Skip to main content
Oficiálna stránka verejnej správy SR
Cyber Resilience Act · National Security Authority

CRA product categories

Last updated:

Classification is not a general judgement about whether a product appears “risky”. The CRA uses specific lists and technical descriptions. Work through these steps:

  1. define the product as a whole and its core functionality;
  2. compare it with CRA Annexes III and IV;
  3. check the detailed description in Implementing Regulation (EU) 2025/2392;
  4. record the decision, including boundary cases, intended purpose and reasonably foreseeable use; and
  5. use the result to select the Article 32 procedure.

An embedded browser inside an application, for example, does not by itself make the whole application an important product. The stricter category applies where the core functionality of the product as a whole matches the technical description of an important or critical product.

Important products — Class I (Annex III)

  1. identity management and privileged-access management systems, including authentication and access-control readers;
  2. standalone and embedded browsers;
  3. password managers;
  4. software that searches for, removes or quarantines malicious software;
  5. products with VPN functionality;
  6. network-management systems;
  7. SIEM systems;
  8. boot managers;
  9. public-key infrastructure and digital-certificate issuance software;
  10. physical and virtual network interfaces;
  11. operating systems;
  12. routers, internet-connection modems and switches;
  13. microprocessors with security-related functionality;
  14. microcontrollers with security-related functionality;
  15. ASICs and FPGAs with security-related functionality;
  16. smart-home general-purpose virtual assistants;
  17. smart-home products with security functionality, including smart door locks, security cameras, baby monitors and alarm systems;
  18. internet-connected toys with social interactive or location-tracking features covered by the applicable toy-safety legislation; and
  19. personal wearable health-monitoring products outside MDR/IVDR, or personal wearables intended for use by and for children.

Important products — Class II (Annex III)

  1. hypervisors and container runtime systems supporting virtualised execution of operating systems and similar environments;
  2. firewalls and intrusion detection/prevention systems;
  3. tamper-resistant microprocessors; and
  4. tamper-resistant microcontrollers.

Critical products (Annex IV)

  1. hardware devices with security boxes;
  2. smart-meter gateways in smart-metering systems and other devices for advanced security purposes, including secure cryptoprocessing; and
  3. smartcards or similar devices, including secure elements.

This is a navigation aid, not a substitute for the legal descriptions. For an actual product, use the full annexes and the technical descriptions in Regulation 2025/2392. The Commission may amend the lists through delegated acts.