CEMarque

What are "important products, class II" under the Cyber Resilience Act?

Last verified 19 September 2026 · Facts v2026.09.4

Class II is the smaller, more serious tier of important products: the four categories listed in Annex III under the class II heading [1]. The categories cover hypervisors and container runtime systems supporting virtualised execution, firewalls and intrusion detection or prevention systems, tamper-resistant microprocessors, and tamper-resistant microcontrollers [1].

As with class I, the binding text is the technical description in the implementing regulation, not the shorthand label — check your product against the description before concluding anything [2].

What class II changes

The route menu narrows to third-party involvement only: a class II product must use EU-type examination plus internal production control (Modules B and C), full quality assurance (Module H), or a European cybersecurity certification scheme at assurance level substantial [3]. There is no self-assessment fallback for class II — applying harmonised standards does not reopen internal control the way it does for class I [3].

That makes the notified-body question unavoidable. Notified bodies for this Regulation are still being designated, with the Commission targeting sufficient capacity by December 2026 on a best-efforts basis [4]. If your product is class II, the sequencing risk is concrete: full application arrives on 11 December 2027, assessment capacity is being built out through the preceding year, and the queue will be shared with every other class II and critical product in the market [5] [4].

The cost of being wrong in either direction

Misclassifying downward — treating a class II product as default and self-assessing — produces a product on the market without the required assessment, which is the kind of breach that sits in the highest fine band, up to EUR 15,000,000 or 2.5% of worldwide turnover [6].

Misclassifying upward is cheaper but still expensive: you would book third-party assessment you do not need. Most software is not class II; the categories are deliberately narrow security infrastructure [1]. A web app with a login page is not an intrusion prevention system, and a container-using product is not a container runtime.

Boundary cases worth naming

The genuinely hard calls cluster at two boundaries. Products that contain a class II function — a NAS with a built-in firewall, an endpoint agent with IDS-like detection — need the description-level reading: classification follows what the product is, per the binding descriptions, and the checker walks that boundary with you [2]. And virtualisation is specific: the category is about providing the virtualised execution environment, not about shipping your app in a container [1].

Check where you stand

The checker matches your product against the binding category descriptions [2], tells you which routes are open, and cites the exact text for each conclusion.

What to do next

Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.

Check my product

Sources

  1. Annex III Class II — important products, class II (items 1–4). Annex III Class II; Implementing Regulation (EU) 2025/2392EUR-Lex
  2. Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the Annex III and Annex IV product categories (in force 21 December 2025); the class matcher uses those descriptions, not shorthand labels. Implementing Regulation (EU) 2025/2392; Art. 7(4)EUR-Lex
  3. Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIIIEUR-Lex
  4. Notified bodies for the CRA are being designated; the Commission targets sufficient capacity by December 2026 (best efforts). CommissionEUR-Lex
  5. The Regulation applies in full from 11 December 2027. Art. 71(2)EUR-Lex
  6. Fines up to EUR 15,000,000 or 2.5% of total worldwide annual turnover, whichever is higher (essential requirements in Annex I; obligations in Arts. 13 and 14); up to EUR 10,000,000 or 2% (other listed obligations, incl. Arts. 18–23, 28, 30, 31, 32); up to EUR 5,000,000 or 1% (incorrect, incomplete or misleading information to notified bodies or authorities). Microenterprises and small enterprises are not fined for missing the 24-hour early-warning deadline; open-source software stewards are not subject to fines. Art. 64(2)–(4), (10)EUR-Lex

Related

CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 10 September 2026 (Facts v2026.09.4). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.