
The previous article settled the question of whether my product has to do the CRA at all. The next question is one of the focal points of the in-person seminar Applus+ Laboratories × SV Surveillance are holding in Taipei on Friday 18 September 2026 — and it decides directly how much money and how much time this will cost you.
This article walks the same reasoning through a fictional case first, so that you can ask sharper questions on the day: is your product a default product, an important product Class I, an important product Class II, or a critical product?
A different classification means a different compliance route. Some products can be self-declared; others must involve a third-party Notified Body. One tier of difference is one more quotation and several more months in the queue. This article does not recite provisions — we take one fictional Taiwanese networking company, “Xiaowang Technology”, and follow it all the way through.
Key points first
The boss asks: is the CRA work the same for all three?
The answer: the technical requirements they have to meet are the same, but the way they are checked is not.
The CRA sorts products into four tiers:
| Classification | Where it is listed | Who does the checking |
|---|---|---|
| Default product | Not on any list | Check it yourself, declare it yourself (Module A) |
| Important product Class I | Annex III, 19 categories | Conditional self-declaration, otherwise a Notified Body |
| Important product Class II | Annex III, 4 categories | A Notified Body, always |
| Critical product | Annex IV, 3 categories | European cybersecurity certification schemes take precedence (such as the EUCC) |

Whichever tier you are in, the 13 product requirements and the 8 vulnerability handling obligations in Annex I all have to be done. Classification adds no requirements; what it decides is who believes you when you say you have met them.
The Class I list in Annex III names “network interfaces such as routers, modems and switches” explicitly, and Xiaowang’s router matches.
Class I carries one special rule: if the applicable harmonised standards are applied in full, the product can be self-declared; if they are not, a Notified Body has to carry out an EU-type examination (Module B+C).
Class II has only four categories, and “firewalls, intrusion detection and prevention systems” is one of them.
Class II has no self-declaration option. However well Xiaowang builds its firewall, however completely it applies the standards, a Notified Body has to be involved.
This is the one that goes wrong most often. The doorbell is built around Xiaowang’s own Wi-Fi module, and inside that module sits a microcontroller with security-related functionality — a component that is itself Class I.
So is the doorbell Class I too?
No. The implementing regulation the Commission published in November 2025 (Commission Implementing Regulation (EU) 2025/2392) is explicit: classification follows the core functionality of the product, and a higher-classified component inside it does not automatically pull the whole product up a tier.
The doorbell’s core functionality is “tell me when someone presses the button”. It is not a security camera, not a door lock and not an alarm system, so it is a default product and self-declaration is enough.
But if Xiaowang’s doorbell were sold on “record and push an alert whenever someone approaches”, it would in substance be a surveillance camera, and it would land in the Class I category for smart home products with security functionalities.

Two products with the same external appearance can sit in different tiers if the functionality they are sold on differs. Classification has to be done per model, not per product category.
| Product | Tier | What to do now |
|---|---|---|
| Router | Class I | Prepare on the assumption of Module B+C |
| Firewall | Class II | Plan for third-party assessment directly; approach a Notified Body early |
| Doorbell | Default | Self-assess against Annex I and build the technical documentation |
Hold on — the router is Class I, so can’t it be self-declared? Why prepare for Module B+C?
Because self-declaration is conditional on applying the published harmonised standards in full, and as of September 2026 not a single CRA harmonised standard has been cited in the Official Journal of the European Union. With no standards published, the condition cannot be met.
So the pragmatic approach for Class I at this stage is to prepare as though a Notified Body will be needed, and to reassess whether the self-declaration route is open once the standards are formally cited.
“It doesn’t apply until the end of 2027 — what’s the hurry?”
The Notified Body regime only began operating in June 2026, and most conformity assessment bodies are still applying for designation. Member States are not required to “ensure that a sufficient number of notified bodies is available” until December 2026.

Xiaowang’s firewall needs a Notified Body, and at this stage so does the router. If the filing is left until the second half of 2027, it is very likely to end up queueing at the door of a handful of newly designated notified bodies alongside every other Class I and Class II product in Europe. The earlier the classification is confirmed, the more time there is to decide whether to join the queue now.
Next in this series: once the classification is settled, what Modules A, B+C and H each require you to prepare.
If you still cannot pin down where your own product sits, or you have reached a conclusion and would like a professional second opinion, we’d be glad to talk it through. You are also welcome to join the in-person seminar in Taipei on Friday 18 September, where you can put questions directly to a CRA expert from Spain and learn more about planning for 2027 compliance and estimating the time and cost of implementation. Registration: Register for the seminar
Q: My product does not appear on any Annex III or Annex IV list — does that mean I don’t have to do the CRA? No. Classification only decides who does the checking. A default product that is not on any list still has to meet the 13 security requirements and the 8 vulnerability handling obligations in Annex I, and still has to issue a declaration of conformity and prepare technical documentation. The only difference is that it can be self-declared under Module A, without a Notified Body.
Q: Is classification done per product or per model? Per model. Xiaowang’s smart doorbell is the example: the same physical product sold on different core functionality (notification only vs. recording plus push alerts) can land in different tiers, so you cannot make one judgment for a whole product line by name — each model has to be reviewed.
Q: What if my product matches several Annex III descriptions at once? The Regulation does not set out an order of precedence for products matching multiple descriptions; the underlying principle is that the product’s core functionality governs. In practice we recommend recording every category that might apply, writing out the reasoning clearly, and keeping it as part of the technical documentation — and asking a Notified Body or a consultant to confirm where necessary.
Q: My module supplier says the module itself is “CRA compliant” — does that make my finished product compliant automatically? No. The CRA places the obligation on the product that is finally placed on the market. A component meeting the requirements of a given tier (an MCU that is itself Class I, for instance) does not extend that treatment to the whole device and does not exempt the finished product from assessment. You still have to prepare the finished product’s own technical documentation, risk assessment and declaration of conformity; the supplier’s documentation is only part of the supporting evidence.
Q: Once the classification is settled, can I file straight away? Not yet. Classification only decides which conformity assessment route applies (Module A, B+C or H). Whether you can actually file, and what you have to prepare, also depends on whether the harmonised standards have been published and whether any notified bodies have been designated — which the next article takes up in detail.
All legal provisions and dates cited in this article are based on the following official documents:
By the Secure Vectors Surveillance Inc. (SV Surveillance) × Applus+ Laboratories consulting team
* This article is regulatory commentary, not legal advice. “Xiaowang Technology” is a fictional case. The harmonised standards timetable and the designation of notified bodies continue to move; before taking a formal decision, rely on the final versions published in the Official Journal of the European Union and on the results of a NANDO database search.