Auditen
Home / Frameworks / Cyber Resilience Act / Important and critical product classes
Cyber Resilience Act · Annexes III–IV

Important and critical product classes

The CRA categorizes products with digital elements into different risk levels to determine how they must be certified. If a product falls under the "Important" (Annex III) or "Critical" (Annex IV) classes, it is subject to more stringent conformity assessment procedures than standard products.

What it means

The EU distinguishes between products based on their potential impact on security and safety if compromised. While most products can be self-assessed for compliance, those listed in Annexes III and IV are deemed higher risk due to their function or the environment in which they operate (e.g., password managers, network interfaces, or industrial control systems).

In practice, this means that simply declaring compliance is not enough for certain high-risk categories. Depending on whether a product is "Important" or "Critical," the manufacturer may be required to undergo a third-party assessment by a notified body rather than relying solely on internal technical documentation and self-declaration.

How to meet it

Evidence an auditor asks for

  • Classification Justification Document: A formal record explaining why the product was categorized as "Uncritical," "Important," or "Critical" with references to the Annexes.
  • Conformity Assessment Certificate: For Critical products, a certificate issued by a notified body confirming compliance.
  • EU Declaration of Conformity: The signed legal document stating the product meets all CRA requirements and specifying its risk class.
  • Technical File: Comprehensive documentation including architecture diagrams, vulnerability assessments, and risk management plans specific to that product class.

Common pitfalls

  • Under-classification: Intentionally or accidentally classifying a "Critical" product as "Important" or "Uncritical" to avoid the cost and time of third-party audits.
  • Static Classification: Failing to re-evaluate the product class when adding new features that might push the device from one category into a higher risk bracket.
  • Ignoring Third-Party Timelines: Starting the notified body assessment process too late in the development cycle, leading to delays in market entry (CE marking).