Most CRA planning I see quietly assumes self-assessment all the way through. For part of the portfolio that assumption is wrong, and the class that breaks it is the one nobody classified.
The Cyber Resilience Act — Regulation (EU) 2024/2847 — sorts every product with digital elements into one of three tiers, and the tier decides how you are allowed to prove conformity. Default products can be self-assessed. Important products may need a third party. Critical products cannot avoid one. That single classification changes your cost, your timeline, and whether an external body sits on the critical path to shipping. The regulation applies in full from 11 December 2027, and a notified-body engagement is not something you start three months out. Which is why the classification is the first piece of work, not the last.
The tier is the decision, not a label
Teams treat classification as a documentation exercise — a field to fill in on the technical file. It is not. It is the branch point that determines the entire conformity route. If you have not confirmed the scope question first — that the thing is a product with digital elements in the CRA sense at all — classification is premature. But once you are in scope, the class is what tells you whether an engineering team can close the assessment on its own or whether you have booked capacity with an external assessor that does not yet exist for your product type.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
The three tiers map to conformity procedures set out in Article 32 and Annex VIII. Default products — the large majority — can use internal control, Module A, which is self-assessment: you compile the technical documentation, you affix the CE marking, no external party signs anything. Important products, listed in Annex III under Article 7, come in two classes. Critical products, listed in Annex IV under Article 8, sit at the top and carry the heaviest route. The words “important” and “critical” are not marketing adjectives; they are legal categories with specific consequences.
How the three tiers actually differ
Important, class I covers products whose compromise is serious but not systemic — password managers, standalone and embedded browsers, VPN products, network management and SIEM systems, boot managers, and microcontrollers with security-related functions, among others in Annex III. Class I is the tier that offers a conditional escape: you may still self-assess under Module A, but only if you fully apply the relevant harmonised standards, common specifications, or a European cybersecurity certification scheme that covers the Annex I essential requirements. Apply them partially, or find that no harmonised standard has been published for your product type, and the escape closes — you fall to a third-party route.
Important, class II covers higher-impact categories — hypervisors and container runtimes, firewalls and intrusion detection and prevention systems intended for industrial use, tamper-resistant microprocessors and microcontrollers. Class II has no self-assessment option at all. Standards or not, you use EU-type examination followed by conformity to type (Module B plus Module C), or full quality assurance (Module H), or a European cybersecurity certification scheme at assurance level at least “substantial”. Every one of those routes involves a notified body or a certification body. There is no internal-only path.
Critical products in Annex IV are a short, specific list: hardware devices with security boxes; smart meter gateways and other devices for advanced security purposes including secure cryptoprocessing; and smartcards or similar devices, including secure elements. For these the Commission can, by delegated act under Article 8, require a European cybersecurity certificate under the EUCC scheme. Where it has not mandated certification, you fall back to the class II procedures — so the floor for a critical product is still a third party. The ceiling is a mandatory certificate.
The Commission published the technical descriptions of these categories in Implementing Regulation (EU) 2025/2392, which is the document to classify against rather than the plain-language annex headings. Recent clarifications there pulled consumer-facing categories — smart home assistants, smart door locks, cameras and baby monitors, internet-connected toys with interactive or tracking features, and health or child wearables — explicitly into the important classes, which caught out vendors who had assumed “consumer” meant “default”.
Where the route changes cost and timeline
The gap between a self-assessed default product and a class II product is not incremental. A notified-body engagement adds a body you do not control to your release path: their queue, their document requests, their examination cycle, their audit of your quality system if you take the Module H route. Notified bodies for the CRA only began to be designated from 11 June 2026, capacity is finite, and the categories that need them most are competing for the same assessors. A firm that discovers in mid-2027 that one of its products is class II is not looking at a few weeks of paperwork — it is looking at joining a queue for a resource in short supply, ahead of a hard deadline.
The self-assessment trap for class I is subtler and just as expensive. A team assumes Module A applies, builds the plan around it, and only later checks whether a harmonised standard actually exists and is fully applicable to their product. If it does not, the class I product needs Module B plus C or H after all — the same notified-body queue, discovered later. The conditional nature of the class I self-assessment route is precisely what makes it dangerous: it looks like the default path until you test the condition.
Run the classification across the whole portfolio, now
The work is a portfolio pass, not a per-product afterthought. Take every product with digital elements you place on the EU market, match it against the technical descriptions in Annex III and Annex IV, and record the class and the resulting route. For class I, note whether a harmonised standard exists and whether you can apply it in full — if not, treat the product as needing a third party and plan accordingly. For anything class II or critical, get into the notified-body conversation early rather than late. This sits alongside the Annex I risk assessment that every product needs regardless of class, and it does not merge with your NIS2 obligations — the CRA governs the product, NIS2 governs the entity, and the two run as separate programmes. The output is a portfolio map that tells you, product by product, which route you are on and where an external body sits on your critical path to the December 2027 conformity deadline.
The classification is the cheapest hour of CRA work you will spend and the one that reprices everything after it. The firms that get caught are not the ones that classified wrongly — they are the ones that assumed self-assessment and never classified at all.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming