III

Annex III

IMPORTANT PRODUCTS WITH DIGITAL ELEMENTS

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

Quick Answer for Manufacturers

Annex III lists the 'important products' in Class I and Class II. This classification determines the conformity assessment procedure — particularly the obligation to involve a notified body for Class II.

This quick answer + FAQ supplements the original legal text with practice-oriented interpretation. Only the original text is legally binding.

Class I

1.

Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers

2.

Standalone and embedded browsers

3.

Password managers

4.

Software that searches for, removes, or quarantines malicious software

5.

Products with digital elements with the function of virtual private network (VPN)

6.

Network management systems

7.

Security information and event management (SIEM) systems

8.

Boot managers

9.

Public key infrastructure and digital certificate issuance software

10.

Physical and virtual network interfaces

11.

Operating systems

12.

Routers, modems intended for the connection to the internet, and switches

13.

Microprocessors with security-related functionalities

14.

Microcontrollers with security-related functionalities

15.

Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities

16.

Smart home general purpose virtual assistants

17.

Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems

18.

Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council (1) that have social interactive features (e.g. speaking or filming) or that have location tracking features

19.

Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children

Class II

1.

Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments

2.

Firewalls, intrusion detection and prevention systems

3.

Tamper-resistant microprocessors

4.

Tamper-resistant microcontrollers

(1)

Directive 2009/48/EC of the European Parliament and of the Council of 18 June 2009 on the safety of toys (OJ L 170, 30.6.2009, p. 1).

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 6.1Core functionality — the key to product classification

Whether a product is 'important' (Annex III) or 'critical' (Annex IV) is determined solely by its core functionality — the main features without which it could not meet its intended purpose. Ancillary functions and integrated components do not change the classification; every product has exactly one core functionality, to be clearly identified in the technical documentation.

Key takeaways

  • Integration is not classification: a smartphone integrating an operating system does not have the core functionality of an operating system (Example 58).
  • Substantially exceeding or falling short of a category takes a product out of it: SOAR software is not a SIEM (Example 59), simple log collection tools without correlation are not either (Example 60).
  • No gaming via marketing: inconsistencies between promotional material, instructions and technical documentation may not be used to escape the stricter regime.
  • Modules of a product that are also marketed separately are classified individually (Example 61: security suite with SIEM, IDS and analytics modules).
  • The technical descriptions of the categories are laid down in Implementing Regulation (EU) 2025/2392.

In practice

Write one sentence per product: 'Without function X the product cannot meet its purpose.' X is the core functionality — match only X against the categories in Annex III/IV (or Implementing Regulation 2025/2392), not your feature list. Make sure marketing material, instructions and technical documentation tell the same story.

Section in the guidance overview
Section 6.2Conformity assessment for important and critical products

Class II and critical products require third-party assessment. Important class I products may use the internal control procedure (module A) where a relevant harmonised standard is applied in full and covers at least all risks associated with the core functionality — risks beyond that scope must be addressed through additional, documented measures.

Key takeaways

  • FOSS exception: important class I/II products placed on the market as FOSS may follow the default-category procedures (Art. 32(5)).
  • Antivirus with extra features (disk cleaning, anti-tracking): self-assessment is possible where the standard covers the core functionality's risks and additional risks are addressed and documented (Example 62).
  • An integrated critical component does not force the whole product into that component's stricter regime — the product's own core functionality remains decisive (Example 63: router integrating a firewall component).
  • Non-compliance with Art. 32 can trigger administrative fines under Art. 64(3).

In practice

For class I products, first check whether a harmonised standard covers all risks of the core functionality — that determines whether you may self-assess (module A) or need a notified body. Risks from additional functions outside the standard must be closed with your own documented measures. FOSS products of classes I/II may always self-assess.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

Common Manufacturer Questions

Which products fall into Class I (Annex III)?

Examples: identity and access management software, browsers, password managers, network management systems, SIEM tools, public key infrastructure, physical and virtual network interfaces, security-purposed microprocessors, home routers, smart home hubs, connected toys — and others.

Which products fall into Class II (Annex III)?

Examples: hypervisors and container runtimes, firewalls/intrusion detection systems, tamper-resistant microprocessors with security functions, smartcards and smartcard readers. Class II has stricter conformity assessment procedures.

Is the list in Annex III exhaustive?

Essentially yes, but the Commission can extend Annex III through delegated acts if new threat landscapes or technologies require it. Manufacturers must monitor updates.

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex