This document is under active development and has not been finalised.
Skip to content

Product Lists (Annex III & IV)

Overview

The Cyber Resilience Act (CRA) defines specific product categories in Annex III and Annex IV that are subject to special conformity assessment procedures. This page contains the complete lists of all product categories specified therein, including descriptions, required assessment procedures, and a relevance assessment for BAUER GROUP.

The classification logic (decision tree, assessment procedure per category) is described on the Product Classification page.

LEGAL BASIS

Art. 7 CRA defines the categories "Important products with digital elements" (Annex III) and "Critical products with digital elements" (Annex IV).

Art. 24(1)-(3) CRA establishes the conformity assessment procedures per category:

  • Class I (Annex III Part I): Internal control (Module A) where harmonised standards are applied, otherwise EU type examination (Module B+C)
  • Class II (Annex III Part II): EU type examination (Module B+C) or Comprehensive quality assurance (Module H)
  • Critical (Annex IV): European cybersecurity certificate (EUCC) at assurance level "substantial" or higher

Art. 7(3) CRA empowers the Commission to adopt delegated acts amending Annexes III and IV.


Annex III -- Important Products with Digital Elements

Part I -- Class I

Class I products may be assessed via Internal control (Module A) where harmonised standards are applied in full. Without harmonised standards, an EU type examination (Module B+C) is required.

No.Product CategoryDescriptionConformity Module
1Identity management systems and privileged access management softwareSystems for managing digital identities and controlling privileged access rights (Privileged Access Management, PAM)Module A* / B+C
2Standalone and embedded browsersWeb browsers as standalone applications or as components embedded in other productsModule A* / B+C
3Password managersSoftware for the secure storage, management, and automatic entry of passwords and credentialsModule A* / B+C
4Software that searches for, removes, or quarantines malicious software (antimalware)Security software that detects, isolates, and removes malwareModule A* / B+C
5Products with digital elements with the function of a virtual private network (VPN)Products that provide virtual private network functionalityModule A* / B+C
6Network management systemsSystems for monitoring, configuring, and managing network infrastructureModule A* / B+C
7Security information and event management (SIEM) systemsSystems for collecting, correlating, and analysing security-relevant events in real timeModule A* / B+C
8Boot managersSoftware that controls the start-up process of a system and enables selection of the operating system to be loadedModule A* / B+C
9Public key infrastructure and digital certificate issuance softwareSoftware for managing cryptographic keys and for issuing, managing, and verifying digital certificatesModule A* / B+C
10Physical and virtual network interfacesHardware and software network interfaces that enable communication within networksModule A* / B+C
11Operating systemsSoftware that manages the basic functions of a computer and enables the execution of applicationsModule A* / B+C
12Routers, modems intended for the connection to the internet, and switchesNetwork hardware intended for connecting to the internet, including routers, modems, and switchesModule A* / B+C
13Microprocessors with security-related functionalitiesMicroprocessors that implement security-related functionalitiesModule A* / B+C
14Microcontrollers with security-related functionalitiesMicrocontrollers that implement security-related functionalitiesModule A* / B+C
15ASICs and FPGAs with security-related functionalitiesApplication-specific integrated circuits (ASICs) and field-programmable gate arrays (FPGAs) with security-related functionalitiesModule A* / B+C
16Smart home virtual assistants with general purposeVoice-controlled or AI-based assistants for use in the smart home with general-purpose functionalityModule A* / B+C
17Smart home products with security functionalitiesSmart home products with security functionalities, including door locks, cameras, baby monitoring systems, and alarm systemsModule A* / B+C
18Internet-connected toys with social interactive features or location trackingInternet-connected toys covered by Directive 2009/48/EC with social interactive features or location trackingModule A* / B+C
19Personal wearable products for health monitoring purposesProducts worn on the body for monitoring health-related parametersModule A* / B+C

* Module A only where harmonised standards are applied in full or where conforming with EU cybersecurity certification

Part II -- Class II

Class II products require mandatory third-party assessment: EU type examination (Module B+C) or Comprehensive quality assurance (Module H).

No.Product CategoryDescriptionConformity Module
1Hypervisors and container runtime systems supporting virtualised execution of operating systemsHypervisors and container runtime systems that support the virtualised execution of operating systemsModule B+C / H
2Firewalls, intrusion detection and/or prevention systemsNetwork security systems for monitoring, detecting, and preventing attacks and unauthorised accessModule B+C / H
3Tamper-resistant microprocessorsMicroprocessors with physical protection against tampering and readout (tamper-resistant)Module B+C / H
4Tamper-resistant microcontrollersMicrocontrollers with physical protection against tampering and readout (tamper-resistant)Module B+C / H

Annex IV -- Critical Products with Digital Elements

Critical products require a European cybersecurity certificate (EUCC) at assurance level "substantial" or higher.

