Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04

Important class I products

Annex III, class I lists nineteen categories, from identity management systems and browsers to routers, modems and switches, microcontrollers with security-related functionalities, smart home products with security functionalities (locks, security cameras, baby monitors, alarms), internet-connected toys and personal wearables with a health monitoring purpose. A product whose core function is one of these follows Art. 32(2).

The Annex wording

19 categories
PointCategory, as the Annex words itFunctions here
class I, point 1Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readersIdentity management system
Privileged access management software or hardware
Authentication or access control reader
Biometric reader
class I, point 2Standalone and embedded browsersStandalone or embedded browser
class I, point 3Password managersPassword manager
class I, point 4Software that searches for, removes, or quarantines malicious softwareSoftware that searches for, removes or quarantines malicious software
class I, point 5Products with digital elements with the function of virtual private network (VPN)Product with the function of a virtual private network
class I, point 6Network management systemsNetwork management system
class I, point 7Security information and event management (SIEM) systemsSecurity information and event management system
class I, point 8Boot managersBoot manager
class I, point 9Public key infrastructure and digital certificate issuance softwarePublic key infrastructure or digital certificate issuance software
class I, point 10Physical and virtual network interfacesPhysical or virtual network interface
class I, point 11Operating systemsOperating system
class I, point 12Routers, modems intended for the connection to the internet, and switchesRouter
Modem intended for connection to the internet
Switch
class I, point 13Microprocessors with security-related functionalitiesMicroprocessor with security-related functionalities
class I, point 14Microcontrollers with security-related functionalitiesMicrocontroller with security-related functionalities
class I, point 15Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalitiesASIC or FPGA with security-related functionalities
class I, point 16Smart home general purpose virtual assistantsSmart home general purpose virtual assistant
class I, point 17Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systemsSmart door lock
Security camera
Baby monitoring system
Alarm system
class I, point 18Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking featuresInternet-connected toy with social interactive or location tracking features
class I, point 19Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for childrenPersonal wearable with a health monitoring purpose
Personal wearable intended for use by and for children

The route this class asks for

Art. 32(2)

Internal control (module A) only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial are applied in full; otherwise EU-type examination (module B then C) or full quality assurance (module H) (Art. 32(2)).

CRA Art. 7(1)Classifying a product as important (Annex III, class I or II)

A product whose core functionality matches a category listed in Annex III is an important product and must follow the stricter conformity routes in Article 32(2) (class I) or 32(3) (class II). Integrating such a component does not by itself move the host product into those routes; the test is the core functionality of the product being placed on the market.

What a notified body or authority asks to see: Classification memo mapping the product's core functionality to Annex III or stating none applies; Reasoning for integrated components that match a category but are not the host product's core function; Record of the conformity route chosen as a result
Where lists usually fall short: Classification made on marketing features rather than core functionality; No review of the classification when the Commission's technical descriptions of the categories are adopted
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 32(2)Conformity assessment for important class I products

For an Annex III class I product, internal control is available only where the manufacturer has applied in full harmonised standards, common specifications or a certification scheme at assurance level at least substantial. Where it has applied them in part, not at all, or none exist, the product and processes must go, for the uncovered requirements, through module B plus C or module H.

What a notified body or authority asks to see: Record of which harmonised standards were applied and whether in full; Notified body certificate where standards were not fully applied
Where lists usually fall short: Internal control used for a class I product while harmonised standards were only partly applied
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer duties

For EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.

What a notified body or authority asks to see: Application to the notified body with the no-parallel-application declaration; EU-type examination certificate and additions; Records of modifications notified to the body
Where lists usually fall short: Type modified after certification without notifying the body
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted. A component with an Annex III function (a cellular or satellite module, a network interface, a secure microcontroller) may be important on its own; integrating it does not in itself make the product it sits in important (Art. 7(1)).