Context card
CRA product categories: default, important and critical
Which CRA products need a notified body, and how many products fall into the stricter categories?
The short answer
Only products whose core functionality matches a category listed in Annex III (important, classes I and II) or Annex IV (critical) face stricter conformity assessment; everything else in scope is in the default category and may use internal control (Module A). As the Open Regulatory Compliance Working Group puts it: "Most products in scope of the CRA are not classified as Important or Critical." The essential requirements, vulnerability handling and reporting obligations apply to every category.
For: Product compliance managers, product managers, security engineers and technical writers preparing CRA technical documentation
Key points
- Default category: every product with digital elements whose core functionality is not listed in Annex III or IV; conformity assessment by internal control (Module A).
- Important, class I (Annex III, e.g. operating systems, password managers, routers and modems for internet connection): Module A only if harmonised standards, common specifications or a certification scheme at level "substantial" are fully applied; otherwise Module B+C or Module H.
- Important, class II (Annex III, e.g. firewalls, intrusion detection and prevention systems, tamper-resistant microprocessors): Module B+C, Module H or a European cybersecurity certification scheme; self-assessment is not allowed.
- Critical (Annex IV, e.g. hardware devices with security boxes, smart meter gateways, smart cards): a European cybersecurity certificate where a delegated act under Article 8(1) requires one; otherwise the class II procedures.
- The category follows the core functionality, as technically described in Implementing Regulation (EU) 2025/2392; integrating an important component does not make the whole product important.
The context
Three tiers, one set of essential requirements
The Cyber Resilience Act does not grade the obligations of manufacturers; it grades how conformity assessment is done (Article 32). All products with digital elements meet the same essential cybersecurity requirements of Annex I, run vulnerability handling over the support period, report actively exploited vulnerabilities and severe incidents, draw up a declaration of conformity and affix the CE marking. What changes with the category is who checks.
| Category | Where listed | Conformity assessment |
|---|---|---|
| Default | not listed | internal control (Module A) |
| Important, class I | Annex III | Module A with fully applied harmonised standards, common specifications or certification; otherwise Module B+C or H |
| Important, class II | Annex III | Module B+C, Module H or European cybersecurity certification |
| Critical | Annex IV | European cybersecurity certificate where a delegated act requires it; otherwise as class II |
For class II and critical products, and for class I without fully applied standards, a notified body is involved. Free and open-source software in classes I and II may use Module A if its technical documentation is public (Article 32(5)).
Most products are default
Annexes III and IV are closed lists of product categories; anything not on them is default. The Open Regulatory Compliance Working Group (ORC WG), which gave technical input on the category descriptions to the Commission, states it plainly: "Most products in scope of the CRA are not classified as Important or Critical." Default does not mean exempt: it means self-assessment against the same requirements, with the burden of proof on the manufacturer.
Core functionality decides
Implementing Regulation (EU) 2025/2392 gives the technical descriptions of the important and critical categories. A product belongs to a category when its core functionality — the function without which it would not serve its intended purpose — matches the description. Ancillary functions do not change the category, and a product that merely contains an important component (a device running an operating system, for example) is not itself an operating system.
For documentation
The technical documentation names the product's core functionality and the category it leads to, with the reasoning. That one statement decides the conformity assessment route — and whether Module A needs the presumption of conformity of fully applied standards. Naming a category never shows conformity by itself.
Questions readers ask next
- Does the default category have lighter obligations?
- No. The essential requirements, vulnerability handling and reporting obligations are the same for every category; only the conformity assessment procedure differs.
- Are critical products always certified?
- Only where the Commission has adopted a delegated act under Article 8(1) requiring a European cybersecurity certificate. Until then, critical products follow the procedures for important class II products.
Sources
- Regulation (EU) 2024/2847 (Cyber Resilience Act) — Official Journal of the European Union, 20 November 2024
- Commission Implementing Regulation (EU) 2025/2392 on the technical description of important and critical products with digital elements — Official Journal of the European Union, 28 November 2025
- CRA Hub: product definitions (README) — Open Regulatory Compliance Working Group (ORC WG), 2 October 2026
Review log and changes
Every context card is checked against its sources before it is published, and again whenever it changes; the date under the byline is the last review. Corrections (something was wrong) and additions (something was missing) are logged below with date and time (Berlin time). Typos, formatting and link fixes are not listed.
Reviewed
No corrections or additions since publication.