Reg (EU) 2024/2847Generate dossier — €149
LIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

Annex III of Regulation (EU) 2024/2847 lists 19 categories of Important products in Class I and 4 categories in Class II. If your product falls into one of these categories, Article 32(2) or 32(3) restricts which conformity assessment procedures you can use. The wrong procedure invalidates your Declaration of Conformity. This is the complete list and the assessment logic.

Article 7(1) of the Cyber Resilience Act defines Important products as those whose core functionality matches a category in Annex III. The classification is not voluntary — it is determined by the product's function, not its marketing label. Class I products under Article 32(2) can still use Module A self-assessment if they apply harmonised standards, common specifications, or a European cybersecurity certification scheme in full. If they do not, they must use Module B+C or Module H with a notified body. Class II products under Article 32(3) must always use Module B+C, Module H, or a European cybersecurity certification scheme at assurance level "substantial" — Module A is never available. CRACheck classifies your product and generates the documentation accordingly. €149. 15–25 minutes. 8 PDFs.

Generate CRA dossier — €149Free: check your product classification

€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side

Regulation (EU) 2024/2847 · Art. 31 + Annex VII · 8 documents · 100% browser-side

Key figures

23
Product categories in Annex III (19 Class I + 4 Class II)
Art. 32
Determines which conformity assessment procedure applies based on classification
€15M
Maximum fine under Art. 64(2) for non-compliance with essential requirements

How CRACheck classifies your product and generates the correct documentation

Classification under the CRA is not a label you choose. It is determined by the core functionality of your product against the categories listed in Annex III and Annex IV. CRACheck runs this classification automatically.

1
Product description
You enter the product's core functionality, connectivity type, intended purpose, and user base.
2
Annex III cross-reference
CRACheck checks whether the product's core functionality matches any of the 19 Class I categories (identity management, browsers, password managers, VPNs, routers, OS, smart home products, etc.) or the 4 Class II categories (hypervisors, firewalls, tamper-resistant microprocessors/microcontrollers).
3
Annex IV cross-reference
CRACheck checks whether the product matches the 3 Critical product categories (hardware security boxes, smart meter gateways, smartcards/secure elements).
4
Classification result
CRACheck outputs the classification: Default, Important Class I, Important Class II, or Critical. The result is documented in the Product Classifier PDF.
5
Conformity assessment path
Based on the classification, CRACheck identifies which conformity assessment procedures under Article 32 are available: Module A (self-assessment), Module B+C (EU-type examination), Module H (full quality assurance), or European cybersecurity certification.
6
Documentation generation
CRACheck generates the 8-document dossier with the classification embedded in every relevant section: risk assessment, technical documentation, Declaration of Conformity, and obligations calendar.

Common mistakes

ART. 7 · ANNEX III

Assuming classification is based on the product name, not its function

Article 7(1) defines Important products by their "core functionality" matching a category in Annex III. A product marketed as a "home hub" may fall under Class I category 16 (smart home general purpose virtual assistants) or category 17 (smart home products with security functionalities) regardless of its brand positioning. Classification follows function, not label.

ART. 32(2)

Using Module A self-assessment for a Class I product without applying harmonised standards

Article 32(2) allows Module A for Class I products only if the manufacturer applies harmonised standards, common specifications, or a European cybersecurity certification scheme in full. If the manufacturer has not applied any of these — or applied them only in part — the product must go through Module B+C or Module H with a notified body.

ART. 7(1)

Believing that integrating an Important product as a component makes the final product Important

Article 7(1) second sentence states that the integration of a product with digital elements which has the core functionality of an Annex III category "shall not in itself render the product in which it is integrated subject to the conformity assessment procedures referred to in Article 32(2) and (3)." The classification applies to the component, not automatically to the final product.

What the ZIP contains

8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.

1

Product Classifier

Automated cross-reference against Annex III Class I (19 categories), Class II (4 categories), and Annex IV Critical (3 categories). Output: Default, Important Class I, Important Class II, or Critical, with the matched category and rationale.

2

Technical Documentation

Annex VII file with the classification embedded in the product description section and the conformity assessment path recorded.

3

Risk Assessment

Cybersecurity risk assessment per Article 13(2)–(3), structured against Annex I. The assessment depth reflects the classification level.

4

User Information

Annex II information sheet. Includes the support period end-date and the security update type per Annex I Part I point (2)(c).

5

Declaration of Conformity

EU Declaration per Article 28 and Annex V. Cites the applicable conformity assessment procedure (Module A, B+C, or H) matching the product classification.

6

CVD Policy

Coordinated vulnerability disclosure policy per Annex I Part II point (5).

7

Notification Template

ENISA/CSIRT notification template per Article 14 (24h/72h/14d).

8

Obligations Calendar

Key dates including conformity assessment deadlines relative to 11 December 2027.

See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.

Generated from your data, in your browser. No data leaves your device.

What you pay

🧾 THE ALTERNATIVE
Regulatory consultancy for CRA classification + Annex VII documentation
€8,000–20,000
The classification analysis alone is typically €2,000–5,000
Separate engagement for each product or product variant
6–16 weeks for the first product
✓ CRACHECK
€149 per product
Automated classification against Annex III and IV
Full 8-document dossier generated in 15–25 minutes
Classification embedded in every document
30-day edit window. 10 regenerations

Two layers

● LAYER 1 — DOCUMENTATION · CRACHECK

Classification + documentation

CRACheck classifies your product against Annex III and Annex IV, identifies the conformity assessment procedures available under Article 32, generates the Annex VII technical documentation with the classification embedded, and produces the EU Declaration of Conformity citing the correct module.

