Classification · CRA / 2024/2847

ORDINARY, IMPORTANT, OR CRITICAL?

Core functionality mapped to Annexes III and IV, with the technical description from Implementing Regulation 2025/2392. And what that means for conformity.

Classification builds on what is explained in the guide to the CRA

The product category decides one practical thing: whether you run the conformity assessment yourselves or a notified body has to be involved. It is decided by the core functionality of the product as a whole (Article 7(1)), not by everything the product can do. Three steps, and the result is there.

The tool assumes the product falls within the scope of the regulation and that you are its manufacturer — the scope and role calculator confirms both. Classification is judged against the technical description of the categories in Implementing Regulation (EU) 2025/2392; we do not reproduce the legal text here, but every statement comes with the article or annex where you can verify it.

An orientation aid, not a legal assessment The result is an orientation aid, not a legal assessment and not an official determination. Classifying a specific product turns on details of its core functionality and design that no form can capture — borderline cases need an assessment of the individual product, and possibly an opinion from a lawyer. What is binding is the text of Regulation (EU) 2024/2847 and Implementing Regulation (EU) 2025/2392 in the Official Journal; the links are in the Official sources section. CypherOn is a cybersecurity consultancy, not a law firm.
1Area
2Category
3Checks
4Result

Which area does the core functionality of the product fall into?

The core functionality is what the customer buys the product for — not a list of everything the product can do. This step only narrows down the list of categories; the decision comes in the next two.

What does the product mainly do?

What counts is the core functionality of the product as a whole. An embedded component that would fall into one of the categories on its own does not turn the product into an important product (Article 7(1)) — a browser inside a news application does not make the application a browser, and a smartphone is not an operating system merely because it contains one (recitals 3 and 5 of Implementing Regulation 2025/2392).

Which category describes that functionality?

The categories are named in Annexes III and IV of the regulation, and Implementing Regulation (EU) 2025/2392 added a technical description for each. Pick the one that matches the core functionality of the product as a whole.

Select the category that matches the core functionality

Each category is shown with its technical description under Implementing Regulation (EU) 2025/2392. The fact that a product performs other functions alongside its core functionality does not take it out of the category (recital 4 of the same regulation).

Confirming the classification

Two things that classification most often fails on: whether the selected function really is the core functionality of the whole, and whether the product matches the technical description of the category down to the detail that decides the class.

Selected category

An indicative result. It does not replace a legal assessment or an official determination, and borderline cases need an individual assessment.

What to do next

    This output is an orientation aid, not a legal assessment. It is based solely on what you entered in the form; the actual classification of a product turns on details of its core functionality and design that a form cannot capture. Borderline cases need an individual assessment, and what is binding is the text of Regulation (EU) 2024/2847 and Implementing Regulation (EU) 2025/2392.

    Does the CRA apply to your product?

    The scope of the regulation and your role in the supply chain: manufacturer, importer, distributor or open-source software steward. The product category comes only as the second step.

    Open the calculator

    Guide to the CRA

    The staggered deadlines under Article 71, who counts as a manufacturer, the Annex I requirements, the software bill of materials, the support period and reporting under Article 14.

    Open the guide

    The regulation, interactively

    The articles and annexes of Regulation (EU) 2024/2847 with practical notes, including Annexes III and IV and the related Implementing Regulation 2025/2392.

    Open the regulation

    Official sources

    The decision logic of the tool is based on these sources, as at 9 August 2026. What is binding is the text of the legislation, not our reading of it.

    Regulation (EU) 2024/2847 (Cyber Resilience Act) ↗ The English language version; all language versions are equally authentic. Scope and exclusions Article 2, requirements for products Article 6, important products and the core functionality rule Article 7, critical products Article 8, presumption of conformity Article 27, EU declaration of conformity Article 28, CE marking Article 30, technical documentation Article 31, conformity assessment procedures Article 32, modules A, B, C and H Annex VIII, transitional provisions Article 69, application Article 71, category lists Annexes III and IV. Commission Implementing Regulation (EU) 2025/2392 ↗ The technical description of the categories of important and critical products, adopted under Article 7(4) of Regulation 2024/2847. Of 28 November 2025, published 1 December 2025, in force since 21 December 2025. Annex I describes the Annex III categories (class I and II), Annex II the Annex IV categories. Recitals 2 to 7 deal with core functionality, integrated components, ancillary functions and the illustrative nature of the examples. Commission Implementing Regulation (EU) 2024/482 (EUCC scheme) ↗ The European cybersecurity certification scheme based on common criteria. The source of the definition of the common criteria and the common evaluation methodology referenced in Article 1 of Implementing Regulation 2025/2392 — and thereby of the AVA_VAN levels that separate class II from Annex IV. Commission — CRA implementation ↗ An overview of the implementing and delegated acts and their status. The source for the statement that the delegated act on European cybersecurity certification schemes under Article 27(9) is planned for Q4 2026 and has not been adopted as at 9 August 2026. Commission — CRA standardisation ↗ The status of harmonised standards and standardisation request M/606 with its 41 standards. The source for the statement that as at 9 August 2026 no references to any harmonised standard for the CRA have been published in the Official Journal and that the first standardisation deliverables are expected in Q3 2026. Commission guidance on the application of the CRA (27 July 2026) ↗ Communication C(2026) 5252 — scope, remote data processing solutions, open source, substantial modification, the support period, reporting and risk assessment. Non-binding, but the best available guidance on borderline questions of scope.
    Content valid as of 9 August 2026

    When the result comes out as an important or critical product

    Annex I requirements go
    into development,
    not into documents.

    Product threat modelling, secure development reviews, vulnerability management and inputs for the technical documentation under Annex VII. Tell us how the classification came out and where you stand.