Important class II products
Annex III, class II lists four categories: hypervisors and container runtime systems; firewalls, intrusion detection and prevention systems; tamper-resistant microprocessors; tamper-resistant microcontrollers. A product whose core function is one of these follows Art. 32(3).
The Annex wording
4 categories| Point | Category, as the Annex words it | Functions here |
|---|---|---|
| class II, point 1 | Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments | Hypervisor Container runtime system |
| class II, point 2 | Firewalls, intrusion detection and prevention systems | Firewall Intrusion detection or prevention system |
| class II, point 3 | Tamper-resistant microprocessors | Tamper-resistant microprocessor |
| class II, point 4 | Tamper-resistant microcontrollers | Tamper-resistant microcontroller |
The route this class asks for
Art. 32(3)EU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least substantial where available (Art. 32(3)); internal control is not among them.
CRA Art. 7(1)Classifying a product as important (Annex III, class I or II)A product whose core functionality matches a category listed in Annex III is an important product and must follow the stricter conformity routes in Article 32(2) (class I) or 32(3) (class II). Integrating such a component does not by itself move the host product into those routes; the test is the core functionality of the product being placed on the market.
CRA Art. 32(3)Conformity assessment for important class II productsFor an Annex III class II product, conformity must be shown by module B plus C, module H, or, where available, a European cybersecurity certification scheme at assurance level at least substantial. Internal control is not available.
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer dutiesFor EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.
By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted. A component with an Annex III function (a cellular or satellite module, a network interface, a secure microcontroller) may be important on its own; integrating it does not in itself make the product it sits in important (Art. 7(1)).