∅ LAYER 2 — NOT INCLUDED

What CRACheck does not do

CRACheck does not perform the conformity assessment procedure itself. For Class II and Critical products, the Module B+C or Module H assessment must be performed by a notified body designated under Article 39 of Regulation (EU) 2024/2847. CRACheck produces the documentation the notified body will review — it does not replace the notified body.

Documentation first, then assessment. The notified body needs your Annex VII file. CRACheck generates it.

Enforcement regime

⚖️
€15M / 2.5% turnover — Art. 64(2)

Non-compliance with Annex I essential requirements and Art. 13/14 obligations.

⚖️
€10M / 2% turnover — Art. 64(3)

Non-compliance with Art. 28 (Declaration of Conformity), Art. 31 (technical documentation), Art. 32 (conformity assessment procedures). Applying the wrong conformity assessment module falls here.

⚖️
€5M / 1% turnover — Art. 64(4)

Supplying incorrect or misleading information to notified bodies or market surveillance authorities. A misclassification that leads to the wrong conformity path could trigger this.

Alternatives

CriterioRegulatory consultancyInternal classificationCRACheck
Price€8,000–20,000Internal headcount€149/product
Classification methodManual expert reviewManual reading of Annex IIIAutomated cross-reference (23 categories)
Delivery6–16 weeksVaries15–25 minutes
OutputClassification memo + gap analysisInternal memo8 PDFs with classification embedded
Conformity pathIdentified manuallyIdentified manuallyAuto-identified per Art. 32
CRACheck€149Automated8 PDFsArt. 32

Product family with variants across multiple Annex III categories?

If your portfolio spans routers, firewalls, and smart home devices — each falling into a different Annex III category — contact us for volume pricing. Pack of 10: €99 per product. Pack of 30: €79 per product.

Request volume pricing
Commercial enquiries via hello@solidwaretools.com

What CRACheck guarantees and what it does not

CRACheck generates a structured document according to Article 31 and Annex VII of Regulation (EU) 2024/2847, based on the information you enter. The accuracy, completeness, and truthfulness of that information is your responsibility as manufacturer.

We guarantee that the document structure follows Article 31 and Annex VII of Regulation (EU) 2024/2847 and that the legal references cited are correct. We do not guarantee that a specific document will be accepted by a market surveillance authority in a specific case.

CRACheck is not legal advice. For situations specific to your product or market, consult a qualified lawyer or specialised regulatory consultancy.

Frequently asked questions

My product has a VPN function but it is not a standalone VPN product. Does Annex III Class I category 5 apply?
Article 7(1) of Regulation (EU) 2024/2847 states that a product is classified as Important if it "has the core functionality of a product category set out in Annex III." If VPN is not the core functionality of your product — for example, it is a secondary feature in a networking appliance — the classification depends on whether another Annex III category matches the primary function. CRACheck asks you to identify the core functionality and maps it accordingly.
Does a Class I product always need a notified body?
Not necessarily. Article 32(2) allows Class I products to use Module A (self-assessment) if the manufacturer applies harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level "substantial" in full. A notified body is required only if the manufacturer has not applied these standards — or applied them only in part — in which case Module B+C or Module H is mandatory.
What are the 4 categories in Class II?
Annex III Class II lists: (1) hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments, (2) firewalls and intrusion detection and prevention systems, (3) tamper-resistant microprocessors, and (4) tamper-resistant microcontrollers. Class II products must always use Module B+C, Module H, or European cybersecurity certification — Module A is never available under Article 32(3).
My product integrates a Class II component (a firewall module). Does my product become Class II?
No. Article 7(1) second sentence of Regulation (EU) 2024/2847 states that the integration of a product with digital elements that has the core functionality of an Annex III category "shall not in itself render the product in which it is integrated" subject to the Class I or Class II conformity assessment procedures. The component is classified separately; the final product's classification depends on its own core functionality.
Is this a subscription?
No. One-time payment. The licence includes 30 days of editing and 10 regenerations. The downloaded PDF is yours permanently.
Can I request a refund?
Under Art. 16(m) of Directive (EU) 2011/83, activating the licence constitutes express consent for immediate generation of digital content, waiving the 14-day withdrawal right. Refunds are only processed for reproducible technical failures.
What if the regulation changes?
If Regulation (EU) 2024/2847 is amended during your licence window, you can regenerate the documentation using the updated version of the generator at no additional cost.
⚠️ Important notice: CRACheck is a self-assessment documentation tool, not legal advice and not a third-party audit. The document under Article 31 and Annex VII of Regulation (EU) 2024/2847 is generated from your input data. You are responsible for the accuracy of the data you provide. CRACheck does not replace a qualified professional assessment.

23 product categories. One classification. The correct conformity path.

CRACheck classifies your product against Annex III and IV, identifies the conformity assessment module, and generates the full 8-document dossier. €149 per product. Browser-side.

€149 one-time
8 PDFs · 15–25 min · automated Annex III/IV classification · 100% browser-side
Generate CRA Dossier
✓ Last regulatory check: 1 May 2026 · No substantive changes detected · View history