Product classes
Detailed overview of all product classes, classifications, and conformity paths under the Cyber Resilience Act. Find out where your product is categorized.
Critical product
Conformity path: European cybersecurity certification can be made mandatory (Art. 8)
Hardware devices with security boxes
Physical payment terminals, hardware security modules, matching tachographs
Smart meter gateways in smart metering systems and other devices for advanced security purposes
Gateways for smart metering systems including secure cryptographic processing
Smartcards or similar devices, including secure elements
Secure elements with microcontroller or microprocessor and tamper protection
Important product, Class II
Conformity path: Notified body (Module B+C or H) or a covering EU certification scheme
Hypervisors and container runtime systems
Systems supporting virtualised execution of operating systems and similar environments
Firewalls, intrusion detection systems and intrusion prevention systems
Network/application firewalls, IDS and IPS
Tamper-resistant microprocessors
Microprocessors protected against potential exploitability of flaws or weaknesses
Tamper-resistant microcontrollers
Microcontrollers protected against potential exploitability of flaws or weaknesses
Important product, Class I
Conformity path: Self-assessment only with full application of harmonised standards / EU certificate, otherwise notified body
Identity management systems and privileged access management software and hardware
Including authentication and access-control readers, including biometric readers
Standalone and embedded browsers
Browser products including embedded browsers and browsers with integrated AI agents
Password managers
Local, browser-extension, enterprise and hardware-based password managers
Software for searching, removing and quarantining malware
Antivirus/anti-malware software, rootkit detection, emergency CD software with that core function
Products with digital elements with virtual private network (VPN) functionality
VPN clients, VPN servers and VPN gateways
Network management systems
End-to-end management systems and software-defined networking controllers
Security information and event management (SIEM) systems
Systems collecting, analysing and correlating security-relevant data
Boot managers
UEFI firmware and single-stage or multi-stage bootloaders
Public key infrastructures and digital certificate issuance software
Key management systems, certificate management, OCSP responders, PKI solutions
Physical and virtual network interfaces
Network interface cards, controllers, adapters and purely virtual network interfaces
Operating systems
Real-time, general-purpose and specialised operating systems
Routers, modems for internet connection and switches
Wired/wireless routers, internet modems, managed/smart/multilayer switches
Microprocessors with security-relevant functions
Main processors with hardware-based security mechanisms
Microcontrollers with security-relevant functions
Programmable integrated circuits with memory and security-relevant functions
Application-specific integrated circuits (ASICs) and FPGAs with security-relevant functions
ASICs and FPGAs with hardware-based security mechanisms
General-purpose virtual assistants for smart home environments
Smart speakers with integrated virtual assistant and standalone virtual assistants
Smart home products with security functions
Including smart door locks, security cameras, baby monitoring systems and alarm systems
Internet-connected toys with social interaction or location features
Toys under Directive 2009/48/EC with speaking, filming or location features
Wearable products for health monitoring or for children
Health trackers outside MDR/IVDR and wearable products for children
Default product
Conformity path: Self-assessment (Module A, internal control)