The full CRA Annex III and Annex IV product list, and the four entries people get wrong
Every important and critical product category under the Cyber Resilience Act, quoted from the Official Journal, with the misreadings that change a conformity route.
The category text below is quoted from Annexes III and IV of Regulation (EU) 2024/2847, consolidated EN text on EUR-Lex, CELEX 32024R2847. Verify against the official text before relying on it for a conformity decision. This is not legal advice.
Classification is the first question in a CRA project and the one that decides the cost of everything after it. Your class sets your conformity route, and your conformity route decides whether you can sign your own Declaration of Conformity or whether you are booking a notified body. Get it wrong in the optimistic direction and you find out late.
It is also the question the freely available sources handle worst. Checking one product category across three CRA information sites recently produced three different answers, and two were wrong in a way that would have changed the conformity route. The usual cause is a summary written from the Commission's 2022 proposal and never updated to the adopted text. So here is the adopted text in full, followed by the specific places people slip.
The four buckets, and what each one costs you
| Bucket | Where it is defined | What it means for conformity |
|---|---|---|
| Default | Anything not named in Annex III or Annex IV | Self-assessment by the manufacturer. Most products land here. |
| Important, Class I | Annex III, Class I, 19 categories | Self-assessment is available where harmonised standards are applied. Without them the route leans toward a third party. |
| Important, Class II | Annex III, Class II, 4 categories | A notified body is involved. This is the jump that changes your budget. |
| Critical | Annex IV, 3 categories | The strictest treatment, which can extend to European cybersecurity certification. |
The practical consequence is that the line between Class I and Class II matters far more than the line between default and Class I. Moving from default to Class I is a documentation question. Moving from Class I to Class II is a procurement question, with a lead time and an invoice attached.
Annex III, Class I: the 19 categories
- Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
- Standalone and embedded browsers
- Password managers
- Software that searches for, removes, or quarantines malicious software
- Products with digital elements with the function of virtual private network (VPN)
- Network management systems
- Security information and event management (SIEM) systems
- Boot managers
- Public key infrastructure and digital certificate issuance software
- Physical and virtual network interfaces
- Operating systems
- Routers, modems intended for the connection to the internet, and switches
- Microprocessors with security-related functionalities
- Microcontrollers with security-related functionalities
- Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
- Smart home general purpose virtual assistants
- Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
- Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features
- Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) 2017/746 do not apply, or personal wearable products that are intended for the use by and for children
Annex III, Class II: the closed list of four
- Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
- Firewalls, intrusion detection and prevention systems
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Four entries. That is the whole class. If your product is not one of those four things, it is not Class II, whatever a summary elsewhere says.
Annex IV: critical products
- Hardware Devices with Security Boxes
- Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing
- Smartcards or similar devices, including secure elements
The four entries people get wrong
Firewalls are Class II, with no industrial-use qualifier
You will see it written that Class II firewalls are only those intended for industrial use, and that general-purpose firewalls are Class I. That qualifier existed in the Commission's 2022 proposal and did not survive into the adopted Regulation. Annex III Class II item 2 reads, in full: firewalls, intrusion detection and prevention systems. There is no restriction on the market it serves. If you sell a firewall into the EU, plan for a notified body.
Operating systems are Class I, not Class II
Operating systems appear at Annex III Class I item 11, and are named nowhere in Class II. At least one widely read summary places them in Class II, which would push an OS vendor into a notified body route it does not need and a budget it does not have to spend.
Processors turn on a security characteristic, not on being a processor
Items 13 to 15 cover microprocessors, microcontrollers, ASICs and FPGAs with security-related functionalities. A general-purpose microcontroller without them sits on the default path. The tamper-resistant versions of the same components appear separately in Class II. The same silicon can therefore land in three different buckets depending on one attribute, which makes this an attribute question rather than a part-number lookup. Write down the reasoning either way.
Health wearables are carved out where MDR or IVDR applies
Item 19 covers personal wearables with a health monitoring purpose only where Regulation (EU) 2017/745 or (EU) 2017/746 do not apply. A product inside the medical device or in vitro diagnostic regimes is outside CRA scope entirely, not merely in a different class. The second limb of item 19 is separate and carries no health condition: wearables intended for use by and for children.
The three that are genuinely open
These are not errors. They are judgment calls, and an honest classification records the reasoning rather than asserting a verdict.
- Item 17 says smart home products with security functionalities, then gives examples: smart door locks, security cameras, baby monitoring systems, alarm systems. The examples illustrate, they do not define. Whether a doorbell camera or a pet camera reads as a security camera for this purpose is a reasoned call, and one a market surveillance authority could take differently from you.
- Item 18 has two qualifying conditions. A connected toy is Class I only where it has social interactive features, such as speaking or filming, or location tracking. A connected toy with neither sits on the default path.
- Bare hardware sold so a customer can install their own firewall software is not obviously a firewall. The same unit shipped with firewall software on it clearly is. The line between them is a commercial description as much as a technical one.
What your class actually changes
The essential requirements in Annex I are the same whatever your class. What changes is who has to be satisfied that you met them, and what that costs. A default or self-assessable Class I product is a documentation project you can run yourself. A Class II product is a project with an external dependency, and the lead time is the part that hurts as December 2027 gets closer.
Which is why the classification question is worth settling now rather than in the quarter you planned to ship. If your honest answer today is a shrug, that is the finding.
Our free applicability check walks the Annex III and IV decision tree and returns a class, the conformity route it implies, and the clause it came from. No signup. Where your product sits on one of the open questions above, it says so rather than pretending otherwise.