Important and critical products under the CRA

Last reviewed: 11 September 2026~6 min read

Check these lists before you plan anything else. Whether your product appears in Annex III or Annex IV determines whether you can self-assess or must involve a notified body — and that single fact drives your cost, your timeline and whether December 2027 is comfortable or impossible.

Annex III Class I — important products

Module A self-assessment remains available only where harmonised standards, common specifications or a European cybersecurity certification scheme covering the relevant essential requirements are applied in full. Otherwise: Module B+C or Module H.

  • Identity management systems and privileged access management software and hardware, including authentication and access control readers, biometric readers
  • Standalone and embedded browsers
  • Password managers
  • Software that searches for, removes or quarantines malicious software
  • Products with a virtual private network (VPN) function
  • Network management systems
  • Security information and event management (SIEM) systems
  • Boot managers
  • Public key infrastructure and digital certificate issuance software
  • Physical and virtual network interfaces
  • Operating systems
  • Routers, modems intended for connection to the internet, and switches
  • Microprocessors with security-related functionalities
  • Microcontrollers with security-related functionalities
  • Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
  • Smart home general purpose virtual assistants
  • Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
  • Internet connected toys with social interactive features or location tracking features
  • Personal wearable products with a health monitoring purpose, or intended for use by children

Annex III Class II — important products

Self-assessment is not available. Module B+C, Module H, or a European cybersecurity certification scheme at assurance level substantial.

  • Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
  • Firewalls, intrusion detection and prevention systems
  • Tamper-resistant microprocessors
  • Tamper-resistant microcontrollers

Annex IV — critical products

The Commission may require these to hold a European cybersecurity certificate under a scheme adopted pursuant to the Cybersecurity Act, at assurance level at least substantial.

  • Hardware devices with security boxes
  • Smart meter gateways within smart metering systems, and other devices for advanced security purposes including for secure cryptoprocessing
  • Smartcards or similar devices, including secure elements
Read the lists functionally, not by product name. The categories describe what a product does. A device that happens to include a VPN function is caught by the VPN entry even if you market it as something else. A microcontroller with security-related functionality is caught whether or not security is its selling point. Classify by function, write down the reasoning, and put that reasoning in your technical file.

What to do if you are on a list

  1. Class I: track the harmonised standards work closely. Your self-assessment route depends on standards being cited in the Official Journal in time and on you applying them in full. Build a notified body fallback into your plan now rather than in late 2027.
  2. Class II: contact notified bodies this year. Designation under the CRA began in 2026 and the pool is small relative to the number of in-scope products. Lead times will stretch.
  3. Annex IV: follow the delegated acts. Certification under an EU scheme is a programme of work, not a procurement.

Compare the conformity assessment routes →  ·  Run your product through the checker →

Sources