Default, important or critical
Every product with digital elements is in one of three classes. Most are “default” and self-assessed. Annex III names the important ones, in two classes, and Annex IV names the critical ones. The class changes how conformity is assessed and whether a notified body is involved.Art. 7
The class never changes a reporting deadline. The 24-hour, 72-hour and final clocks in Article 14 are the same for a default product and a critical one. What the class changes is the route to the CE marking, and how early you must book the people who sign it off.
Find your category
Search in your own words; the list is matched on plain-language keywords as well as the annex wording. No match usually means default, and the sentence at the end of each list says what to check.
Self-assessment, but only if you fully apply the standards. Internal control is available where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full and cover the essential requirements. Where they are not, a third-party procedure applies: EU type-examination followed by conformity to type, or full quality assurance.Art. 32(2), Annex VIII
Identity management systems, and privileged access management software and hardware, including authentication and access control readers
identity · sso · iam · pam · authentication · access control · biometric
Standalone and embedded browsers
browser · webview · chromium · embedded browser
Password managers
password · vault · secrets manager
Software that searches for, removes or quarantines malicious software
antivirus · malware · edr · endpoint protection
Products with the function of a virtual private network (VPN)
vpn · tunnel · wireguard · ipsec
Network management systems
network management · nms · monitoring · snmp
Security information and event management (SIEM) systems
siem · log management · security analytics
Boot managers
bootloader · boot manager · uefi · grub
Public key infrastructure and digital certificate issuance software
pki · certificate authority · ca · x509
Physical and virtual network interfaces
nic · network interface · virtual switch
Operating systems
operating system · os · rtos · linux distribution · firmware os
Routers, modems intended for connection to the internet, and switches
router · modem · switch · gateway · access point
Microprocessors with security-related functionalities
microprocessor · cpu · soc
Microcontrollers with security-related functionalities
microcontroller · mcu
ASICs and FPGAs with security-related functionalities
asic · fpga · silicon
Smart home general purpose virtual assistants
voice assistant · smart speaker · virtual assistant
Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems
smart lock · camera · baby monitor · alarm · doorbell
Internet-connected toys with social interactive features or location tracking
toy · children · tracking
Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children
wearable · fitness tracker · smartwatch · health
Third-party assessment. A notified body is required. Class II cannot be self-assessed. You need EU type-examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H), carried out by a notified body. Book this early: the queue, not the assessment, is what sets your launch date.Art. 32(3), Annex VIII Parts II and III
Hypervisors and container runtime systems supporting virtualised execution of operating systems
hypervisor · container runtime · kvm · kubernetes runtime · vmm
Firewalls, intrusion detection and prevention systems
firewall · ids · ips · waf
Tamper-resistant microprocessors
tamper resistant · secure processor
Tamper-resistant microcontrollers
tamper resistant · secure element mcu
European cybersecurity certificate, where a delegated act requires one. Critical products may be required by delegated act to hold a European cybersecurity certificate at assurance level "substantial" under an EUCC scheme. Where no such requirement applies, the class II procedures apply instead, so a notified body is involved either way.Art. 8, Art. 32(4), Annex IV
Hardware devices with security boxes
hsm · security box · hardware security module
Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing
smart meter · gateway · cryptoprocessor
Smartcards and similar devices, including secure elements
smartcard · secure element · sim · ese
Default
Self-assessment (internal control, Module A). You assess conformity yourself, draw up the technical documentation and the EU declaration of conformity, and affix the CE marking. No third party is involved.Art. 32(1), Annex VIII Part I
Everything not in the lists above. The essential requirements of Annex I and the reporting duty in Article 14 apply in full; only the assessment route is lighter.
The class is one of five scope questions
The scope check asks it alongside what you ship, where you sell it and where you are established, and returns the article each part of the verdict rests on.
The lists are transcribed from the Regulation as adopted and reviewed in diffs. The Commission may adjust them by delegated act; the date beside the margin index is when they were last checked. If your product is a non-EU manufacturer’s, the class applies just the same.
This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.