Testing Services
Industry
EU CRAFDA & MDRPayment & FinanceNewsAbout Us
EN繁中
Contact Us
← Back to news
Knowledge

Is My Product Class I or Class II? CRA Product Classification, Explained Through One Router

September 10, 2026
Is My Product Class I or Class II? CRA Product Classification, Explained Through One Router

The previous article settled the question of whether my product has to do the CRA at all. The next question is one of the focal points of the in-person seminar Applus+ Laboratories × SV Surveillance are holding in Taipei on Friday 18 September 2026 — and it decides directly how much money and how much time this will cost you.

This article walks the same reasoning through a fictional case first, so that you can ask sharper questions on the day: is your product a default product, an important product Class I, an important product Class II, or a critical product?

A different classification means a different compliance route. Some products can be self-declared; others must involve a third-party Notified Body. One tier of difference is one more quotation and several more months in the queue. This article does not recite provisions — we take one fictional Taiwanese networking company, “Xiaowang Technology”, and follow it all the way through.

Key points first

  • The CRA sorts products into four tiers: default products, important products Class I (Annex III, 19 categories), important products Class II (Annex III, 4 categories) and critical products (Annex IV, 3 categories). What changes between them is who confirms that you are compliant.
  • Whichever tier you land in, the 13 security requirements and 8 vulnerability handling obligations in Annex I all have to be met. Classification adds no extra requirements.
  • Classification is done per model and turns on core functionality: two products that look identical can classify differently if the functionality they are sold on differs.
  • Routers, firewalls and other common networking equipment are already named in the Annex III lists, so networking manufacturers should work through their catalogue model by model as a priority.

Xiaowang Technology’s product line — three things it sells into Europe

  • A home Wi-Fi router
  • An enterprise firewall
  • A smart doorbell (built around the company’s own Wi-Fi module)

The boss asks: is the CRA work the same for all three?

The answer: the technical requirements they have to meet are the same, but the way they are checked is not.

Step one: classification changes only who does the checking

The CRA sorts products into four tiers:

ClassificationWhere it is listedWho does the checking
Default productNot on any listCheck it yourself, declare it yourself (Module A)
Important product Class IAnnex III, 19 categoriesConditional self-declaration, otherwise a Notified Body
Important product Class IIAnnex III, 4 categoriesA Notified Body, always
Critical productAnnex IV, 3 categoriesEuropean cybersecurity certification schemes take precedence (such as the EUCC)
The CRA classification pyramid: default products, important products Class I and Class II, and critical products, with the assessment route for each tier
The CRA’s four classification tiers

Whichever tier you are in, the 13 product requirements and the 8 vulnerability handling obligations in Annex I all have to be done. Classification adds no requirements; what it decides is who believes you when you say you have met them.

Step two: matching the three products to the lists

Home router → Class I

The Class I list in Annex III names “network interfaces such as routers, modems and switches” explicitly, and Xiaowang’s router matches.

Class I carries one special rule: if the applicable harmonised standards are applied in full, the product can be self-declared; if they are not, a Notified Body has to carry out an EU-type examination (Module B+C).

Enterprise firewall → Class II

Class II has only four categories, and “firewalls, intrusion detection and prevention systems” is one of them.

Class II has no self-declaration option. However well Xiaowang builds its firewall, however completely it applies the standards, a Notified Body has to be involved.

Smart doorbell → it depends on the core functionality

This is the one that goes wrong most often. The doorbell is built around Xiaowang’s own Wi-Fi module, and inside that module sits a microcontroller with security-related functionality — a component that is itself Class I.

So is the doorbell Class I too?

No. The implementing regulation the Commission published in November 2025 (Commission Implementing Regulation (EU) 2025/2392) is explicit: classification follows the core functionality of the product, and a higher-classified component inside it does not automatically pull the whole product up a tier.

The doorbell’s core functionality is “tell me when someone presses the button”. It is not a security camera, not a door lock and not an alarm system, so it is a default product and self-declaration is enough.

But if Xiaowang’s doorbell were sold on “record and push an alert whenever someone approaches”, it would in substance be a surveillance camera, and it would land in the Class I category for smart home products with security functionalities.

The same smart doorbell classified two ways: button-press notification only is a default product that can be self-declared, while recording plus alerting makes it an important product Class I smart home security product
Same doorbell, different core functionality — different classification

Two products with the same external appearance can sit in different tiers if the functionality they are sold on differs. Classification has to be done per model, not per product category.

Step three: what Xiaowang should be doing now

ProductTierWhat to do now
RouterClass IPrepare on the assumption of Module B+C
FirewallClass IIPlan for third-party assessment directly; approach a Notified Body early
DoorbellDefaultSelf-assess against Annex I and build the technical documentation

Hold on — the router is Class I, so can’t it be self-declared? Why prepare for Module B+C?

Because self-declaration is conditional on applying the published harmonised standards in full, and as of September 2026 not a single CRA harmonised standard has been cited in the Official Journal of the European Union. With no standards published, the condition cannot be met.

