Reg (EU) 2024/2847Generate dossier — €149
LIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

Your product appears in Annex III of Regulation (EU) 2024/2847. It is classified as Important — either Class I or Class II. The conformity assessment path under Article 32 depends on which class and whether harmonised standards exist. Class I with full harmonised standards: you may still self-assess under Module A. Class I without harmonised standards or Class II: you need a notified body. CRACheck generates the documentation you bring to either path.

Annex III lists 19 Class I categories and 4 Class II categories. Class I includes routers, operating systems, smart home devices, identity management systems, and wearables. Class II includes firewalls, hypervisors, and tamper-resistant processors. For Class I, Article 32(2) triggers stricter assessment only when harmonised standards, common specifications, or European cybersecurity certification schemes at assurance level "substantial" have not been applied in full. If they have, Article 32(1) allows Module A. For Class II, Article 32(3) always requires Module B+C, Module H, or a certification scheme. CRACheck produces the Annex VII documentation that both paths require as their starting input. Eight documents, €149.

Generate Class I/II documentation — €149Free: check your product classification

€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side

Regulation (EU) 2024/2847 · Art. 32 + Annex III + Annex VIII · 8 documents · 100% browser-side

Key numbers

23
product categories in Annex III — 19 Class I and 4 Class II
Module B+C or H
required for Class II and for Class I without harmonised standards (Art. 32(2)–(3))
€149
CRACheck documentation cost — the same package you submit to the notified body

How CRACheck works

You enter your product data. CRACheck structures the documentation per Article 31 + Annex VII.

1
Identify your Annex III category
CRACheck's Product Classifier maps your product against the 19 Class I and 4 Class II categories. The category determines the conformity assessment path.
2
Determine if harmonised standards apply (Class I only)
If your Class I product fully applies harmonised standards or a certification scheme at assurance level "substantial," Article 32(1) allows Module A. If not, Article 32(2) applies.
3
Prepare the technical documentation
Whether you self-assess (Module A) or go to a notified body (Module B+C or H), the technical documentation per Annex VII is required.
4
Prepare the risk assessment
Article 13(2)–(3) risk assessment, mapped against Annex I. The notified body will review this as part of the EU-type examination.
5
Choose your notified body (if required)
For Module B, Annex VIII Part II, point 3 requires you to lodge an application with a single notified body of your choice.
6
Submit documentation to the notified body
Annex VIII Part II, point 3 lists what the application must include: name and address, written declaration, technical documentation per Annex VII, and supporting evidence.
7
Receive examination and certificate
The notified body examines your documentation and product specimens. If conformity is established, an EU-type examination certificate is issued.

Common mistakes

CLASS I TRAP

"Assuming all Class I products need a notified body"

Article 32(2) is conditional: Class I products only need Module B+C or H where the manufacturer has not applied harmonised standards in full. If you fully apply the relevant harmonised standards, Article 32(1) applies and Module A is available.

CLASS II

"Trying to self-assess a Class II product"

Article 32(3) is unconditional for Class II: the manufacturer shall demonstrate conformity using Module B+C, Module H, or a European cybersecurity certification scheme at assurance level at least "substantial." Module A is not available for Class II products.

DOCUMENTATION TIMING

"Contacting the notified body before preparing the technical documentation"

Annex VIII Part II, point 3.3 requires the application to the notified body to include the technical documentation that makes it possible to assess conformity. Approaching a notified body without the Annex VII documentation means the examination cannot begin. Prepare the documentation first.

What the ZIP contains

8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.

1

Product Classifier

Critical for Class I/II: confirms the exact Annex III category and the applicable Article 32 paragraph. Distinguishes between Class I with harmonised standards (Module A possible) and Class I without (notified body required).

2

Technical Documentation

Per Annex VII. For notified body submissions, this is what Annex VIII Part II, point 3.3 requires as part of the application.

3

Risk Assessment

Per Article 13(2)–(3). The notified body will review this under Annex VIII Part II, point 4.1 when examining the adequacy of the technical design.

4

User Information

Per Annex II. Required regardless of the assessment path.

5

Declaration of Conformity

Per Article 28 and Annex V. For Module H, the notified body's identification number follows the CE marking per Article 30(4).

6

CVD Policy

Per Part II, point (5) of Annex I. The notified body under Module B will verify that vulnerability handling processes are in place.

7

Notification Template

Article 14 ENISA structure. The notified body performs periodic audits to ensure Part II of Annex I is implemented. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.

8

Obligations Calendar

Key dates including notified body designation timeline (Chapter IV from 11 June 2026), your expected examination timeline, and support period milestones.

Mira antes de comprar — Descargar dossier de muestra (PDF, empresa ficticia) — Estructura real, artículos reales, formato real. Datos ficticios.

Generated from your data, in your browser. No data leaves your device.

