Core functionality mapped to Annexes III and IV, with the technical description from Implementing Regulation 2025/2392. And what that means for conformity.
Classification builds on what is explained in theguide to the CRA
The product category decides one practical thing: whether you run the conformity assessment yourselves or a notified body has to be involved. It is decided by the core functionality of the product as a whole (Article 7(1)), not by everything the product can do. Three steps, and the result is there.
The tool assumes the product falls within the scope of the regulation and that you are its manufacturer — the scope and role calculator confirms both. Classification is judged against the technical description of the categories in Implementing Regulation (EU) 2025/2392; we do not reproduce the legal text here, but every statement comes with the article or annex where you can verify it.
An orientation aid, not a legal assessment
The result is an orientation aid, not a legal assessment and not an official determination. Classifying a specific product turns on details of its core functionality and design that no form can capture — borderline cases need an assessment of the individual product, and possibly an opinion from a lawyer. What is binding is the text of Regulation (EU) 2024/2847 and Implementing Regulation (EU) 2025/2392 in the Official Journal; the links are in the Official sources section. CypherOn is a cybersecurity consultancy, not a law firm.
1Area
2Category
3Checks
4Result
Which area does the core functionality of the product fall into?
The core functionality is what the customer buys the product for — not a list of everything the product can do. This step only narrows down the list of categories; the decision comes in the next two.
Which category describes that functionality?
The categories are named in Annexes III and IV of the regulation, and Implementing Regulation (EU) 2025/2392 added a technical description for each. Pick the one that matches the core functionality of the product as a whole.
Confirming the classification
Two things that classification most often fails on: whether the selected function really is the core functionality of the whole, and whether the product matches the technical description of the category down to the detail that decides the class.
Selected category
An indicative result. It does not replace a legal assessment or an official determination, and borderline cases need an individual assessment.
What to do next
This output is an orientation aid, not a legal assessment. It is based solely on what you entered in the form; the actual classification of a product turns on details of its core functionality and design that a form cannot capture. Borderline cases need an individual assessment, and what is binding is the text of Regulation (EU) 2024/2847 and Implementing Regulation (EU) 2025/2392.
CypherOn provides cybersecurity consulting services and is not a law firm. For legal opinions, turn to an attorney registered with the Czech Bar Association.
When the result comes out as an important or critical product
Annex I requirements go into development, not into documents.
Product threat modelling, secure development reviews, vulnerability management and inputs for the technical documentation under Annex VII. Tell us how the classification came out and where you stand.
Google Analytics loads even without your consent — without it, it runs in a limited, cookie-less mode, but Google still sees your IP address. Consent enables analytics cookies. We do not sell personal data; who we pass it to is described in the privacy policy.