The Cyber Resilience Act sorts products with digital elements into three groups, and the group decides how you are allowed to prove conformity — not what the security requirements are.
The short answer
The Cyber Resilience Act sorts products with digital elements into three groups, and the group decides **how you are allowed to prove conformity** — not what the security requirements are.
``` default products not listed self-assessment (internal control) important products Annex III class I and class II, see below critical products Annex IV may require European cybersecurity certification ```
**Annex III is the list of important products. Annex IV is the list of critical products.**
This ordering is worth stating plainly because **it is frequently reversed in secondary sources**, including in material written by people who work with the regulation. The error is not cosmetic: it points a product at the wrong conformity route, and the wrong route is discovered at the worst moment — when a launch date depends on it.
**The essential requirements in Annex I are identical for all three groups.** A default product must be as secure as a critical one. What changes is **who verifies it, and how long that takes.**
Why the class matters more than it looks
For most products, the answer is: not at all. **Default products self-assess through internal control.** The manufacturer performs the assessment, compiles the technical documentation, draws up the EU declaration of conformity and affixes the CE marking. No external party is involved, and the timeline is entirely yours.
The moment a product appears on Annex III or Annex IV, **an external dependency enters the schedule**.
**Important products — Annex III, class I**
Self-assessment remains available, **but conditionally**. It is open where harmonised standards, European cybersecurity certification schemes or common specifications have been applied **in full**.
**"In full" is the operative phrase.** Partial application, or application of a standard that does not cover every relevant requirement, does not preserve the self-assessment route. Where the condition is not met, a **third-party conformity assessment** applies.
This creates a determination that has to be made honestly and early: *have we applied the standard completely, or mostly?* The commercial pressure runs toward "completely". The consequence of being wrong runs the other way.
**Important products — Annex III, class II**
**A third-party route applies regardless.** There is no full-application escape: class II products go to a notified body.
Class II sits above class I in the risk ordering, and the categories reflect functions whose compromise has broader consequences.
**Critical products — Annex IV**
The highest tier. Critical products may be required to obtain a **European cybersecurity certificate** under a scheme adopted for that purpose.
**This is a different kind of dependency.** A third-party assessment depends on a notified body's availability. A certification requirement depends on a **scheme existing and being operational** for your product category — which is not something a manufacturer can accelerate by paying more or planning better.
The real cost is the calendar, not the fee
The difference between self-assessment and a third-party route is usually presented as an assessment fee. **For a product launch, the fee is the smaller number.**
``` self-assessment timeline controlled entirely by you third-party route queue + assessment + remediation + re-assessment certification (IV) scheme availability + certification body + the above ```
Three practical consequences follow:
1. **A notified body's calendar is a market, and it tightens as a deadline approaches.** The full application of the CRA on **11 December 2027** will concentrate demand. Assessment slots close to that date are the scarcest resource in the programme. 2. **Findings cost a cycle, not a fix.** A remediation identified during a third-party assessment is followed by re-assessment, and the second slot is booked from the same queue as the first. 3. **A misclassification discovered late cannot be recovered by effort.** Finding in month ten that you are class II, not default, does not add work — it adds a dependency you have no history with.
How to classify, and when to stop guessing
1. **Read Annex III and Annex IV against your product's function**, not against your product category or your marketing description. The lists describe what a product *does*. 2. **Check the delegated and implementing acts.** The Commission is empowered to specify the technical description of the listed categories. A category that reads ambiguously in the annex may be defined precisely elsewhere. 3. **Classify each product, not each product line.** A family can straddle two classes when one variant adds a function that appears on a list. 4. **Where the reading is genuinely ambiguous, take the higher class for planning purposes.** Booking an assessment you turn out not to need costs a deposit. Discovering you needed one costs the launch.
**And verify the annex numbering against the regulation itself.** If a source tells you Annex III is critical, that source has not been checked — and anything else it says about the conformity route deserves the same scepticism.
What to establish first
1. **Determine the class before designing the compliance plan.** Every date in that plan depends on it. 2. **If class I: decide whether you will apply harmonised standards in full**, and be truthful about it. This decision, not the product, determines whether you need a notified body. 3. **If class II or Annex IV: contact a notified body or certification body now**, before the documentation is ready. Availability is the constraint; readiness is not. 4. **Document the classification reasoning.** A market surveillance authority may ask why you self-assessed. "It was not on the list" is only an answer if you can show which list you read and when.
Tools available on NexCyber
- Free applicability assessment — confirm CRA scope and product classification
- Compliance responsibility mapper — RACI by role
- Penalty calculator — exposure by regulation
Further reading
→ What is the Cyber Resilience Act → CE marking explained → Technical documentation pack for the CRA → SBOM under the CRA: format, depth and signing → CRA penalties and how they are calculated → CRA regulation overview
*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. The technical description of the product categories in Annex III and Annex IV is refined by delegated and implementing acts, and harmonised standards and certification schemes continue to be adopted — verify against the current text of Regulation (EU) 2024/2847 and the Official Journal. Consult your notified body, your competent authority or a qualified adviser.*
This is an educational explainer. For the canonical regulation reference, see the dedicated CRA page — or run an assessment to see how it applies to your product.