Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04
important class I · product function

Privileged access management software or hardware

By the Annex wording, a privileged access management software or hardware points to the important class I class (Annex III, class I, point 1). The route that class asks for: internal control (module A) only where harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least substantial are applied in full; otherwise EU-type examination (module B then C) or full quality assurance (module H) (Art. 32(2)).

The Annex wording

Annex III, class I, point 1
Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers

Cited to the held text of Regulation (EU) 2024/2847. By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted.

A line that places here

example

PAM-2 | privileged access management | EU, UK | consumers | harmonised standard

Check this line

What the finder reads on these lines

11 of the 14 notes

Clauses

7 cited
RegimeClauseApplies when
CRACRA Art. 7(1) Classifying a product as important (Annex III, class I or II)sold in the EU
CRACRA Art. 32(2) Conformity assessment for important class I productssold in the EU
CRACRA Annex VIII Part II Module B: EU-type examination application and manufacturer dutiessold in the EU
CRACRA Art. 13(1) Design, development and production to Annex I Part Isold in the EU
CRACRA Annex I Part I(1) Appropriate level of cybersecurity based on the riskssold in the EU
CaliforniaCalifornia 1798.91.04(a) Reasonable security feature or featuressold in California, as the manufacturer
CaliforniaCalifornia 1798.91.04(b) Authentication outside a local area network: unique password or forced new credentialsold in California, as the manufacturer

The route clause, set out

CRA Art. 32(2)Conformity assessment for important class I products

For an Annex III class I product, internal control is available only where the manufacturer has applied in full harmonised standards, common specifications or a certification scheme at assurance level at least substantial. Where it has applied them in part, not at all, or none exist, the product and processes must go, for the uncovered requirements, through module B plus C or module H.

What a notified body or authority asks to see: Record of which harmonised standards were applied and whether in full; Notified body certificate where standards were not fully applied
Where lists usually fall short: Internal control used for a class I product while harmonised standards were only partly applied
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

Other functions in important products, class i (annex iii)