So the pragmatic approach for Class I at this stage is to prepare as though a Notified Body will be needed, and to reassess whether the self-declaration route is open once the standards are formally cited.

The boss’s last question

“It doesn’t apply until the end of 2027 — what’s the hurry?”

The Notified Body regime only began operating in June 2026, and most conformity assessment bodies are still applying for designation. Member States are not required to “ensure that a sufficient number of notified bodies is available” until December 2026.

CRA timeline pressure: 11 June 2026 the notified body rules apply, September 2026 today, 11 December 2026 Member States must ensure sufficient notified bodies, 11 December 2027 the CRA applies in full
The Notified Body timeline, and the squeeze it creates

Xiaowang’s firewall needs a Notified Body, and at this stage so does the router. If the filing is left until the second half of 2027, it is very likely to end up queueing at the door of a handful of newly designated notified bodies alongside every other Class I and Class II product in Europe. The earlier the classification is confirmed, the more time there is to decide whether to join the queue now.

In short

  • Classification does not change the technical requirements; it changes who does the checking.
  • Check the lists: routers are Class I, firewalls are Class II.
  • Look at the core functionality: a Class I component inside does not make the whole device Class I.
  • Class I cannot really be self-declared yet, because the harmonised standards have not been published.
  • For products that need a Notified Body, the earlier the approach, the better.

Next in this series: once the classification is settled, what Modules A, B+C and H each require you to prepare.

If you still cannot pin down where your own product sits, or you have reached a conclusion and would like a professional second opinion, we’d be glad to talk it through. You are also welcome to join the in-person seminar in Taipei on Friday 18 September, where you can put questions directly to a CRA expert from Spain and learn more about planning for 2027 compliance and estimating the time and cost of implementation. Registration: Register for the seminar

Frequently asked questions

Q: My product does not appear on any Annex III or Annex IV list — does that mean I don’t have to do the CRA? No. Classification only decides who does the checking. A default product that is not on any list still has to meet the 13 security requirements and the 8 vulnerability handling obligations in Annex I, and still has to issue a declaration of conformity and prepare technical documentation. The only difference is that it can be self-declared under Module A, without a Notified Body.

Q: Is classification done per product or per model? Per model. Xiaowang’s smart doorbell is the example: the same physical product sold on different core functionality (notification only vs. recording plus push alerts) can land in different tiers, so you cannot make one judgment for a whole product line by name — each model has to be reviewed.

Q: What if my product matches several Annex III descriptions at once? The Regulation does not set out an order of precedence for products matching multiple descriptions; the underlying principle is that the product’s core functionality governs. In practice we recommend recording every category that might apply, writing out the reasoning clearly, and keeping it as part of the technical documentation — and asking a Notified Body or a consultant to confirm where necessary.

Q: My module supplier says the module itself is “CRA compliant” — does that make my finished product compliant automatically? No. The CRA places the obligation on the product that is finally placed on the market. A component meeting the requirements of a given tier (an MCU that is itself Class I, for instance) does not extend that treatment to the whole device and does not exempt the finished product from assessment. You still have to prepare the finished product’s own technical documentation, risk assessment and declaration of conformity; the supplier’s documentation is only part of the supporting evidence.

Q: Once the classification is settled, can I file straight away? Not yet. Classification only decides which conformity assessment route applies (Module A, B+C or H). Whether you can actually file, and what you have to prepare, also depends on whether the harmonised standards have been published and whether any notified bodies have been designated — which the next article takes up in detail.

Glossary

  • Annex III / IV | The CRA annexes listing which product categories count as important products (Class I / II) or critical products; the first place to look when determining classification.
  • Harmonised standard | A technical standard formally cited by the EU in the Official Journal; only where it is applied in full does presumption of conformity arise, which is one of the conditions for Class I self-declaration.
  • Notified Body (NB) | A conformity assessment and certification body designated by an EU Member State and qualified to carry out third-party conformity assessment.
  • EU-type examination (Module B) | A one-off technical review carried out by a Notified Body on a given “type” (a representative sample of the design); once it passes, a certificate is issued and subsequent series production is controlled by the manufacturer itself (Module C).
  • Core functionality | The basis on which the CRA determines a product’s classification — the use the product is sold on. Using a higher-classified component internally does not automatically raise the classification of the whole product.

References

All legal provisions and dates cited in this article are based on the following official documents:

  • Regulation (EU) 2024/2847 (Cyber Resilience Act) full text, EUR-Lex: https://eur-lex.europa.eu/eli/reg/2024/2847/oj — Annexes I, III and IV; Articles 7, 8 and 32
  • Commission Implementing Regulation (EU) 2025/2392 (published 28 November 2025)

By the Secure Vectors Surveillance Inc. (SV Surveillance) × Applus+ Laboratories consulting team

* This article is regulatory commentary, not legal advice. “Xiaowang Technology” is a fictional case. The harmonised standards timetable and the designation of notified bodies continue to move; before taking a formal decision, rely on the final versions published in the Official Journal of the European Union and on the results of a NANDO database search.

Keep Reading

More from the lab