Before you can decide how to demonstrate conformity, you have to know how hard the CRA is going to look at your product. That's classification, and it's the step that quietly determines everything downstream — so it's the one to get right first.
Why classify first
The CRA sorts products into three tiers of scrutiny, and the tier sets your conformity route, how much external involvement you need, and how much lead time that involvement takes. Classify late and you can discover, in the run-up to December 2027, that a product needs a notified body you haven't engaged — a scheduling problem no amount of evidence fixes. Classify first and the rest of the programme has a shape.
Default
The large majority of products are default class — anything not called out in the CRA's Annex III or Annex IV lists. Default products self-assess under Module A internal control: no notified body, though the full technical file and Declaration of Conformity are still required. If your product isn't doing something security-critical for other systems, this is very likely where it sits.
Important (Annex III)
"Important" products are those listed in Annex III — categories whose core function is security-relevant or whose compromise would meaningfully affect other systems. Examples include password managers, VPNs, network management tools, and boot managers. The tier splits in two:
- Class I — can self-assess if the relevant harmonised standards are applied; otherwise a third-party route.
- Class II — the higher-risk items (e.g. firewalls, tamper-resistant microprocessors); a third-party route is required.
Critical (Annex IV)
"Critical" products are the highest-risk categories, listed in Annex IV — for example hardware security modules and smart-meter gateways. These face the strictest route, potentially including mandatory European cybersecurity certification under an EU scheme. If your product is here, third-party involvement is unavoidable and the lead time is long.
How to classify yours
The method is straightforward, even if the edge cases aren't: check your product against the Annex IV list first (critical), then Annex III (important); if it's in neither, it's default. The judgement calls come from products that arguably perform an Annex III function as a feature — a management tool with VPN capability, say — where you have to reason about the product's core purpose. Document the reasoning either way; classification is itself part of the record an authority may ask about. Once you know the class, the route follows, and the conformity pillar covers what it entails.
Frequently asked
What are the CRA product classes?
Three tiers of increasing scrutiny: default (the large majority of products), important (listed in Annex III, split into Class I and the higher-risk Class II), and critical (listed in Annex IV, the highest-risk categories). The class determines the conformity assessment route.
How is a product classified as important or critical?
By whether it falls into the categories the CRA lists in Annex III (important) or Annex IV (critical). Those lists are built around the product’s core function — particularly security-related functionality — and the risk its compromise would pose. If your product isn’t in either list, it is default class.
Why does classification matter so much?
Because it decides whether you can self-assess (default, and important Class I with standards) or must involve a third party (important Class II, critical). The third-party routes take longer and need external bodies, so discovering your class late is costly.