Annex III of the EU Cyber Resilience Act lists the 'important' product categories that face stricter conformity assessment before CE marking, split into Class I (lower-risk important) and Class II (higher-risk important). Class I products can keep self-assessment only by fully applying harmonised standards, while Class II products need third-party involvement.
Why Annex III Matters: Three-Tier Product Classification
The CRA classifies products into three risk tiers, each with different conformity assessment requirements:
| Tier | Classification | Conformity Assessment |
|---|---|---|
| Default | Not in Annex III or IV | Self-assessment (Module A) allowed |
| Important, Class I | Annex III Class I | Self-assessment only if harmonised standards are fully applied, otherwise third party |
| Important, Class II | Annex III Class II | Third party always required |
| Critical | Listed in Annex IV | European cybersecurity certification scheme where mandated, otherwise the Class II routes |
The split inside Annex III matters commercially. A Class I product keeps the self-assessment route as long as harmonised standards, common specifications, or a European cybersecurity certification scheme cover all of the applicable essential requirements. A Class II product loses that option outright and must involve a notified body or a certification scheme at assurance level at least substantial.
Annex III Class I - Important Products
Class I covers important products that have significant cybersecurity implications but where existing security standards or market maturity provide some assurance baseline. It is the longer of the two lists, with 19 categories:
- Identity and access management - Identity management systems, privileged access management software and hardware, authentication and access control readers including biometric readers
- Browsers - Standalone and embedded browsers
- Password managers - Software designed primarily to store and manage credentials
- Malware detection software - Products that search for, remove, or quarantine malicious software
- VPN products - Products with a virtual private network function
- Network management systems - Products managing network devices and configurations
- SIEM systems - Security information and event management software
- Boot managers - Secure boot and firmware management tools
- Public key infrastructure - Certificate issuance and PKI software
- Network interfaces - Physical and virtual network interfaces
- Operating systems
- Routers, modems intended for connection to the internet, and switches - Including consumer models
- Microprocessors with security-related functionalities
- Microcontrollers with security-related functionalities
- ASICs and FPGAs with security-related functionalities
- Smart home general purpose virtual assistants
- Smart home products with security functionalities - Smart door locks, security cameras, baby monitors, alarm systems
- Internet-connected toys - Those with social interactive features or location tracking, covered by Directive 2009/48/EC
- Personal wearables - Health monitoring wearables and wearables intended for children
For Class I, the manufacturer keeps the Module A self-assessment route when harmonised standards, common specifications, or a European cybersecurity certification scheme cover all applicable essential requirements. Where that coverage is missing, a notified body route applies.
Annex III Class II - Important Products (Higher Risk)
Class II covers important products where a compromise would have more severe consequences, often affecting critical infrastructure or large populations. The list is short and closed, with four categories:
- Hypervisors and container runtime systems - Products supporting virtualised execution of operating systems and similar environments
- Firewalls, intrusion detection and prevention systems - In hardware or software form
- Tamper-resistant microprocessors
- Tamper-resistant microcontrollers
Anything outside those four is not Class II. Hardware security modules, smart meter gateways, and smartcards or secure elements sit one tier higher, in Annex IV. Routers, modems, switches, and microprocessors or microcontrollers with security-related functionality that are not tamper-resistant sit one tier lower, in Class I.
For Class II, self-assessment is unavailable in every case. The manufacturer uses EU type-examination followed by conformity to type (Module B + C), full quality assurance (Module H), or a European cybersecurity certification scheme at assurance level at least substantial.
How to Determine If Your Product Is Annex III
Determining Annex III classification requires careful analysis:
- Read the Annex III text - The classification is based on product function, not product name. A general-purpose microcontroller is a Default product; the same part shipped with security-related functionality such as secure boot or key storage is Class I, and a tamper-resistant version of it is Class II.
- Check the intended use - The classification often depends on the primary use case and typical deployment environment.
- Review draft delegated acts - The European Commission may add products to Annex III via delegated regulation. Monitor ENISA and Commission publications for updates.
- Seek legal counsel - For borderline cases, the product classification has significant commercial implications (mandatory third-party audit costs, delays to market). Professional legal and technical advice is recommended.
Conformity Assessment for Annex III Products
- Module A: Internal control, available only where harmonised standards, common specifications, or a European cybersecurity certification scheme cover all applicable essential requirements
- Module B + C: Notified body reviews technical documentation (Module B) + manufacturer declares conformity to assessed type (Module C)
- Module H: Full quality assurance - notified body audits the manufacturer's quality management system
- Module B + C
- Module H
- A European cybersecurity certification scheme at assurance level at least substantial
Where a notified body is involved, the CE marking is followed by that body's identification number, and the EU declaration of conformity records the route taken.
Finding an Accredited Notified Body
Notified bodies for CRA conformity assessment are designated by EU member state accreditation bodies and listed in the NANDO database (New Approach Notified and Designated Organisations).
- Ensure they are notified specifically for CRA assessment (designations will expand as September 2026 approaches)
- Check their experience with your product category
- Factor in lead times - notified bodies are expected to face significant demand backlogs before the September 2026 deadline
Early engagement with a notified body is strongly recommended for Annex III manufacturers.
Reading the categories after the Commission guidance
The technical descriptions of the categories are set out in Commission Implementing Regulation (EU) 2025/2392. Commission guidance C(2026) 5252 explains how to apply them.
A product belongs to a category where it has the core functionality of that category, meaning its main features and technical capabilities without which it could not meet its intended purpose. A product has only one core functionality for classification purposes, and it must be identified in the technical documentation.
Additional functions do not change the classification, and merely integrating a listed product does not pull the host product into the category. A smartphone that contains an operating system does not thereby have the core functionality of an operating system.
Where a product substantially exceeds or substantially falls short of a category, it is outside it. Security orchestration, automation and response software generally exceeds the SIEM category, because incident response forms a core part of its capabilities. A log collection and visualisation tool that performs no correlation and provides no actionable security insight falls short of it. This is judged objectively on the product's actual technical characteristics rather than on how it is marketed.
Where the manufacturer also offers modules of an integrated product separately, for separate purchase, licensing or subscription, each module is a standalone product classified on its own core functionality. A suite sold with separately available SIEM, intrusion detection and analytics modules yields a class I product, a class II product and a default-category product respectively.
CVD Portal helps you comply with Annex III automatically.
Public submission portal, 48-hour acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Start your free portalFrequently asked
Is my consumer router covered by Annex III?+
Yes. Annex III Class I lists routers and modems intended for connection to the internet, along with switches, and it draws no line between consumer and professional models. A consumer router is therefore an Important Product in Class I, which means self-assessment survives only where harmonised standards cover all applicable essential requirements. Routers do not become Class II by being sold for industrial use, because Class II is a closed list of four categories that does not include them.
What happens if I self-assess a product that should have been Annex III?+
This would constitute a non-conformity under the CRA. National market surveillance authorities can require product withdrawal, corrective action, or impose fines. The CE marking would be considered improperly affixed, which carries its own legal consequences.
When will the notified body designation process be complete?+
ENISA and national accreditation bodies are working to designate CRA notified bodies before the September 2026 deadline. However, this process is still in progress. Manufacturers of Annex III products should monitor the NANDO database and engage early with candidates.
Do CVD Portal obligations differ for Annex III products?+
The CVD and Article 14 obligations (Articles 13 and 14) apply equally to all in-scope products regardless of Annex III classification. Annex III only affects the conformity assessment route, not the post-market vulnerability handling obligations.
Related CRA Articles
Need a CVD policy that satisfies Annex III?
Download a free CRA-compliant template and deploy it in minutes.