CRA product classes explained: Default, Important (I & II) and Critical in plain English
The EU Cyber Resilience Act sorts products into risk classes that decide how you prove compliance — self-assessment or a notified body. Which class your product falls in, with plain examples, and why most products are Default.
Not sure if you’re in scope?
Run the free 3-minute scope check for your product and get your risk class, deadlines and obligations.
Check if the CRA applies to youIn short
The CRA sorts products into four risk levels — Default, Important Class I, Important Class II and Critical — and your class decides how you prove compliance: self-assessment or an external notified body. Around 90% of products fall in the Default class and can self-assess; only specific security-critical products (such as password managers, firewalls, hypervisors or hardware security modules) sit in the higher classes.
Under the EU Cyber Resilience Act, not every product carries the same burden. The regulation sorts products into risk classes, and your class decides one crucial thing: how you prove compliance — whether you can self-assess, or whether you need an external body to check your work. Getting your class right is the difference between a manageable internal project and a five-figure external one.
This guide explains the four levels in plain English, with real examples, so you can place your own product.
Want the answer for your specific product in three minutes? Run the free scope check — it computes your class automatically.
The four levels at a glance
| Class | How you prove compliance | Roughly what share of products |
|---|---|---|
| Default | Self-assessment — you do the work and sign off yourself | ~90% |
| Important — Class I | Apply harmonised standards, or use a notified body | small minority |
| Important — Class II | Notified body assessment required | smaller still |
| Critical | European cybersecurity certification | very few |
The key insight: the class is not about how "important" your product is to you — it's about whether the product itself performs security functions that, if compromised, would put other systems at risk. A €50,000 industrial machine can be Default class; a €30 password manager is Important. The regulation cares about the security role, not the price tag.
Default class — where most products land
If your product does not perform a core security function, it's Default. This covers the vast majority of connected products: environmental sensors, asset trackers, smart appliances, most IoT devices, machines with a controller and connectivity, business software, mobile apps, most firmware.
How you prove it: self-assessment. You compile your technical documentation (SBOM, risk assessment, vulnerability-handling process), sign the EU Declaration of Conformity yourself, and affix the CE marking. No external body, no waiting lists, no certification fees.
For a small manufacturer this is the good-news class: the work is real, but it's work you can do internally — or hand to CRA compliance software built for self-assessment. Our compliance checklist walks through exactly what to prepare.
Default class means self-assessment — you still have to produce the SBOM, risk assessment and technical file yourself.
Nordchecks is built for exactly that: it generates and maintains the documentation a self-assessed product needs, so signing your Declaration of Conformity is the last step, not the hard one.
Try Nordchecks freeImportant — Class I
These are products whose function is security-adjacent — if they're compromised, they can be used to attack the systems around them. The regulation lists them (Annex III, Class I). In plain terms:
- Identity and access management software (password managers, authentication tools)
- Standalone web browsers
- Antivirus / malware detection
- VPNs
- Network management and monitoring systems
- Smart home products with security functions (smart locks, security cameras, alarm-connected devices, baby monitors with remote access)
- Internet-connected toys with recording or location tracking
- Wearables that handle health data
- Consumer routers and modems
- Microprocessors and microcontrollers with security-related functions
How you prove it: you either apply the relevant harmonised standards (once published) and self-assess against them, or you involve a notified body. This is a step up in effort and, potentially, cost.
Important — Class II
A shorter, higher-stakes list (Annex III, Class II) — products that sit deeper in the security stack:
- Hypervisors and container runtimes
- Firewalls, intrusion detection and prevention systems for industrial use
- Tamper-resistant microprocessors and microcontrollers
How you prove it: a notified body assessment is mandatory — you can't self-assess your way out of Class II. Plan for third-party involvement, and start early: notified body capacity is expected to be tight as the December 2027 deadline approaches.
Critical products
The smallest, most sensitive category (Annex IV) — products the EU considers critical infrastructure for cybersecurity:
- Hardware security modules (HSMs)
- Smart meter gateways
- Smartcards and secure elements
How you prove it: these require a European cybersecurity certification scheme. This is the heaviest regime and applies to very few manufacturers.
The industrial-context trap
One thing that catches machine builders and industrial vendors: a product's class can shift upward based on how it's used. A network monitoring function or an industrial firewall built into your machine can pull the whole product toward Class I or II, even if the machine itself is otherwise ordinary. If your product has any security or network-control function, don't assume Default — verify.
How to place your own product
Ask, in order:
- Does it perform a security function? (VPN, access control, malware detection, firewall, secure element…) If clearly no → Default.
- Is it on the Class I list? (browsers, password managers, smart locks, routers, network monitoring…) If yes → Important Class I.
- Is it deep security infrastructure? (hypervisor, industrial firewall, tamper-resistant chip…) → Class II.
- Is it an HSM, smart meter gateway, or secure element? → Critical.
For most products the answer stops at step 1 with "Default" — self-assessment, no external body. But because the consequences of guessing wrong (doing unnecessary notified-body work, or missing a required one) are expensive, it's worth confirming rather than assuming.
Three minutes to certainty: check your product's class free — no signup, based on the regulation's Annex III and IV.