重要和关键产品类别

Important products 和 critical products 是适用范围内的 CRA 产品,并且其 core functionality 匹配 Annex III 或 Annex IV 中的类别。Commission Implementing Regulation (EU) 2025/2392 提供读取这些类别名称所需的技术说明。

Regulation 2025/2392 技术说明

By 11 December 2025, the Commission shall adopt an implementing act specifying the technical description of the categories of products with digital elements under classes I and II as set out in Annex III and the technical description of the categories of products with digital elements as set out in Annex IV. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 62(2).

Regulation (EU) 2024/2847, Article 7(4)

Regulation 2025/2392 就是该 implementing act。它不替代 Annex III 或 Annex IV。它用技术术语解释类别名称含义,使同一产品在 EU 内被一致分类。

完整技术说明和读取规则见 Regulation 2025/2392 技术说明

Core functionality

Commission FAQ 简明说明了这一点:manufacturer 应查看产品的 core functionality。产品内部的某个功能不够。主要目的不同的产品,不会仅因包含、嵌入或可模拟某个列明功能,就被分类为 important 或 critical product。

产品内部组件

嵌入式浏览器本身不会让新闻 App 变成浏览器产品。

设备内的安全硬件

笔记本电脑内的 secure element 本身不会让笔记本电脑变成 secure-element product。

相似能力

SOAR 软件可以执行类似 SIEM 的任务,但不一定以 SIEM 作为 core functionality。

Important products

Annex III 将 important products 分为 Class I 和 Class II。Class II 是更严格类别。下面列出类别名称;技术说明见 Regulation 2025/2392。

Critical products

Annex IV 比 Annex III 更短。它覆盖安全作用高度集中的产品,例如 tamper-resistant hardware、smart meter gateways、smartcards 和 secure elements。

  1. Hardware Devices with Security Boxes
  2. Smart meter gateways within smart metering systems as defined in Article 2(23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessing
  3. Smartcards or similar devices, including secure elements

类别效果

类别影响用于说明 Annex I 符合性的路径。它不决定产品是否在适用范围内,也不替代 cybersecurity risk assessment。

  • Important Class I products 只有在相关要求由已适用的 harmonised standards、common specifications 或适用 certification scheme 覆盖时,才能使用 internal control;否则需要更严格路径。
  • Important Class II products 使用 Module B plus C、Module H,或适用的 European cybersecurity certification scheme。
  • Critical products 在 Article 8(1) 路径被触发时使用 certification;否则按 Article 32(3) 的 Class II 路径处理。
  • Annex III 中的 important free and open-source software,如果在产品 placed on the market 时公开 Article 31 technical documentation,可以使用 Article 32(1) 路径。

路径细节见 合格评定

Sources