Important class I products
Annex III, class I lists nineteen categories, from identity management systems and browsers to routers, modems and switches, microcontrollers with security-related functionalities, smart home products with security functionalities (locks, security cameras, baby monitors, alarms), internet-connected toys and personal wearables with a health monitoring purpose. A product whose core function is one of these follows Art. 32(2).
The Annex wording
19 categories| Point | Category, as the Annex words it | Functions here |
|---|---|---|
| class I, point 1 | Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers | Identity management system Privileged access management software or hardware Authentication or access control reader Biometric reader |
| class I, point 2 | Standalone and embedded browsers | Standalone or embedded browser |
| class I, point 3 | Password managers | Password manager |
| class I, point 4 | Software that searches for, removes, or quarantines malicious software | Software that searches for, removes or quarantines malicious software |
| class I, point 5 | Products with digital elements with the function of virtual private network (VPN) | Product with the function of a virtual private network |
| class I, point 6 | Network management systems | Network management system |
| class I, point 7 | Security information and event management (SIEM) systems | Security information and event management system |
| class I, point 8 | Boot managers | Boot manager |
| class I, point 9 | Public key infrastructure and digital certificate issuance software | Public key infrastructure or digital certificate issuance software |
| class I, point 10 | Physical and virtual network interfaces | Physical or virtual network interface |
| class I, point 11 | Operating systems | Operating system |
| class I, point 12 | Routers, modems intended for the connection to the internet, and switches | Router Modem intended for connection to the internet Switch |
| class I, point 13 | Microprocessors with security-related functionalities | Microprocessor with security-related functionalities |
| class I, point 14 | Microcontrollers with security-related functionalities | Microcontroller with security-related functionalities |
| class I, point 15 | Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities | ASIC or FPGA with security-related functionalities |
| class I, point 16 | Smart home general purpose virtual assistants | Smart home general purpose virtual assistant |
| class I, point 17 | Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems | Smart door lock Security camera Baby monitoring system Alarm system |
| class I, point 18 | Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features | Internet-connected toy with social interactive or location tracking features |
| class I, point 19 | Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children | Personal wearable with a health monitoring purpose Personal wearable intended for use by and for children |
The route this class asks for
Art. 32(2)Internal control (module A) only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial are applied in full; otherwise EU-type examination (module B then C) or full quality assurance (module H) (Art. 32(2)).
CRA Art. 7(1)Classifying a product as important (Annex III, class I or II)A product whose core functionality matches a category listed in Annex III is an important product and must follow the stricter conformity routes in Article 32(2) (class I) or 32(3) (class II). Integrating such a component does not by itself move the host product into those routes; the test is the core functionality of the product being placed on the market.
CRA Art. 32(2)Conformity assessment for important class I productsFor an Annex III class I product, internal control is available only where the manufacturer has applied in full harmonised standards, common specifications or a certification scheme at assurance level at least substantial. Where it has applied them in part, not at all, or none exist, the product and processes must go, for the uncovered requirements, through module B plus C or module H.
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer dutiesFor EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.
By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted. A component with an Annex III function (a cellular or satellite module, a network interface, a secure microcontroller) may be important on its own; integrating it does not in itself make the product it sits in important (Art. 7(1)).