What are "important products, class I" under the Cyber Resilience Act?
The class system decides how you demonstrate conformity, not whether the Regulation applies. Every in-scope product has the same essential requirements; class determines the assessment route.
Important products, class I, are the 19 categories listed in Annex III under the class I heading [1]. The list includes categories such as identity and access management software, standalone and embedded browsers, password managers, VPN products, network management systems, operating systems, routers and modems for internet connection, microcontrollers with security functions, and smart home general-purpose virtual assistants [1].
Two cautions about reading that list.
First, the legally binding descriptions are not the shorthand labels. An implementing regulation provides the technical descriptions of each Annex III and Annex IV category, and classification runs on those descriptions, not on whether your marketing copy uses a similar word [2]. "We have a dashboard" does not make you network management software; whether your product matches the description does.
Second, the class attaches to the product's function, not to its importance to you. A tiny open-source password manager and an enterprise identity suite sit in the same class because they perform the same category of function [1].
What class I changes
A default (unclassed) product may assess itself under internal control, known as Module A [3]. A class I product loses unconditional access to that route: it must use EU-type examination plus internal production control (Modules B and C), full quality assurance (Module H), or a European cybersecurity certification scheme at assurance level substantial — unless it applies harmonised standards, common specifications or such a scheme in full, in which case internal control remains available [3].
That "unless" is currently the crux. No harmonised standards for this Regulation have yet been cited in the Official Journal; the standardisation request covers 41 standards with first deliverables expected in Q3 2026 [4]. Until standards you can apply in full exist, a class I product's self-assessment path is not yet open, and the third-party routes require a notified body — which are themselves still being designated, with the Commission targeting sufficient capacity by December 2026 [4] [5].
The practical consequence: if your product is class I, your timeline planning must include either "harmonised standards arrive and we apply them in full" or "we book a notified body", and both of those are queues that form before full application on 11 December 2027 [6] [5].
If you are not on the list
Most software is not: ordinary mobile apps, games, SaaS companion apps and business tools are default products, keep Module A self-assessment, and never need a notified body [3]. Do not talk yourself into a class you are not in.
Check where you stand
The checker matches your product against the binding category descriptions and tells you your class and the routes actually open to you, with citations.
What to do next
Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.
Sources
- Annex III Class I — important products, class I (items 1–19). Annex III Class I; Implementing Regulation (EU) 2025/2392 — EUR-Lex ↩
- Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the Annex III and Annex IV product categories (in force 21 December 2025); the class matcher uses those descriptions, not shorthand labels. Implementing Regulation (EU) 2025/2392; Art. 7(4) — EUR-Lex ↩
- Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIII — EUR-Lex ↩
- No harmonised standards for the CRA have been cited in the Official Journal as of the facts date; the Commission’s standardisation request M/606 covers 41 standards, with the first deliverables expected in Q3 2026. Commission / CEN-CENELEC — EUR-Lex ↩
- Notified bodies for the CRA are being designated; the Commission targets sufficient capacity by December 2026 (best efforts). Commission — EUR-Lex ↩
- The Regulation applies in full from 11 December 2027. Art. 71(2) — EUR-Lex ↩
Related
- Does my product need third-party assessment under the CRA?
Most products, no — default products self-assess under Module A. A notified body enters only for important class I products not applying standards in full, for class II, and for critical products without a certification scheme.
- Is my product an important product class II under the CRA?
Class II is the higher "important" tier — hypervisors, firewalls, tamper-resistant microprocessors and similar security-critical categories — and it removes self-assessment entirely: a notified body or certification scheme is mandatory.
- What goes in a CRA declaration of conformity?
A one-document statement, in the Annex V structure, in which the manufacturer takes sole responsibility that the product meets the essential requirements. A simplified web-linked form exists, and it travels with the product's paperwork for a decade or more.
- Does the CRA require a coordinated vulnerability disclosure policy?
Yes. Every manufacturer must have a coordinated vulnerability disclosure policy in place, a contact address for reports, a single point of contact for users, and a practice of publishing fixed vulnerabilities.
CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 10 September 2026 (Facts v2026.09.4). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.