No.Product CategoryDescriptionConformity Module
1Hardware devices with security boxes (HSMs, smartcards, etc.)Hardware security modules (HSMs), smartcards, and comparable devices that perform cryptographic operations in a protected environmentEUCC
2Smartcard readersDevices for reading and processing smartcard data for authentication, signature, or encryptionEUCC
3Sensor and actuator components for robots and robot controllers (industrial applications)Sensors and actuators used in robots and robot controllers for industrial applicationsEUCC
4Smart meters within the meaning of Article 2(23) of Directive (EU) 2019/944Electronic metering systems for measuring energy consumption under the Electricity Internal Market DirectiveEUCC
5All devices and software components belonging to Advanced Metering Infrastructure (AMI)All devices and software that are part of the advanced metering infrastructureEUCC

Conformity Module Overview

Product CategoryModule A (Self)Module B+C (Type)Module H (Quality)EUCC
Standard (not in Annex III/IV)---
Class I (Annex III Part I)✅*--
Class II (Annex III Part II)--
Critical (Annex IV)---

* Only where harmonised standards are applied in full

Detailed information on the individual modules:


BAUER GROUP Relevance Assessment

The following table assesses the relevance of each product category from Annex III and IV for BAUER GROUP.

Annex III Part I -- Class I

No.Product CategoryRelevanceRationale
1Identity management systems / PAMTo be assessedIf IAM solutions or PAM software are offered
2Standalone and embedded browsersNot relevantBAUER GROUP does not manufacture browsers
3Password managersTo be assessedIf credential management solutions are offered
4Antimalware softwareNot relevantBAUER GROUP does not manufacture antimalware software
5VPN productsTo be assessedIf VPN functionality is integrated in products
6Network management systemsTo be assessedIf network monitoring tools are offered
7SIEM systemsNot relevantBAUER GROUP does not manufacture SIEM systems
8Boot managersNot relevantBAUER GROUP does not manufacture boot managers
9PKI and certificate issuance softwareTo be assessedIf certificate management solutions are offered
10Physical and virtual network interfacesTo be assessedIf network components with firmware are manufactured
11Operating systemsTo be assessedIf OS-level products or embedded operating systems
12Routers, modems, switchesTo be assessedIf network hardware with firmware is offered
13Microprocessors (security-related)To be assessedIf microprocessors with security functions are developed
14Microcontrollers (security-related)RelevantESP32/STM32 firmware with security-related functions
15ASICs / FPGAs (security-related)To be assessedIf ASICs or FPGAs with security functions are used
16Smart home virtual assistantsNot relevantBAUER GROUP does not manufacture smart home assistants
17Smart home products with security functionalitiesNot relevantBAUER GROUP does not manufacture smart home security products
18Internet-connected toysNot relevantBAUER GROUP does not manufacture toys
19Health monitoring wearablesNot relevantBAUER GROUP does not manufacture health wearables

Annex III Part II -- Class II

No.Product CategoryRelevanceRationale
1Hypervisors / container runtimeNot relevantBAUER GROUP uses containers but does not offer a runtime
2Firewalls / IDS / IPSTo be assessedIf security products with firewall/IDS functionality
3Tamper-resistant microprocessorsNot relevantBAUER GROUP does not manufacture tamper-resistant processors
4Tamper-resistant microcontrollersNot relevantBAUER GROUP does not manufacture tamper-resistant controllers

Annex IV -- Critical

No.Product CategoryRelevanceRationale
1HSMs, smartcards, etc.Not relevantBAUER GROUP uses HSMs but does not manufacture them
2Smartcard readersNot relevantBAUER GROUP does not manufacture smartcard readers
3Robot sensors and actuators (industrial)To be assessedIf industrial robotics components are manufactured
4Smart meters (Directive (EU) 2019/944)To be assessedIf energy metering devices are manufactured
5Advanced Metering Infrastructure (AMI)To be assessedIf AMI components are manufactured

Relevance Summary

Relevance StatusNumber of Categories
Relevant1
To be assessed14
Not relevant13
Total28

RECOMMENDATION

The relevance assessment should be carried out individually for each BAUER GROUP product line and documented in the respective Product Description. The assessment in the table above serves as initial guidance.

KEEP THIS LIST UPDATED

The product lists in Annex III and Annex IV may be amended by delegated acts of the European Commission pursuant to Art. 7(3) CRA. These lists must therefore be reviewed regularly for updates and compared against the currently applicable version of Regulation (EU) 2024/2847. Amendments may include the addition of new product categories as well as the reclassification of existing categories.

Next Steps

  1. Perform classification -- Use the decision tree on the Product Classification page
  2. Review relevance -- Compare each BAUER GROUP product against the lists above
  3. Determine assessment procedure -- Select the correct conformity module
  4. Document -- Record the classification in the Product Description
  5. Risk assessment -- Create a Risk Assessment for each classified product

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT