Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04
important class II · product function

Container runtime system

By the Annex wording, a container runtime system points to the important class II class (Annex III, class II, point 1). The route that class asks for: eU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least substantial where available (Art. 32(3)); internal control is not among them.

The Annex wording

Annex III, class II, point 1
Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments

Cited to the held text of Regulation (EU) 2024/2847. By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted.

A line that places here

example

CR-1 | container runtime | EU | businesses | notified body

Check this line

What the finder reads on these lines

8 of the 14 notes

Clauses

7 cited
RegimeClauseApplies when
CRACRA Art. 7(1) Classifying a product as important (Annex III, class I or II)sold in the EU
CRACRA Art. 32(3) Conformity assessment for important class II productssold in the EU
CRACRA Annex VIII Part II Module B: EU-type examination application and manufacturer dutiessold in the EU
CRACRA Art. 13(1) Design, development and production to Annex I Part Isold in the EU
CRACRA Annex I Part I(1) Appropriate level of cybersecurity based on the riskssold in the EU
CaliforniaCalifornia 1798.91.04(a) Reasonable security feature or featuressold in California, as the manufacturer
CaliforniaCalifornia 1798.91.04(b) Authentication outside a local area network: unique password or forced new credentialsold in California, as the manufacturer

The route clause, set out

CRA Art. 32(3)Conformity assessment for important class II products

For an Annex III class II product, conformity must be shown by module B plus C, module H, or, where available, a European cybersecurity certification scheme at assurance level at least substantial. Internal control is not available.

What a notified body or authority asks to see: EU-type examination certificate, quality system approval or European cybersecurity certificate
Where lists usually fall short: Class II product self-assessed
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

Other functions in important products, class ii (annex iii)