Is your product in scope of the Cyber Resilience Act (CRA)?
Four questions. The verdict is computed in your browser - nothing is sent anywhere - and every line cites the provision it rests on.
All 26 categories Annex III and Annex IV list
The form above answers for one product. This is the whole map: every category the CRA singles out as important or critical, what the Implementing Regulation says falls in it and the conformity route that follows from 11 December 2027. Core functionality decides which one you are in - the primary purpose the product is on the market for, not a feature it happens to include.
Each summary condenses that category's technical description in Implementing Regulation (EU) 2025/2392, adopted 28 November 2025. It is a summary, not a verbatim quote - the annex point linked beside it is the text that governs.
Annex III - class I - Important, class I
19 categories of important products. Applying harmonised standards in full is what keeps a manufacturer here out of a notified body's hands - and no harmonised standard for the CRA has been published in the Official Journal yet.
Conformity route from 11 December 2027: Notified body, unless harmonised standards are applied in full
Identity management systems and privileged access management software and hardware
Authentication, authorisation and credential lifecycle management, including access control readers and biometric components.
Source: Annex III, class I, point 1; Annex I, class I, point 1
Standalone and embedded browsers
Software that retrieves, renders and interacts with web content by interpreting markup and web protocols.
Source: Annex III, class I, point 2; Annex I, class I, point 2
Password managers
Products storing credentials locally or remotely, with generation, sharing and application integration.
Source: Annex III, class I, point 3; Annex I, class I, point 3
Software that searches for, removes or quarantines malicious software
Anti-virus and anti-malware products detecting and neutralising viruses, worms, ransomware, spyware and trojans.
Source: Annex III, class I, point 4; Annex I, class I, point 4
Products with a virtual private network (VPN) function
Products establishing an encrypted logical tunnel over physical or virtual network resources.
Source: Annex III, class I, point 5; Annex I, class I, point 5
Network management systems
Products monitoring and controlling connected network elements such as servers, routers, switches and end devices.
Source: Annex III, class I, point 6; Annex I, class I, point 6
Security information and event management (SIEM) systems
Products collecting, correlating and analysing security-relevant data for threat detection and forensics.
Source: Annex III, class I, point 7; Annex I, class I, point 7
Boot managers
Software managing system start-up: hardware initialisation and loading of the operating system.
Source: Annex III, class I, point 8; Annex I, class I, point 8
Public key infrastructure and digital certificate issuance software
Products managing issuance, distribution and validation of digital certificates and the related key operations.
Source: Annex III, class I, point 9; Annex I, class I, point 9
Physical and virtual network interfaces
Products providing data-link-layer connectivity through drivers and adapters or their virtual emulation.
Source: Annex III, class I, point 10; Annex I, class I, point 10
Operating systems
Software abstracting hardware and controlling application execution, resource management and scheduling.
Source: Annex III, class I, point 11; Annex I, class I, point 11
Routers, modems intended for the connection to the internet, and switches
Products routing data between networks, converting signals and forwarding packets, with management functions.
Source: Annex III, class I, point 12; Annex I, class I, point 12
Microprocessors with security-related functionalities
Integrated circuits providing encryption, authentication, secure key storage or a trusted execution environment.
Source: Annex III, class I, point 13; Annex I, class I, point 13
Microcontrollers with security-related functionalities
Integrated circuits with on-board memory whose security features include encryption or trusted execution.
Source: Annex III, class I, point 14; Annex I, class I, point 14
ASICs and FPGAs with security-related functionalities
Custom-designed or reprogrammable circuits providing encryption, authentication or secure boot.
Source: Annex III, class I, point 15; Annex I, class I, point 15
Smart home general purpose virtual assistants
Internet-connected products processing natural-language prompts to deliver services and control home devices.
Source: Annex III, class I, point 16; Annex I, class I, point 16
Smart home products with security functionalities
Products protecting residential physical security: door locks, cameras, monitoring and alarm infrastructure.
Source: Annex III, class I, point 17; Annex I, class I, point 17
Internet connected toys
Toys within Directive 2009/48/EC with social interactive features (microphone, camera) or location tracking.
Source: Annex III, class I, point 18; Annex I, class I, point 18
Personal wearable products
Body-worn products monitoring health, or intended for children under 14; medical devices are excluded.
Source: Annex III, class I, point 19; Annex I, class I, point 19
Annex III - class II - Important, class II
4 categories of important products, one step stricter than class I: applying harmonised standards does not remove the notified body from the route.
Conformity route from 11 December 2027: Notified body required
Hypervisors and container runtime systems
Software abstracting compute resources to run virtual machines or containerised applications in isolation.
Source: Annex III, class II, point 1; Annex I, class II, point 1
Firewalls, intrusion detection and prevention systems
Products restricting unauthorised network traffic and detecting or responding to intrusions.
Source: Annex III, class II, point 2; Annex I, class II, point 2
Tamper-resistant microprocessors
Microprocessors with security functionalities resisting physical tampering at AVA_VAN level 2 or 3.
Source: Annex III, class II, point 3; Annex I, class II, point 3
Tamper-resistant microcontrollers
Microcontrollers with security functionalities resisting physical tampering at AVA_VAN level 2 or 3.
Source: Annex III, class II, point 4; Annex I, class II, point 4
Annex IV - critical - Critical
3 categories, the narrowest list in the regulation. Conformity here runs through a European cybersecurity certification scheme rather than a notified body alone.
Conformity route from 11 December 2027: European cybersecurity certification scheme
Hardware devices with security boxes
Multi-component devices with tamper evidence or resistance that store sensitive data or perform cryptographic operations - payment terminals, HSMs, tachographs.
Source: Annex IV, point 1; Annex II, point 1
Smart meter gateways
Products controlling communication within smart metering systems: meter data collection, encryption and firewalling.
Source: Annex IV, point 2; Annex II, point 2
Smartcards or similar devices, including secure elements
Secure microcontrollers or microprocessors at AVA_VAN.4 handling cryptographic operations and identity or payment credentials.
Source: Annex IV, point 3; Annex II, point 3
Not on either list? That is a verdict, not a gap.
Most software is in none of these categories and that is the cheapest outcome the regulation offers: a default-class product self-assesses under Article 32(1) - no notified body, no certification scheme. Being absent from Annex III and Annex IV does not put you outside the CRA. It puts you in the lightest conformity route inside it.
None of this moves the September date. Article 14's 24-hour early warning applies to every product in scope, in every class, default class included - and to products you shipped years ago.