Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04

Important class II products

Annex III, class II lists four categories: hypervisors and container runtime systems; firewalls, intrusion detection and prevention systems; tamper-resistant microprocessors; tamper-resistant microcontrollers. A product whose core function is one of these follows Art. 32(3).

The Annex wording

4 categories
PointCategory, as the Annex words itFunctions here
class II, point 1Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environmentsHypervisor
Container runtime system
class II, point 2Firewalls, intrusion detection and prevention systemsFirewall
Intrusion detection or prevention system
class II, point 3Tamper-resistant microprocessorsTamper-resistant microprocessor
class II, point 4Tamper-resistant microcontrollersTamper-resistant microcontroller

The route this class asks for

Art. 32(3)

EU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least substantial where available (Art. 32(3)); internal control is not among them.

CRA Art. 7(1)Classifying a product as important (Annex III, class I or II)

A product whose core functionality matches a category listed in Annex III is an important product and must follow the stricter conformity routes in Article 32(2) (class I) or 32(3) (class II). Integrating such a component does not by itself move the host product into those routes; the test is the core functionality of the product being placed on the market.

What a notified body or authority asks to see: Classification memo mapping the product's core functionality to Annex III or stating none applies; Reasoning for integrated components that match a category but are not the host product's core function; Record of the conformity route chosen as a result
Where lists usually fall short: Classification made on marketing features rather than core functionality; No review of the classification when the Commission's technical descriptions of the categories are adopted
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 32(3)Conformity assessment for important class II products

For an Annex III class II product, conformity must be shown by module B plus C, module H, or, where available, a European cybersecurity certification scheme at assurance level at least substantial. Internal control is not available.

What a notified body or authority asks to see: EU-type examination certificate, quality system approval or European cybersecurity certificate
Where lists usually fall short: Class II product self-assessed
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer duties

For EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.

What a notified body or authority asks to see: Application to the notified body with the no-parallel-application declaration; EU-type examination certificate and additions; Records of modifications notified to the body
Where lists usually fall short: Type modified after certification without notifying the body
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted. A component with an Annex III function (a cellular or satellite module, a network interface, a secure microcontroller) may be important on its own; integrating it does not in itself make the product it sits in important (Art. 7(1)).