Skip to content
folhas.io
secure by design for connected products· Articles

Articles

Classifying the product under the CRA: the decision that sets the cost of everything else

Default, important class I, important class II or critical. The product's category determines whether conformity is a self-assessment or a notified body, and the difference is measured in tens of thousands of euros and months of calendar.

Published

Before any technical requirement, the CRA forces a framing question: which category does the product fall into? The answer determines the conformity assessment route and, with it, the cost, the timeline and the third-party dependency of the entire project.

The four categories

Default products. Everything not listed in the annexes. The manufacturer self-assesses under internal production control (the equivalent of Module A in classic CE assessments): it applies the essential cybersecurity requirements of Annex I, assembles the technical documentation, signs the EU declaration of conformity and affixes the CE marking. No third parties. The Commission estimates this is the case for around 90% of the products in scope.

Important, class I (Annex III). Nineteen categories, among them: identity and access management systems, browsers, password managers, VPNs, network management systems, SIEM, boot managers, PKI, physical and virtual network interfaces, operating systems, routers and switches, microprocessors and microcontrollers with security functionalities, smart home virtual assistants, smart home products with security functionalities (locks, cameras, alarms, baby monitors), connected toys with social interaction or location features, and health-monitoring wearables.

For class I, self-assessment is only available if a harmonised standard exists and is applied (or a common specification, or European certification) covering the requirements. Without an applicable harmonised standard, a notified body steps in: EU-type examination (Module B+C) or full quality assurance (Module H).

Important, class II (Annex III). Hypervisors and container runtimes, firewalls and intrusion detection/prevention systems, tamper-resistant microprocessors and microcontrollers. Here the notified body is always mandatory, regardless of standards.

Critical (Annex IV). Hardware devices with security boxes, smart meter gateways, smartcards and secure elements. The Commission may require European cybersecurity certification (EUCC, for example).

Diagram: default products go to self-assessment; class I goes to self-assessment with a harmonised standard and to a notified body without one; class II always requires a notified body; critical products may require European certification.
From category to conformity route. The class I fork, with or without a harmonised standard, is where the schedule risk lives.

The most common misreading

The classification applies to the product being placed on the market, not to the components inside it. An agricultural sensor built on a microcontroller with a secure element does not become class I because of it: the one placing the MCU on the market is the MCU manufacturer. The right question is always “what is the main functionality of my product, as Annex III describes it?”. The Commission’s July 2026 guidance devotes an entire section to delimiting these categories, because this is where most framing doubts live.

The case we run into most often: a generic IoT device (environmental monitoring, telemetry, agriculture) is typically a default product. It becomes class I if its function is a security one, such as a surveillance camera, a lock or an alarm.

The schedule trap in the class I categories

For class I without a cited harmonised standard, the cheap route (self-assessment) closes. And the state of the CRA’s harmonised standards is, today, the most fragile point of the whole edifice: the sectoral standards are being drafted under standardisation request M/606, and several will not be cited in the Official Journal much before December 2027. A class I manufacturer who planned for “Module A” may discover late that it needs a notified body, with indicative costs of EUR 15,000–50,000 and 6–12 months of calendar, in a market of notified bodies still being designated.

The sensible way to manage this risk: decide the classification in writing, with reasoning, right at the design stage; track the state of the category’s standards; and have a budgeted plan B with a notified body in case the standard does not arrive in time.

What this means for manufacturers

  1. Classification is a business architecture decision, not a legal detail. A feature added to the product (“and it also works as an alarm”) can change the category and multiply the cost of conformity.
  2. Documenting the reasoning behind the chosen category is part of the technical documentation; it is the first thing a market surveillance authority will want to see.
  3. For default products, the real work is in the essential cybersecurity requirements of Annex I and in the vulnerability handling process. Self-assessment is not an exemption, it is self-accountability.

Sources