Intrusion detection or prevention system
By the Annex wording, an intrusion detection or prevention system points to the important class II class (Annex III, class II, point 2). The route that class asks for: eU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least substantial where available (Art. 32(3)); internal control is not among them.
The Annex wording
Annex III, class II, point 2Firewalls, intrusion detection and prevention systems
Cited to the held text of Regulation (EU) 2024/2847. By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted.
A line that places here
exampleIDS-4 | intrusion detection system | EU | businesses | notified body
What the finder reads on these lines
8 of the 14 notes- 2. Important class II function with self-assessment, or no notified body, planned: Which Art. 32(3) procedure will this product go through, and with which notified body?
- 4. No process to report an actively exploited vulnerability or a severe incident: Who notifies the CSIRT and ENISA within 24 hours when this product carries an actively exploited vulnerability, and where is the process written down?
- 5. No support period stated, or under five years with no reason recorded: What is the support period, how was it set, and where is its end date shown to buyers?
- 7. No published vulnerability contact: Where does a researcher report a vulnerability in this product, and is that address published?
- 8. No security update mechanism, or unsigned updates: How does a security fix reach units already sold, and how does the device check the update is genuine?
- 9. No software bill of materials kept, or partial: Where is the machine-readable SBOM for this product, and does it cover at least the top-level dependencies?
- 11. Manufacturer outside the EU with no authorised representative: Will the company appoint an EU authorised representative, and if not, which importer holds the documentation for the market surveillance authorities?
- 12. Still on sale for 11 December 2027 with no conformity route planned: Which route will this product take, and by when, so units made available from 11 December 2027 carry the declaration?
Clauses
13 cited| Regime | Clause | Applies when |
|---|---|---|
| CRA | CRA Art. 7(1) Classifying a product as important (Annex III, class I or II) | sold in the EU |
| CRA | CRA Art. 32(3) Conformity assessment for important class II products | sold in the EU |
| CRA | CRA Annex VIII Part II Module B: EU-type examination application and manufacturer duties | sold in the EU |
| CRA | CRA Art. 13(1) Design, development and production to Annex I Part I | sold in the EU |
| CRA | CRA Annex I Part I(1) Appropriate level of cybersecurity based on the risks | sold in the EU |
| UK PSTI | UK PSTI R.1 No universal default passwords | sold to UK consumers |
| UK PSTI | UK PSTI R.2 Published point of contact for security issues | sold to UK consumers |
| UK PSTI | UK PSTI R.3 Published defined support period | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.1 (provision group) No universal default passwords | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilities | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.3 (provision group) Keep software updated | sold to UK consumers |
| California | California 1798.91.04(a) Reasonable security feature or features | sold in California, as the manufacturer |
| California | California 1798.91.04(b) Authentication outside a local area network: unique password or forced new credential | sold in California, as the manufacturer |
The route clause, set out
CRA Art. 32(3)Conformity assessment for important class II productsFor an Annex III class II product, conformity must be shown by module B plus C, module H, or, where available, a European cybersecurity certification scheme at assurance level at least substantial. Internal control is not available.