Product Classification
CRA classification is the category assigned to an in-scope product with digital elements. A product stays in the default category unless its core functionality matches an Annex III important category or an Annex IV critical category.
Classification outcomes
Classification comes after scope. First ask whether the product is a product with digital elements made available on the EU market and not excluded by Article 2. Then classify the product by the CRA category that matches its core functionality.
Default category
The residual category for in-scope products that do not have the core functionality of an Annex III or Annex IV category.
Important Class I
Annex III Class I categories are important products. The CRA keeps them separate from Class II.
Important Class II
Annex III Class II categories are important products. They move to a stricter class after classification.
Critical products
Annex IV categories are critical products. They are a separate list from Annex III important products.
Core functionality
Products with digital elements which have the core functionality of a product category set out in Annex III shall be considered to be important products with digital elements and shall be subject to the conformity assessment procedures referred to in Article 32(2) and (3). The integration of a product with digital elements which has the core functionality of a product category set out in Annex III shall not in itself render the product in which it is integrated subject to the conformity assessment procedures referred to in Article 32(2) and (3).
Regulation (EU) 2024/2847, Article 7(1)
Articles 7 and 8 use the same idea: the product must have the core functionality of a listed category. The assessment is about what the product as a whole is placed on the market to do. It is not enough that the product includes a feature, library, semiconductor, or module that could itself fit a listed category.
This cuts both ways. Extra functions do not stop a product from being important if its main function still matches an Annex III category. A router can include firewall functions and still be classified by its router core functionality. But a product with a different main purpose does not become a listed product merely because it can perform some of the same tasks.
Integrated components
A news app does not become a browser product just because it embeds a browser component. A laptop does not become a secure-element product just because it contains a secure element.
Overlapping functions
SOAR software can have SIEM-like capabilities, but the Commission FAQ treats SOAR as generally outside the SIEM category when its core functionality is different.
Annex III important products
Annex III lists important products with digital elements and divides them into Class I and Class II. Regulation 2025/2392 gives the technical description for each listed category. The result is a category decision, not a general ranking of every cybersecurity risk.
Class I
Important products that may still use internal control when the relevant standards, common specifications, or certification route is applied.
Class II
Important products that must use stricter conformity routes.
Annex IV critical products
Annex IV lists critical products with digital elements. The list is narrower than Annex III and focuses on products with security-box, smart-meter-gateway, secure cryptoprocessing, smartcard, or secure element functions. Article 8 can make certification relevant for these products by delegated act.
Technical descriptions reference
Commission Implementing Regulation (EU) 2025/2392 supplies technical descriptions for the Annex III and Annex IV categories; the detailed reading rules and full descriptions are explained in Regulation 2025/2392 Technical Descriptions.
Classification and conformity
Classification does not prove Annex I conformity. It tells the manufacturer which Article 32 route may be available or required. The routes themselves are explained in Conformity Assessment.
Classification and risk assessment
The Commission FAQ separates classification from the manufacturer's cybersecurity risk assessment. A default product, an important product, and a critical product all still need risk-based application of the Annex I requirements.
Two products can share a classification and still need different security measures because their intended purpose, foreseeable use, and conditions of use differ. Classification selects the conformity route; the risk assessment explains how the product and the manufacturer's processes meet the CRA requirements for that product.