- Tobiáš Trnka
- 13 min read
What are products with digital elements under the Cyber Resilience Act (CRA), and why does their category matter? In practice, a product’s category determines how its manufacturer must demonstrate compliance with the CRA. This includes how detailed the required documentation must be, whether an internal conformity assessment is sufficient, or whether the manufacturer must involve a third party or use a European cybersecurity certification scheme. What product categories does the CRA define, and what conformity assessment modules are available?
What are products with digital elements under the CRA
The concept of a product with digital elements is central to the entire CRA. It is from these products that the individual obligations arise. If a company neither manufactures, imports nor supplies such a product, the CRA typically does not apply to it. So what exactly does the term cover?
The definition of products with digital elements is relatively broad. Put simply, it covers software or hardware with a direct or indirect data connection to another device or network. This may be a standalone software product, a physical device with software, an IoT device, but also a software or hardware component, provided it is placed on the market separately.
Another relevant factor is whether the product uses what is known as a remote data processing solution, for example the cloud-based part of a service. This applies where such a solution is essential for one of the product's functions and has been designed by the manufacturer. A product with digital elements therefore need not be merely a standalone physical device or an application in the narrow sense. It will often be a broader solution combining hardware, software, a mobile or web application, remote management or a cloud interface.
The CRA deliberately does not apply to all products with digital elements, however. Excluded are those products already governed by their own sector-specific EU legislation. The aim is to avoid duplicate rules and regulatory overlaps. Specifically, the CRA does not apply, for example, to medical devices and in vitro diagnostic medical devices, motor vehicles and their components falling under the General Safety Regulation, certain certified civil aviation products, or marine equipment.
In addition to these sectoral exemptions, the CRA also does not apply to products developed or modified exclusively for national security or defence purposes, or to products specifically designed to process classified information. Spare parts intended to replace identical components manufactured to the same specifications are excluded as well. If your product falls into one of these categories, the CRA obligations do not apply to it. It remains subject to the rules of the relevant sectoral legislation, however.
Why product classification matters
The CRA does not only address whether it applies to a product with digital elements at all. It also distinguishes between different categories of these products. It is the assignment to the correct category that determines which obligations will apply to the product and how demanding it will be to demonstrate conformity. The CRA divides products into the following categories:
Other products with digital elements (the vast majority of the market) – the manufacturer verifies the product's security themselves.
Important products, class I (for example, password managers, browsers, VPNs, or routers for home use) – in most cases, security must be verified by an independent third party.
Important products, class II (for example, firewalls or hypervisors) – involving an independent third party is always mandatory.
Critical products (for example, hardware security devices or smart cards) – these require European cybersecurity certification under the Cybersecurity Act.
For ordinary products, internal assessment may be sufficient. For important and critical products, the procedure is stricter. For the precise definition of products, we recommend checking Commission Implementing Regulation (EU) 2025/2392 on the technical description of the categories of important and critical products with digital elements. Its annexes set out the individual product categories and their descriptions in detail.
How to choose the right conformity assessment module
The CRA sets out several routes for demonstrating that a product meets the essential cybersecurity requirements. Which route is mandatory for a given product depends mainly on the category it falls into under the Regulation.
In the following paragraphs we use the term notified body. This is an independent organisation designated by the state that assesses whether products meet the requirements of European legislation. In simple terms, it can be thought of as an accredited testing laboratory or auditor. Which specific bodies will perform this role has not yet been firmly established.
The CRA uses the following modules for conformity assessment:
Module A – conformity assessment based on internal control
The manufacturer assesses conformity entirely on their own, without involving a notified body. They are responsible for meeting the essential requirements of the CRA, maintaining the technical documentation, drawing up the declaration of conformity and affixing the CE marking.
This module is the simplest and least expensive route. However, it is available only for other (general) products, and for important products in class I where the manufacturer applies harmonised standards in full.
Module B – EU type-examination
The manufacturer submits the technical documentation, a risk assessment and a sample of the product to a selected notified body. The notified body examines and tests the product. If the product meets the essential requirements of the CRA, the notified body issues an EU type-examination certificate. This serves as official evidence that the specific design type has undergone independent verification.
Module B alone is not sufficient. It must always be complemented by Module C.
Module C – conformity to type based on internal production control
Module C follows on from Module B. Its purpose is to ensure that every manufactured unit conforms to the approved type set out in the certificate. The manufacturer takes the necessary measures during production, checks the conformity of individual products, affixes the CE marking and draws up the declaration of conformity, which they retain for ten years or for the support period of the product.
The combination of Modules B+C therefore means: independent verification of the type and manufacturer-controlled verification of series production.
