← CRA Glossary
CRA Legal Terms

Important Product Class II

Important Product Class II is the highest risk tier under the EU Cyber Resilience Act's product classification system, covering products with digital elements whose compromise could have severe or widespread impact. Class II products - including industrial control systems, medical devices, and critical infrastructure components - face mandatory third-party conformity assessment.

Important Product Class II is the highest risk tier under the EU Cyber Resilience Act's product classification system, covering products with digital elements whose compromise could have severe or widespread impact. Class II products - including industrial control systems, medical devices, and critical infrastructure components - face mandatory third-party conformity assessment.

CRA Legal Terms

What Is Important Product Class II?

Important Product Class II is the highest risk classification in the EU Cyber Resilience Act, reserved for products with digital elements that present a particularly significant cybersecurity risk - products whose compromise could have severe, widespread, or safety-critical consequences. Annex III Part II lists the specific categories, which include: operating systems for servers and industrial systems, hypervisors, industrial automation and control systems (ICS/SCADA), industrial IoT, programmable logic controllers (PLCs), safety devices for industrial environments, and smart meter gateways. These are products embedded in critical infrastructure or safety systems where a security failure could affect public safety or essential services.

CRA reference:Annex III Part II, Article 6(3)

Mandatory Third-Party Conformity Assessment for Class II

Unlike Class I, Important Class II manufacturers cannot self-certify regardless of whether a harmonised standard exists. Article 6(3) of the CRA requires Class II manufacturers to have their products assessed by a notified body or to obtain a European cybersecurity certificate under the EU Cybersecurity Act. This mandatory third-party involvement reflects the regulatory determination that the stakes of non-compliance for these products are too high to rely on manufacturer self-assessment. Notified bodies must be accredited for the relevant product category and are listed in the EU NANDO database. Manufacturers should engage a notified body early in their development cycle, as assessment timelines can be significant.

CRA reference:Article 6(3), Article 24(2), Annex VIII

Compliance Requirements for Class II Manufacturers

Class II manufacturers must satisfy all CRA essential requirements and additionally produce comprehensive technical documentation demonstrating compliance with each Annex I requirement. The notified body assessment evaluates both the product's technical security properties and the manufacturer's quality management system and processes. Class II manufacturers must also: maintain the technical file for ten years after last market placement (the standard period under most EU product regulations); immediately notify ENISA and market surveillance authorities of any actively exploited vulnerability; and ensure their CVD process meets the highest standards of responsiveness and transparency. Post-market surveillance by authorities will focus disproportionately on Class II products.

CRA reference:Article 6(3), Article 14, Article 23, Annex III Part II

Common Mistakes

The most damaging error for Class II manufacturers is underestimating the lead time required for notified body assessment. Assessment processes for complex industrial systems can take many months; manufacturers who begin the process only weeks before the compliance deadline will face non-compliance by default. A second error is treating the Class II assessment as a one-time event: any significant change to the product may require reassessment. Manufacturers should also avoid assuming that compliance with other sector-specific regulations (such as the EU Medical Devices Regulation) automatically satisfies CRA Class II requirements - the two regulatory regimes have different scopes and requirements.

CRA reference:Annex III Part II, Article 24(2)

CVD Portal makes Important Product Class II compliance straightforward.

Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.

Start your free portal

Frequently asked

Which products are classified as Important Class II under the CRA?+

Annex III Part II lists Important Class II product categories including: server operating systems, industrial operating systems, hypervisors and container runtimes, programmable logic controllers (PLCs), industrial IoT devices, safety-certified industrial components, smart meter gateways, and industrial firewalls and security systems. The European Commission may expand this list via delegated acts as the threat landscape evolves. Manufacturers should monitor Annex III updates closely.

Can a Class II manufacturer avoid notified body assessment?+

No. Article 6(3) of the CRA makes notified body involvement (or a European cybersecurity certificate) mandatory for all Class II products. There is no self-certification route for Class II, regardless of whether harmonised standards exist. This reflects the legislative determination that the risks associated with Class II product compromise are too severe to permit manufacturer self-assessment. Manufacturers who affix the CE marking without completing the required third-party assessment are committing a serious regulatory violation.

Does the CRA apply to Class II products that are already regulated under other EU law?+

The CRA includes specific provisions for products covered by other sector-specific EU legislation - for example, medical devices (EU MDR) and civil aviation components. Where sector legislation provides equivalent cybersecurity requirements and conformity assessment, the more specific legislation may take precedence over the CRA for those specific requirements. However, manufacturers should not assume automatic exemption: they should map both regulatory frameworks and identify any gaps where the CRA applies supplementary requirements.

Related terms

Important Product Class IImportant Product Class I is the lower tier of the CRA's two-tier classification for products with digital elements that present a significant cybersecurity risk. Class I products face an elevated conformity assessment pathway compared to Default Class products, but less stringent than Class II. Examples include identity management software and general-purpose browsers.Default Class Product (CRA)Default Class products are the baseline category under the EU Cyber Resilience Act - products with digital elements that do not fall into the Important Class I or Class II elevated risk classifications. The vast majority of consumer and commercial connected products are Default Class. Manufacturers may self-certify conformity through an internal control procedure.Annex III Important Product ClassificationAnnex III of the EU Cyber Resilience Act lists product categories classified as 'Important' (Class I or Class II) or 'Critical', which are subject to stricter conformity assessment requirements than the Default class. Most products not listed in Annex III fall into the Default class and can self-certify.Conformity AssessmentConformity assessment is the process by which a manufacturer demonstrates that its product meets the CRA's essential cybersecurity requirements. The process required depends on the product's classification: Default and Class I products can self-assess; Class II and Critical products require third-party assessment by a notified body.Conformity Assessment ProcedureA Conformity Assessment Procedure is the formal process by which a manufacturer demonstrates that a product meets applicable EU essential requirements before affixing the CE mark and placing it on the market. Under the Cyber Resilience Act, the required procedure depends on the product's risk classification.EU Type-ExaminationEU Type-Examination is a conformity assessment procedure in which a Notified Body examines a representative sample (the 'type') of a product and issues a certificate confirming it meets the applicable EU essential requirements. It is one of the mandatory routes for Important Class II products under the Cyber Resilience Act.

Sector checklists covering Important Product Class II

Industrial Controllers & PLCsIndustrial controllers, PLCs, and SCADA components are classified as Important Class II under Annex III of the CRA, requiring third-party conformity assessment. These products have long operational lifetimes (10–20+ years), network connectivity, and significant safety implications. CRA compliance must be planned well in advance of the September 2026 deadline.Medical DevicesMedical devices regulated under the EU Medical Device Regulation (MDR) or In Vitro Diagnostic Regulation (IVDR) are generally excluded from the CRA. However, software products used in healthcare that are not classified as medical devices under MDR may fall within CRA scope. Manufacturers should carefully verify their product's regulatory classification.Building Automation & Smart BuildingsBuilding automation systems (BAS/BMS) control HVAC, lighting, access, fire safety, and energy management across commercial and industrial buildings. Most BAS components are Default class under the CRA, but those deployed in hospitals, data centres, and other critical facilities may be treated as critical infrastructure components. The BACnet and Modbus protocols widely used in BAS were not designed with security in mind - CRA compliance requires significant attention to protocol security and access control.EV Charging EquipmentEV charging equipment sits at the intersection of energy infrastructure, payment systems, and connected vehicles - making it a high-priority CRA compliance target. Residential chargers are typically Default class, while public charging networks connected to grid management systems may be classified as critical infrastructure under NIS2 and face Annex III Important product classification under the CRA. The OCPP (Open Charge Point Protocol) ecosystem introduces supply chain complexity that manufacturers must address.

Browse the full CRA Compliance Checklist

See how Important Product Class II fits into your complete CRA compliance programme.

View checklists →