Guide

CRA Product Classification: Default vs Class I vs Class II

Your CRA classification determines which conformity assessment you need. Use this guide to identify your product's classification tier.

March 2026 · 9 min read

Why Classification Matters

Your classification determines which conformity assessment you must follow.

Default (Most Products)

Self-assessment using Module A. Evaluate, document, issue DoC, apply CE mark.

Class I (Important)

Annex III Section I: identity management, password managers, VPNs, SIEM, firewalls, routers. Third-party notified body assessment required in practice — Module A self-assessment only available once harmonised CRA standards are published (Article 32). No harmonised standards published as of 2026.

Class II (Critical)

Annex III Section II: hypervisors, HSMs, smartcard readers, industrial firewalls. Mandatory third-party assessment.

Find Your Classification

Take the CRA Assessment →

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.