Guides · Updated 27 July 2026

CRA classification for 20 common connected products

A table you can find your own product in, built from the technical descriptions the Commission published in Implementing Regulation (EU) 2025/2392 rather than from the category names alone.

The short answer

Most connected products are default products and can be self-assessed under module A. The exceptions are specific: routers, modems and switches, operating systems, smart home products with security functionalities, smart home virtual assistants, internet-connected toys with social or location features, health wearables outside the medical device rules, network interfaces, and microcontrollers or microprocessors with security-related functionalities are all Annex III Class I. Hypervisors, container runtimes, firewalls, intrusion detection and prevention systems and tamper-resistant chips designed to AVA_VAN 2 or 3 are Class II. Hardware devices with security boxes, smart meter gateways and secure elements designed to at least AVA_VAN.4 are Annex IV critical. Classification is decided by the product’s core functionality, so a component from a listed category inside your product does not classify the whole product.

Read this before the table

The category names in Annex III and Annex IV are short. "Network management systems" tells a firmware engineer almost nothing about whether their gateway is one. In November 2025 the Commission published Implementing Regulation (EU) 2025/2392, which gives the technical description of every category, plus the rule that decides how to apply them.

That rule, recital (2): the core functionality of the product decides whether it meets a category description. Not what is inside it. Not what it is capable of. So before you look for your product in the table below, ask what the product is for, and answer about the whole product rather than about its most interesting part.

The act gives its own examples of the trap. Embedding a browser into a news app does not make the news app a browser. A smartphone contains an operating system and a password manager and is generally neither. SOAR software can do what a SIEM does and is generally not a SIEM. Meanwhile a router with a firewall in it is still a router, and an operating system with a browser in it is still an operating system.

The table

Classification first, then the reason. Where a product is a default product, that is a real answer and the most common one.

Default products, self-assessed under module A

  • Connected industrial sensor or actuator. It measures or actuates. Being on a network does not put it in any Annex III category.
  • Smart thermostat or connected HVAC controller. Comfort control is not a security functionality, so Annex III Class I item 17 does not reach it.
  • Connected appliance: fridge, washing machine, oven. Same reasoning.
  • Smart lighting, bulbs and controllers. No security function, no category.
  • EV charger. It moves power and talks to a back end. Not a listed category on its own.
  • Agricultural or environmental telemetry device. Sensing and reporting.
  • Fitness band with no health monitoring. If it counts steps and does not sense body metrics relevant to health, item 19 does not apply. If it tracks heart rate or blood oxygen, it does.
  • Point of sale terminal that is not a payment terminal. If it has a hardware security envelope and does cryptographic operations, see Annex IV below.

Annex III Class I: self-assessment only if you apply the harmonised standards in full

  • Home or business router, cable, DSL, fibre or cellular modem, managed switch, wireless access point. Item 12, and the technical description names bridges such as wireless access points explicitly.
  • Any product whose core functionality is an operating system, including a real-time operating system shipped as a product. Item 11.
  • Smart door lock, home security camera, baby monitor, alarm system, and the hub or app that centrally controls them. Item 17.
  • Smart speaker with an integrated general-purpose virtual assistant. Item 16.
  • Internet-connected toy with a microphone, speaker, camera or keyboard, or with location tracking. Item 18. A toy that only senses that a user is nearby does not count as location tracking; the act says so in terms.
  • Health-monitoring wearable outside the medical device and IVD regulations, and any wearable intended for use by and for children under 14. Item 19.
  • Wi-Fi, Ethernet, Bluetooth, Zigbee or Fieldbus network interface cards, controllers and adapters, sold as products. Item 10.
  • Microcontroller or microprocessor with security-related functionalities aimed at protecting things beyond the chip itself: secure key storage, a trusted execution environment, a secure boot chain. Items 13 and 14, subject to the AVA_VAN question below.
  • VPN client, server or gateway. Item 5.
  • Boot manager, including UEFI firmware and multi-stage boot loaders. Item 8.

Annex III Class II: no self-assessment at any level of standards adoption

  • Hypervisor, bare metal or hosted, and container runtime systems. Item 1.
  • Network or web application firewall, anti-spam gateway, intrusion detection or prevention system, network-based or host-based. Item 2.
  • Tamper-resistant microprocessor or microcontroller: the Class I chip plus tamper evidence, resistance or response, designed to AVA_VAN level 2 or 3. Items 3 and 4.

Annex IV critical: a European cybersecurity certification scheme

  • Payment terminal, hardware security module, tachograph: hardware with a physical envelope providing tamper evidence, resistance or response. Point 1.
  • Smart meter gateway in an electricity, gas or heat metering system. Point 2.
  • Secure element or smartcard: designed to at least AVA_VAN.4. Includes TPMs, embedded and replaceable UICCs, payment and access cards, identity and travel documents. Point 3.

The chip question, because one number moves you three tiers

A microcontroller with security-related functionalities is Class I. The same part with tamper evidence, resistance or response designed to AVA_VAN 2 or 3 is Class II. Designed for at least AVA_VAN.4, it is a secure element and it is Annex IV. AVA_VAN is the Common Criteria vulnerability assessment level, and 2025/2392 recital (8) chose it because it is standardised, published, and already underpins the EUCC scheme.

None of that appears in the CRA itself. If you build silicon and you have been classifying from Annex III alone, this is the paragraph to act on.

What this changes about your conformity route, and what it does not

Classification decides your conformity assessment procedure under Article 32 and nothing else. Recital (6) of the same act is explicit that the Article 13(2) and 13(3) risk assessment applies to every product with digital elements, and that the manufacturer must evaluate the security of the whole product, taking the integrated components into account.

So the browser you embedded stays out of your classification and stays firmly inside your risk assessment. Record both decisions. A technical file that shows which categories were considered and set aside, with the reason, answers a question a market surveillance authority would otherwise have to ask you.

One exclusion worth knowing

Delegated Regulation (EU) 2025/1535 excludes products within the scope of Regulation (EU) No 168/2013, the L-category two- and three-wheel vehicles and quadricycles, because UN Regulation No 155 covers their cybersecurity to at least the same level. The exclusion does not extend to L1e vehicles designed to pedal, which were left out of the compulsory application of UN Regulation No 155. An electric moped is outside the CRA. A pedal-assist e-bike is inside it.

Questions people actually ask

Is my smart thermostat an important product under the CRA?

Generally no. Annex III Class I item 17 covers smart home products with security functionalities, which the implementing regulation describes as products protecting the physical security of consumers in a residential setting. A thermostat controls comfort, so it is normally a default product and can be self-assessed under module A.

Does having a Wi-Fi chip in my product make it Annex III Class I?

No. Item 10 covers network interfaces placed on the market as products. A module inside your product is a component, and Implementing Regulation (EU) 2025/2392 recital (3) is clear that an integrated component does not classify the product as a whole. Your risk assessment still has to cover it.

Is an EV charger a critical product?

No. Annex IV point 2 covers smart meter gateways within smart metering systems as defined in Article 2(23) of Directive (EU) 2019/944. A charger that meters and reports its own consumption is not a smart meter gateway.

Is a smartwatch an Annex III Class I product?

It is if it senses body metrics relevant to health, under item 19, or if it is intended for use by and for children under 14. A watch that only tells the time and counts steps is not covered by item 19, and having an operating system inside it does not make it an operating system.

Are e-bikes covered by the Cyber Resilience Act?

Pedal-assist L1e vehicles are. Delegated Regulation (EU) 2025/1535 excludes L-category vehicles under Regulation (EU) No 168/2013 from the CRA, but expressly does not extend that exclusion to L1e category vehicles designed to pedal.