Default, important or critical

Every product with digital elements is in one of three classes. Most are “default” and self-assessed. Annex III names the important ones, in two classes, and Annex IV names the critical ones. The class changes how conformity is assessed and whether a notified body is involved.Art. 7

The class never changes a reporting deadline. The 24-hour, 72-hour and final clocks in Article 14 are the same for a default product and a critical one. What the class changes is the route to the CE marking, and how early you must book the people who sign it off.

Find your category

Search in your own words; the list is matched on plain-language keywords as well as the annex wording. No match usually means default, and the sentence at the end of each list says what to check.

Important, class I

Self-assessment possibleAnnex III class I

Self-assessment, but only if you fully apply the standards. Internal control is available where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full and cover the essential requirements. Where they are not, a third-party procedure applies: EU type-examination followed by conformity to type, or full quality assurance.Art. 32⁠(2)⁠, Annex VIII

  1. Identity management systems, and privileged access management software and hardware, including authentication and access control readers

    identity · sso · iam · pam · authentication · access control · biometric

  2. Standalone and embedded browsers

    browser · webview · chromium · embedded browser

  3. Password managers

    password · vault · secrets manager

  4. Software that searches for, removes or quarantines malicious software

    antivirus · malware · edr · endpoint protection

  5. Products with the function of a virtual private network (VPN)

    vpn · tunnel · wireguard · ipsec

  6. Network management systems

    network management · nms · monitoring · snmp

  7. Security information and event management (SIEM) systems

    siem · log management · security analytics

  8. Boot managers

    bootloader · boot manager · uefi · grub

  9. Public key infrastructure and digital certificate issuance software

    pki · certificate authority · ca · x509

  10. Physical and virtual network interfaces

    nic · network interface · virtual switch

  11. Operating systems

    operating system · os · rtos · linux distribution · firmware os

  12. Routers, modems intended for connection to the internet, and switches

    router · modem · switch · gateway · access point

  13. Microprocessors with security-related functionalities

    microprocessor · cpu · soc

  14. Microcontrollers with security-related functionalities

    microcontroller · mcu

  15. ASICs and FPGAs with security-related functionalities

    asic · fpga · silicon

  16. Smart home general purpose virtual assistants

    voice assistant · smart speaker · virtual assistant

  17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitors and alarm systems

    smart lock · camera · baby monitor · alarm · doorbell

  18. Internet-connected toys with social interactive features or location tracking

    toy · children · tracking

  19. Personal wearables with a health monitoring purpose outside the medical device regulations, or wearables intended for children

    wearable · fitness tracker · smartwatch · health

Important, class II

Notified body requiredAnnex III class II

Third-party assessment. A notified body is required. Class II cannot be self-assessed. You need EU type-examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H), carried out by a notified body. Book this early: the queue, not the assessment, is what sets your launch date.Art. 32⁠(3)⁠, Annex VIII Parts II and III

  1. Hypervisors and container runtime systems supporting virtualised execution of operating systems

    hypervisor · container runtime · kvm · kubernetes runtime · vmm

  2. Firewalls, intrusion detection and prevention systems

    firewall · ids · ips · waf

  3. Tamper-resistant microprocessors

    tamper resistant · secure processor

  4. Tamper-resistant microcontrollers

    tamper resistant · secure element mcu

Critical

Notified body requiredAnnex IV

European cybersecurity certificate, where a delegated act requires one. Critical products may be required by delegated act to hold a European cybersecurity certificate at assurance level "substantial" under an EUCC scheme. Where no such requirement applies, the class II procedures apply instead, so a notified body is involved either way.Art. 8, Art. 32⁠(4)⁠, Annex IV

  1. Hardware devices with security boxes

    hsm · security box · hardware security module

  2. Smart meter gateways, and other devices for advanced security purposes including secure cryptoprocessing

    smart meter · gateway · cryptoprocessor

  3. Smartcards and similar devices, including secure elements

    smartcard · secure element · sim · ese

Default

Self-assessment (internal control, Module A). You assess conformity yourself, draw up the technical documentation and the EU declaration of conformity, and affix the CE marking. No third party is involved.Art. 32⁠(1)⁠, Annex VIII Part I

Everything not in the lists above. The essential requirements of Annex I and the reporting duty in Article 14 apply in full; only the assessment route is lighter.

The class is one of five scope questions

The scope check asks it alongside what you ship, where you sell it and where you are established, and returns the article each part of the verdict rests on.

The lists are transcribed from the Regulation as adopted and reviewed in diffs. The Commission may adjust them by delegated act; the date beside the margin index is when they were last checked. If your product is a non-EU manufacturer’s, the class applies just the same.

This produces evidence, timelines and drafts. It is not legal advice, and you remain the party responsible for reporting.