Showing posts with label EU CRA. Show all posts
Showing posts with label EU CRA. Show all posts

Sunday, August 2, 2026

CRA Annex II vs Annex IV Classification Explained: A Practical 2026 Guide


CRA Annex II vs Annex IV Classification Explained: A Practical 2026 Guide

CRA Annex II vs Annex IV classification explained sits at the heart of every EU Cyber Resilience Act project. We break down each product tier, show you how to pick the right conformity route, and share a simple step-by-step method. So you avoid costly mistakes and reach CE marking with confidence in 2026.

Why Product Classification Is the First Step in CRA Compliance

We always start CRA work with one question: how risky is your product? The CRA Annex II vs Annex IV classification explained approach helps answer that fast. Classification decides everything that follows. So getting it right early saves time, money, and stress.

The Cyber Resilience Act splits products into risk tiers. Each tier carries different rules. And each rule shapes your workload for months.


How Classification Determines Your Conformity Assessment Route

Your product tier sets your conformity assessment route CRA teams must follow. A low-risk product often needs only self-declaration of conformity. But a critical product may need a notified body EU CRA review.

So the tier is not just paperwork. It decides cost, timeline, and effort. Above all, it decides whether you can self-assess or must bring in outside help.


Getting It Wrong - Consequences of Misclassification

Misclassification hurts. Firstly, you may pick the wrong assessment path. Secondly, you may fail your audit and delay your launch.

Regulators can also impose fines. And a wrong CE marking route for software can trigger recalls. So we treat classification as a serious first step, not a quick guess.


CRA Product Categories Explained

The CRA uses a product risk tier system. Most products sit low. A few sit very high. Let us walk through each level clearly.


Default Category - The Majority of Digital Products

Most software and connected devices land here. This default category cybersecurity regulation covers apps, games, and simple tools. These products carry lower risk.


Self-Assessment Path and Documentation Requirements

Here you can use self-declaration of conformity. You test against the CRA rules yourself. Then you keep technical files, risk notes, and update records ready for inspection.


Annex III Class I - Important Products With Digital Elements

Class I covers important digital products with digital elements. These carry more risk than default products. So they need extra care.


Examples - Identity Management, VPNs, Network Management Systems

Think password managers, VPNs, and network management systems. Firewalls for home use also fit here. These tools protect access and data.


Assessment Options - Harmonised Standards or Third Party

You get a choice. Follow harmonised standards CRA fully, and you may self-assess. But skip them, and you must use a third party instead.


Annex III Class II - More Critical Products

Class II holds more critical products with digital elements. The CRA Annex III class I class II difference comes down to risk and impact. Class II products can cause wider harm if breached.


Examples - Operating Systems, Industrial Firewalls, Secure Elements


Examples include operating systems, industrial firewalls, and secure elements. Industrial automation CRA classification often lands here too. These sit deep inside critical systems.


Mandatory Third-Party Assessment

Self-assessment is not enough here. You must use a third-party body. So plan for extra time and budget.

Annex IV - Highly Critical Products


Annex IV holds the highest-risk products. These are critical products with digital elements at the top tier. They protect the most sensitive systems.

Examples - Smart Meter Gateways, Hardware Security Modules

Examples include smart meter gateways and hardware security modules. These guard energy grids and encryption keys. A breach here spreads far.


EU Type-Examination Required

Annex IV needs EU type-examination. A notified body checks your product design directly. So this route takes the most effort of all.


How to Classify Your Own Product Step by Step

We use a simple method with every client. It removes doubt. And it keeps teams aligned.


Decision Tree - Functionality, Intended Use, and Risk Level

First, look at what your product does. Secondly, check its intended use. After that, weigh the risk if it fails.


How to Classify Your Own Product Step by Step

This is how to classify product under CRA in plain terms. Match your product against the CRA critical product categories lists. Then place it in the right tier.

Tier

Risk Level

Assessment Route (2026)

Notified Body?

Default

Low

Self-declaration of conformity

No

Annex III Class I

Elevated

Harmonised standards or third party

Sometimes

Annex III Class II

High

Mandatory third-party assessment

Yes

Annex IV

Highest

EU type-examination

Yes, always

 

Borderline Cases - When a Product Sits Between Two Categories


Some products sit on the edge. A tool might act like Class I and Class II at once. So we check its most critical function first.

When in doubt, we pick the higher tier. This keeps you safe. And it prevents audit surprises later.

Using an Automated Classification Engine to Remove Guesswork


Manual classification takes hours. An automated engine cuts that to minutes. We use one that maps your product features against the CRA product classification rules.

The engine flags borderline cases too. So you never miss a hidden risk. Meanwhile, your team stays focused on building.

What Happens After Classification


Classification is the start, not the end. Next, you turn your tier into real controls. Then you pick your assessment body.

Mapping Classification to Your CRA Control Matrix


Each tier links to a control set. We map your class to a clear control matrix. So every rule ties back to a task and an owner.

This keeps your team on track. And it makes audits far smoother.

Control Matrix for Team Management Tier 1 Tier 2 Tiers Rule 1 Tier 3 Control Sets Rule 2 Rule 3 Task A Control Matrix Task B Tasks Owner X Task C Owners Owner Y Owner Z Team on Track Benefits Smoother Audits

Choosing Between Internal and External Conformity Assessment Bodies


Default and some Class I products allow internal checks. But Class II and Annex IV need external bodies. So choose your notified body early, since good ones book up fast in 2026.

FAQ

What is the difference between Annex III Class I and Class II?

Class I holds important products like VPNs and password managers. Class II holds more critical ones like operating systems and industrial firewalls. Class II always needs third-party assessment.


Does the CRA apply to SaaS products?

Mostly no. Pure SaaS often falls under other rules. But software sold as a product with digital elements can fall under the CRA.


Who decides which Annex my product falls under?

You classify first, based on the CRA lists. But a notified body confirms it for higher tiers. So responsibility is shared.


Can a single product fall under multiple categories?

Yes. A product may show features from two tiers. In that case, we apply the highest tier that fits.


What are harmonised standards under the CRA?

These are agreed EU technical standards. Follow them, and you gain a presumption of conformity. So they simplify your path.


Is a notified body always required for Annex IV products?

Yes. Annex IV always needs EU type-examination by a notified body. There is no self-assessment route here.


Conclusion

We hope this guide made CRA Annex II vs Annex IV classification explained clear and simple. Classification shapes your entire CRA journey. So start it early and get it right.

Above all, treat your product tier as the foundation for every control that follows. UbiComply.ai automates classification, control mapping, and audit readiness for you. So you can reach CE marking faster and with full confidence in 2026.


Your Complete Cyber Resilience Act Compliance Checklist for 2026: An 8-Step Guide for Manufacturers

The cyber resilience act compliance checklist is now a top priority for every digital product manufacturer selling into the EU. This guide w...