CRA Annex II vs Annex IV classification explained sits at the heart of every EU Cyber Resilience Act project. We break down each product tier, show you how to pick the right conformity route, and share a simple step-by-step method. So you avoid costly mistakes and reach CE marking with confidence in 2026.
Why Product Classification Is the First Step in CRA Compliance
We always start CRA work with one question: how risky is your product? The CRA Annex II vs Annex IV classification explained approach helps answer that fast. Classification decides everything that follows. So getting it right early saves time, money, and stress.
The Cyber Resilience Act splits products into risk tiers. Each tier carries different rules. And each rule shapes your workload for months.
How Classification Determines Your Conformity Assessment Route
Your product tier sets your conformity assessment route CRA teams must follow. A low-risk product often needs only self-declaration of conformity. But a critical product may need a notified body EU CRA review.
So the tier is not just paperwork. It decides cost, timeline, and effort. Above all, it decides whether you can self-assess or must bring in outside help.
Getting It Wrong - Consequences of Misclassification
Misclassification hurts. Firstly, you may pick the wrong assessment path. Secondly, you may fail your audit and delay your launch.
Regulators can also impose fines. And a wrong CE marking route for software can trigger recalls. So we treat classification as a serious first step, not a quick guess.
CRA Product Categories Explained
The CRA uses a product risk tier system. Most products sit low. A few sit very high. Let us walk through each level clearly.
Default Category - The Majority of Digital Products
Most software and connected devices land here. This default category cybersecurity regulation covers apps, games, and simple tools. These products carry lower risk.
Self-Assessment Path and Documentation Requirements
Here you can use self-declaration of conformity. You test against the CRA rules yourself. Then you keep technical files, risk notes, and update records ready for inspection.
Annex III Class I - Important Products With Digital Elements
Class I covers important digital products with digital elements. These carry more risk than default products. So they need extra care.
Examples - Identity Management, VPNs, Network Management Systems
Think password managers, VPNs, and network management systems. Firewalls for home use also fit here. These tools protect access and data.
Assessment Options - Harmonised Standards or Third Party
You get a choice. Follow harmonised standards CRA fully, and you may self-assess. But skip them, and you must use a third party instead.
Annex III Class II - More Critical Products
Class II holds more critical products with digital elements. The CRA Annex III class I class II difference comes down to risk and impact. Class II products can cause wider harm if breached.
Examples - Operating Systems, Industrial Firewalls, Secure Elements
Examples include operating systems, industrial firewalls, and secure elements. Industrial automation CRA classification often lands here too. These sit deep inside critical systems.
Mandatory Third-Party Assessment
Self-assessment is not enough here. You must use a third-party body. So plan for extra time and budget.
Annex IV - Highly Critical Products
Annex IV holds the highest-risk products. These are critical products with digital elements at the top tier. They protect the most sensitive systems.
Examples - Smart Meter Gateways, Hardware Security Modules
Examples include smart meter gateways and hardware security modules. These guard energy grids and encryption keys. A breach here spreads far.
EU Type-Examination Required
Annex IV needs EU type-examination. A notified body checks your product design directly. So this route takes the most effort of all.
How to Classify Your Own Product Step by Step
We use a simple method with every client. It removes doubt. And it keeps teams aligned.
Decision Tree - Functionality, Intended Use, and Risk Level
First, look at what your product does. Secondly, check its intended use. After that, weigh the risk if it fails.
This is how to classify product under CRA in plain terms. Match your product against the CRA critical product categories lists. Then place it in the right tier.
Borderline Cases - When a Product Sits Between Two Categories
Some products sit on the edge. A tool might act like Class I and Class II at once. So we check its most critical function first.
When in doubt, we pick the higher tier. This keeps you safe. And it prevents audit surprises later.
Using an Automated Classification Engine to Remove Guesswork
Manual classification takes hours. An automated engine cuts that to minutes. We use one that maps your product features against the CRA product classification rules.
The engine flags borderline cases too. So you never miss a hidden risk. Meanwhile, your team stays focused on building.
What Happens After Classification
Classification is the start, not the end. Next, you turn your tier into real controls. Then you pick your assessment body.
Mapping Classification to Your CRA Control Matrix
Each tier links to a control set. We map your class to a clear control matrix. So every rule ties back to a task and an owner.
This keeps your team on track. And it makes audits far smoother.
Choosing Between Internal and External Conformity Assessment Bodies
Default and some Class I products allow internal checks. But Class II and Annex IV need external bodies. So choose your notified body early, since good ones book up fast in 2026.
FAQ
What is the difference between Annex III Class I and Class II?
Class I holds important products like VPNs and password managers. Class II holds more critical ones like operating systems and industrial firewalls. Class II always needs third-party assessment.
Does the CRA apply to SaaS products?
Mostly no. Pure SaaS often falls under other rules. But software sold as a product with digital elements can fall under the CRA.
Who decides which Annex my product falls under?
You classify first, based on the CRA lists. But a notified body confirms it for higher tiers. So responsibility is shared.
Can a single product fall under multiple categories?
Yes. A product may show features from two tiers. In that case, we apply the highest tier that fits.
What are harmonised standards under the CRA?
These are agreed EU technical standards. Follow them, and you gain a presumption of conformity. So they simplify your path.
Is a notified body always required for Annex IV products?
Yes. Annex IV always needs EU type-examination by a notified body. There is no self-assessment route here.
Conclusion
We hope this guide made CRA Annex II vs Annex IV classification explained clear and simple. Classification shapes your entire CRA journey. So start it early and get it right.
Above all, treat your product tier as the foundation for every control that follows. UbiComply.ai automates classification, control mapping, and audit readiness for you. So you can reach CE marking faster and with full confidence in 2026.

No comments:
Post a Comment