What you pay

🧾 NOTIFIED BODY EXAMINATION (MODULE B+C)
€5,000–€15,000
Notified body fees + months of examination. Requires prepared technical documentation as input. Certificate may need updates. Periodic audits.
✓ CRACHECK
€149
€149. 15–25 min. Generates the Annex VII technical file that the notified body application requires per Annex VIII Part II, point 3.3. Reduces examination time. Regenerate if the body requests changes.

Two layers

● LAYER 1

The Annex VII documentation package

CRACheck generates the technical documentation, risk assessment, declaration of conformity, and supporting documents that the notified body application requires under Annex VIII Part II, point 3. Well-structured documentation reduces examination time and cost.

∅ LAYER 2

The third-party examination and certificate

The notified body examines your technical design, tests product specimens, verifies vulnerability handling processes, and issues (or refuses) an EU-type examination certificate. CRACheck does not perform or substitute any part of this examination.

CRACheck builds the documentation package. The notified body examines it. Both steps are necessary for Class I without harmonised standards and for all Class II products.

Enforcement regime

Article 64 of Regulation (EU) 2024/2847.

🔴
Essential requirements + manufacturer obligations (Art. 64(2))
€15,000,000 / 2.5%

Non-compliance with Annex I or Articles 13/14.

🟠
Wrong conformity assessment procedure (Art. 64(3))
€10,000,000 / 2%

Using Module A for a product that requires Module B+C or H, or failing to produce technical documentation.

🟡
Misleading information (Art. 64(4))
€5,000,000 / 1%

Misleading information to notified bodies or authorities.

Alternatives

CriterionDefault (Module A)Class I with harmonised standardsClass I without harmonised standardsClass II
Legal basisArt. 32(1)(a)Art. 32(1) — all optionsArt. 32(2)Art. 32(3)
Notified bodyNot requiredNot requiredRequired (Module B+C or H)Required (Module B+C, H, or certification)
CRACheck documentationFull packageFull packageFull package (input to NB)Full package (input to NB)
Estimated total cost (docs + NB)€149€149€149 + €5K–€15K€149 + €8K–€20K

Multiple Class I or Class II products?

Each Important product needs its own Annex VII documentation and classification determination. Pack of 10: €99 per product.

Request Volume Pricing
The Product Classifier determines Class I vs. Class II for each product independently.

What CRACheck guarantees and what it does not

CRACheck generates a structured document based on Article 31 and Annex VII of Regulation (EU) 2024/2847 from the information you provide. The accuracy of the classification and product data is your responsibility as the manufacturer.

We guarantee that the document structure follows Article 31 and Annex VII and that all legal references are correct. We do not guarantee that a notified body will issue a positive certificate based on the documentation, nor that a market surveillance authority will accept the classification.

CRACheck is not legal advice. For classification disputes or notified body selection, consult a regulatory specialist.

Frequently asked questions

What are the 19 Class I categories in Annex III?
Identity management systems, standalone and embedded browsers, password managers, anti-malware software, VPN products, network management systems, SIEM systems, boot managers, PKI and certificate issuance software, physical and virtual network interfaces, operating systems, routers/modems/switches, microprocessors with security functions, microcontrollers with security functions, ASICs/FPGAs with security functions, smart home virtual assistants, smart home products with security functions, internet-connected toys, and health-monitoring/children's wearables.
What are the 4 Class II categories?
Hypervisors and container runtime systems, firewalls and intrusion detection/prevention systems, tamper-resistant microprocessors, and tamper-resistant microcontrollers.
When can a Class I product still use Module A?
When the manufacturer has applied in full harmonised standards, common specifications, or European cybersecurity certification schemes at assurance level at least "substantial" as referenced in Article 27. In that case, Article 32(1) applies.
How much does a notified body examination cost?
Costs vary by product complexity and notified body. Typical ranges are €5,000–€15,000 for Module B EU-type examination. Article 32(6) requires fees to be proportionate for SMEs and startups.
When will notified bodies be ready?
Chapter IV governing notification of conformity assessment bodies applies from 11 June 2026. Member States must designate notifying authorities and notified bodies before that date.
Is this a subscription?
No. One-time payment. 30 days editing, 10 regenerations. PDF yours permanently.
Can I request a refund?
Per Article 16(m) of Directive (EU) 2011/83, licence activation constitutes express consent. Refunds only for reproducible technical failures.
What if the regulation changes?
Regenerate at no additional cost during licence validity.
⚠️ Important notice: CRACheck is a self-assessment documentation tool, not legal advice and not a third-party audit. The document under Article 31 and Annex VII of Regulation (EU) 2024/2847 is generated from your input data. You are responsible for the accuracy of the data you provide. CRACheck does not replace a qualified professional assessment.

The notified body examines your documentation. Make sure it is complete before you walk in.

Eight documents. Article 31 + Annex VII fully structured. Regulation (EU) 2024/2847. Your data stays on your device. The ZIP you download is yours forever.

€149 one-time
8-document professional dossier · 15–25 minutes · No subscription · Browser-side
Generate Class I/II documentation — €149
✓ Last regulatory check: 1 May 2026 · No substantive changes detected · View history