Fossick › CRA scope check › Important product, class I
Important product class I under the Cyber Resilience Act
The product is listed in Annex III, class I: a category whose compromise gives an attacker material leverage over other systems. Examples include identity and password managers, VPNs, network management systems, SIEM, boot managers, public key infrastructure software, operating systems, routers, modems and switches, microprocessors and microcontrollers with security-related functions, smart home assistants and connected toys.
What the manufacturer must do
- Everything required of a default product: Annex I essential requirements, vulnerability handling, SBOM, risk assessment, reporting, Declaration of Conformity and CE marking.
- In addition, demonstrate conformity through a recognised route rather than a purely internal one where harmonised standards are not applied in full.
- Keep evidence that maps each Annex I requirement to a concrete design or process control, because this file is the object of the assessment.
Which deadlines apply
Reporting duties apply from 11 September 2026. All remaining obligations apply from 11 December 2027. Notified body capacity is finite, so class I products should start the conformity route well before that date.
What the conformity route looks like
Self-assessment is available only if the product is designed and manufactured in full accordance with the relevant harmonised standards or a European cybersecurity certification scheme. Otherwise a third party conformity assessment by a notified body is required (EU type-examination or full quality assurance).
The reporting timeline
The reporting duty is the one that bites first, and it runs on three clocks that all start when the manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting the security of the product.
- 24 hours — early warning to ENISA and the CSIRT designated as coordinator in the Member State of main establishment.
- 72 hours — full notification, with an assessment of the vulnerability or incident and any corrective or mitigating measures taken.
- 14 days — final report once a corrective or mitigating measure is available: a description of the vulnerability, its severity and impact, and where available the exploitation vector.
The 14 day clock runs from the availability of the fix, not from the initial awareness, so a long remediation does not remove the earlier two deadlines.
Products already on the market are reached too
The reporting duty is not limited to new launches. From 11 September 2026 it applies to products with digital elements that are already placed on the EU market, for the whole time the manufacturer supports them. A product shipped in 2024 and still supported in 2027 is inside the regime, even though it was designed before it existed. The full set of obligations, including the technical documentation and CE marking, applies to products placed on the market from 11 December 2027, and to substantially modified versions of existing products after that date.
Check another product
This is guidance, not a legal determination. Classification under the Cyber Resilience Act depends on the full technical description of your product and, in borderline cases, on the assessment of a notified body or your national market surveillance authority.