virtual assistants
- Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
- Internet connected toys with social interactive features or location tracking features
- Personal wearable products with a health monitoring purpose, or intended for use by children
Annex III Class II — important products
Self-assessment is not available. Module B+C, Module H, or a European cybersecurity certification scheme at assurance level substantial.
- Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
- Firewalls, intrusion detection and prevention systems
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Annex IV — critical products
The Commission may require these to hold a European cybersecurity certificate under a scheme adopted pursuant to the Cybersecurity Act, at assurance level at least substantial.
- Hardware devices with security boxes
- Smart meter gateways within smart metering systems, and other devices for advanced security purposes including for secure cryptoprocessing
- Smartcards or similar devices, including secure elements
What to do if you are on a list
- Class I: track the harmonised standards work closely. Your self-assessment route depends on standards being cited in the Official Journal in time and on you applying them in full. Build a notified body fallback into your plan now rather than in late 2027.
- Class II: contact notified bodies this year. Designation under the CRA began in 2026 and the pool is small relative to the number of in-scope products. Lead times will stretch.
- Annex IV: follow the delegated acts. Certification under an EU scheme is a programme of work, not a procurement.
Compare the conformity assessment routes → · Run your product through the checker →
Get told when the requirements change
None of the 35 CRA harmonised standards is published yet. When they land — and when deadlines move — we email you. No more than twice a month.