Important and Critical Product Categories
Important and critical products are in-scope CRA products whose core functionality matches a category in Annex III or Annex IV. Commission Implementing Regulation (EU) 2025/2392 gives the technical descriptions used to read those category names.
Regulation 2025/2392 technical descriptions
By 11 December 2025, the Commission shall adopt an implementing act specifying the technical description of the categories of products with digital elements under classes I and II as set out in Annex III and the technical description of the categories of products with digital elements as set out in Annex IV. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 62(2).
Regulation (EU) 2024/2847, Article 7(4)
Regulation 2025/2392 is that implementing act. It does not replace Annex III or Annex IV. It explains what the category names mean in technical terms, so the same product is classified consistently across the EU.
The full technical descriptions and reading rules are explained in Regulation 2025/2392 Technical Descriptions.
Core functionality
The Commission FAQ states the point simply: the manufacturer should look at the product's core functionality. A feature inside the product is not enough. A product with another main purpose is not classified as important or critical merely because it includes, embeds, or can mimic a listed function.
Component inside a product
An embedded browser does not by itself make a news app a browser product.
Security hardware inside a device
A secure element inside a laptop does not by itself make the laptop a secure-element product.
Similar capability
SOAR software can perform SIEM-like tasks without having SIEM as its core functionality.
Important products
Annex III divides important products into Class I and Class II. Class II is the stricter class. The list below gives the category names; the technical descriptions are in Regulation 2025/2392.
Annex III lists these Class I categories:
- Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
- Standalone and embedded browsers
- Password managers
- Software that searches for, removes, or quarantines malicious software
- Products with digital elements with the function of virtual private network (VPN)
- Network management systems
- Security information and event management (SIEM) systems
- Boot managers
- Public key infrastructure and digital certificate issuance software
- Physical and virtual network interfaces
- Operating systems
- Routers, modems intended for the connection to the internet, and switches
- Microprocessors with security-related functionalities
- Microcontrollers with security-related functionalities
- Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
- Smart home general purpose virtual assistants
- Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
- Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features
- Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) 2017/746 of the European Parliament and of the Council do not apply, or personal wearable products that are intended for the use by and for children
Annex III lists these Class II categories:
- Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
- Firewalls, intrusion detection and prevention systems
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Critical products
Annex IV is shorter than Annex III. It covers products whose security role is especially concentrated, such as tamper-resistant hardware, smart meter gateways, smartcards, and secure elements.
- Hardware Devices with Security Boxes
- Smart meter gateways within smart metering systems as defined in Article 2(23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessing
- Smartcards or similar devices, including secure elements
Category effect
The category affects the route used to show conformity with Annex I. It does not decide whether the product is in scope, and it does not replace the cybersecurity risk assessment.
- Important Class I products can use internal control only for requirements covered by applied harmonised standards, common specifications, or an applicable certification scheme; otherwise a stricter route is needed.
- Important Class II products use Module B plus C, Module H, or an applicable European cybersecurity certification scheme.
- Critical products use certification under Article 8(1) when that route is triggered; otherwise they follow the Class II routes in Article 32(3).
- Important free and open-source software in Annex III can use the Article 32(1) routes if the Article 31 technical documentation is public when the product is placed on the market.
The route details are explained in Conformity Assessment.