Module H – conformity based on full quality assurance
Under Module H, it is not just the specific product type that is assessed. The notified body audits the manufacturer's entire quality system, covering design, development, production, inspection and vulnerability handling procedures. Once the manufacturer's quality system has been approved, the manufacturer can guarantee conformity for an entire category of their products. At the same time, however, they are subject to ongoing surveillance audits.
Module H is more demanding to implement, but it offers greater flexibility for companies with a broader product portfolio or frequent updates.
Assessment based on harmonised standards and European certification
Alongside the modules described above, there is one further alternative route. Where the manufacturer applies harmonised standards, common specifications or a European cybersecurity certification scheme at least at assurance level "substantial" in full when designing the product, a presumption of conformity with the essential requirements of the CRA applies.
For other (general) products and important products in class I, this means the manufacturer can rely on internal control (Module A) without a notified body. For important products in class II and critical products, European certification functions as a full alternative to Modules B+C and H.
The product category determines the conformity assessment module
In practice, the modules described above are not applied in the same way to all products. What matters most is the category the product with digital elements falls into. One procedure will apply to an ordinary application, another to a password manager, and yet another to technology underpinning critical infrastructure.
Other (general) products with digital elements
The vast majority of products on the market fall into the category of general products. Estimates suggest as much as 90% of all products with digital elements. These include, for example, ordinary applications, office tools, simple IoT devices or photo editing applications. For these products, it is enough for the manufacturer to carry out the conformity assessment themselves through internal processes. No notified body or external audit is required.
Important products, class I
This category includes, for example, password managers, standalone browsers, VPN solutions, antivirus software, routers for connection to the internet, operating systems, smart door locks, security cameras and internet-connected toys with social interactive features. For these products, the manufacturer has three routes to choose from.
If harmonised standards, common specifications or the relevant European certification scheme at least at assurance level "substantial" are applied in full at the design stage, the manufacturer can rely on internal control.
If the standards are not applied in full, or none yet exist, a notified body must be involved. In that case, the manufacturer can choose either the combination of Modules B+C, i.e. type-examination followed by internal production control, or Module H, i.e. full quality assurance.
Important products, class II
Class II covers products with a higher risk profile. These include, for example, hypervisors and container runtime systems, firewalls, intrusion detection and prevention systems (IDS/IPS), and tamper-resistant microprocessors and microcontrollers. For these products, internal control alone is no longer sufficient, not even where harmonised standards are applied in full. The manufacturer must always involve a notified body and has three options:
- Modules B+C – type-examination by an independent auditor followed by internal control of series production,
- Module H – a full audit of the manufacturer's quality system with ongoing surveillance,
- European cybersecurity certification scheme at least at assurance level "substantial" under Regulation (EU) 2019/881, where one is available for the product type in question.
Critical products
The category of critical products covers technologies on which the functioning of key infrastructure depends and whose misuse could cause significant disruption to supply chains within the EU internal market. Specifically, this includes hardware devices with security boxes, for example hardware security modules protecting cryptographic keys, smart meter gateways within smart metering systems (typically smart electricity meters), and smart cards and similar devices with secure elements.
Critical products are subject to a regime similar to that for important products in class II. In principle, a European cybersecurity certification scheme should be used for them. If no such scheme is available for the product in question, however, which is the case as at the date of publication of this article, third-party assessment through Modules B+C or H applies.
Where to start in practice
The first step is to establish clearly which products your company manufactures or places on the market. These may be software, hardware, a combination of a device and an application, a standalone component, or a product that relies on remote data processing to function.
Next, write down what the product is for and how it is normally used, because a simple end-user application will be assessed differently from a product providing identity management, network protection or remote device management.
Finally, you should compare the product's main function against Annexes III and IV of the CRA and the technical descriptions in Implementing Regulation 2025/2392. It is advisable to record the outcome of the classification in your documentation, including a brief justification of why the product does or does not fall into a particular category.
Do not leave product classification until the last minute
We recommend addressing product classification under the CRA as early as possible, ideally when the product is being designed or its next version planned, rather than leaving it until just before the product is placed on the market.
If you discover at a late stage of development that your product falls into the important or critical category, this can affect the entire go-to-market timeline. Documentation will need to be added, development aligned with the relevant standards or technical specifications, the capacity of the body carrying out the conformity assessment factored in, and the budget and project plan possibly adjusted.
Early classification therefore helps not only the legal or compliance team, but also development and product management. It tells the company which route to conformity it will have to take, allowing it to adapt the product architecture, security testing, vulnerability management and support plan accordingly.