Skip to the main content
SentinelSphere CRA

All posts

Which group is your product in? A ten-minute check

Ordinary, important or critical: the group decides who checks your work. Six steps to a defensible answer, and the record that makes it stick.

· 5 min read · By DASKALOS APPS

  • product groups
  • CE marking
  • scope

Why the group matters

Every covered product has to be equally secure. What the group changes is who checks that it is: you, an outside body, or a formal certification scheme.

Default products may self-assess their conformity; important products (Annex III, class I and class II) and critical products (Annex IV) follow stricter conformity routes.[Arts. 7, 8, 32; Annexes III, IV]

It also decides whether we are the right people to help you. We work on ordinary products, which is most of what a small manufacturer makes, and we say so plainly when a product belongs somewhere else.

Ten minutes with the steps below gets most products to a defensible answer. The last step, writing down why, is the one people skip and the one an inspector asks about.

Step 1: is the product covered at all?

The group only matters if the law covers the product. Three questions:

  • Does it have software in it, and can it connect to a device or a network, directly or indirectly? A product with digital elements is a software or hardware product and its remote data processing solutions, including software or hardware components placed on the market separately.[Art. 3(1)]
  • Do you make it available in the EU in the course of doing business? The Regulation applies to products with digital elements made available on the Union market in the course of a commercial activity, whatever the size or place of establishment of the manufacturer.[Art. 2(1); Art. 3]
  • Is it already covered by another rulebook that takes over? Products already covered by the medical device, in-vitro diagnostic, motor vehicle type-approval, civil aviation and marine equipment regimes, and products developed exclusively for national security or defence, are outside the scope of the Cyber Resilience Act.[Art. 2]

Yes, yes, no means carry on. If you are unsure about the cloud half of a product, or about open source with money around it, use the scope check or get a scoping memorandum.

Step 2: write down what the product does

Not what it is for — what functions it has. The groups are defined by function, and one box can have three of them. A building controller that also terminates a VPN and serves a configuration page has three functions to check, not one.

List them in ordinary words: "moves traffic between two networks", "stores passwords", "manages other devices", "takes payments", "runs other people's code", "controls a physical lock".

Step 3: compare each function with the lists

The law lists the products that count as important or critical.

Important products with digital elements are listed in Annex III in two classes; the Commission may update the list by delegated act.[Art. 7; Annex III] Critical products with digital elements are listed in Annex IV and may be required by delegated act to obtain a European cybersecurity certificate.[Art. 8; Annex IV]

If none of your functions matches, the product is ordinary. If one matches, the product takes that group, and where two functions match different classes, the stricter one wins.

Important, class I:

Annex III class I includes, among others, identity and access management software, browsers, password managers, anti-malware software, VPN products, network management systems, SIEM systems, boot managers, public-key infrastructure software, operating systems, routers and modems intended for internet connection, microprocessors and microcontrollers with security-related functions, smart home products with security functions such as locks, cameras and alarms, connected toys with social interaction or location tracking, and personal wearable health-monitoring products.[Annex III, Class I]

Important, class II:

Annex III class II includes hypervisors and container runtime systems, firewalls and intrusion detection or prevention systems, and tamper-resistant microprocessors and microcontrollers.[Annex III, Class II]

Critical:

Annex IV (critical products) covers hardware devices with security boxes, smart meter gateways, and smartcards or similar devices including secure elements.[Annex IV]

Two traps. A product that merely contains a listed component is not automatically in that class; what counts is whether the listed function is what the product is. A machine running embedded Linux that happens to include a firewall package is not a firewall. And "general purpose" does not mean ordinary: an operating system, or a general-purpose chip with security functions, is on the list.

A worked example

An industrial gateway: embedded Linux, the vendor's own firmware, a web page for configuration, a data feed to the customer's system, and a VPN client used only to fetch updates.

Its functions: collect sensor data, forward it, serve a configuration page, run a VPN client, update itself. For each one, ask whether the gateway is that kind of product or merely uses that kind of part. A gateway forwarding its own sensor data is not a router as a product category, and a VPN client used for updates does not make it a VPN product. A gateway sold to route traffic between a customer's networks would be a different conversation.

The scoping memorandum records which of those it is, why, and how confident you are. That is the difference between a defensible answer and a guess.

Step 4: read off who checks your work

Conformity assessment uses the modules in Annex VIII: internal control (Module A) for default products; important class I products may use internal control only when applying harmonised standards, common specifications or a certification scheme; important class II products need a third party (Modules B and C, or H).[Art. 32; Annex VIII]

In practice:

  • Ordinary: you check your own work. You do the risk assessment, write the paperwork, keep the evidence and sign the declaration.
  • Important, class I: you can still check your own work, but only if you follow the relevant European standards in full. Products that conform to harmonised standards published in the Official Journal are presumed to conform to the essential requirements those standards cover.[Art. 27] No harmonised standard for the Cyber Resilience Act has been published in the Official Journal yet, so no presumption of conformity is available and controls are versioned against the drafts.[Status at date of verification] Until they are published, plan for an outside body.
  • Important, class II: an outside body checks it.
  • Critical: a formal European certificate may be required.

Step 5: the dates do not change

Your group does not move the deadlines.

Manufacturers' reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026.[Art. 71(2); Art. 14] The main obligations of the Cyber Resilience Act (essential requirements, technical documentation, conformity assessment, CE marking, importer and distributor duties) apply from 11 December 2027.[Art. 71(2)]

What it changes is how long the route takes. An outside body needs capacity in its diary and a finished folder of paperwork well before the second date.

Step 6: write down why

This is the step that turns ten minutes into evidence. Record:

  • the products and versions the decision covers;
  • each function you identified, and the group you compared it with;
  • the group you concluded, with the reference, or "not listed" for ordinary;
  • how confident you are and why: a clear match, a clear miss, or a line you had to interpret;
  • who decided, and when.

Put it with your paperwork. When the European standards are published, or the lists change, review it and record the review. A group with no written reasoning is the first thing an inspector pulls on.

What changes if you are not ordinary

Budget, lead time and reader. The paperwork has to be finished earlier because somebody else will read it, and the standards you apply become a contractual matter with them. We do not run those checks and we are not a certification body. If your product lands there, we say so in the memo and tell you what the route involves, rather than quietly carrying on. The engineering work that comes first is the same either way.

The checklist

  • The product is confirmed as covered, with the reason.
  • Every function of the product is listed in ordinary words.
  • Each function has been compared with the important and critical lists, and the result written down.
  • The group and its reference are recorded, or "not listed".
  • Who checks your work is recorded.
  • Confidence and reasoning are recorded, with a name and a date.
  • A reminder is set for when the European standards are published or the lists change.

If you want help

This post is written so you can do it yourself, and most of the work is reading your own product honestly. If you would rather have an engineer do it and put a name on the result, that is our scoping and classification memo: covered or not, the group, who checks your work, how long to support the product, the dates and three next steps, for each product line. You send the product details when it suits you and the signed memo comes back in writing.

Book a scoping call

One useful thing a month

A short email about the regulation and the engineering behind it. No sequences, no pressure.

Not sure where you stand?

Answer six questions and find out whether the law reaches your product.