This document is under active development and has not been finalised.
Skip to content

Product Classification Record

LEGAL DOCUMENTATION

This record documents the CRA product classification decision. It must be completed before a product with digital elements is placed on the EU market and shall be retained for at least 10 years (Art. 13(12) CRA).

1. Product Identification

FieldValue
Product Name
Product Version
Product Identifier
Intended Purpose
Product Owner
Security Lead
Assessment Date

2. Scope Assessment

QuestionAnswerReference
Does the product contain digital elements (software, firmware, hardware with data connection)?[ ] Yes / [ ] NoArt. 3(1)
Is the product made available on the EU market?[ ] Yes / [ ] NoArt. 2(1)
Does any sectoral exemption apply (medical, automotive, aviation, marine, military)?[ ] Yes / [ ] NoArt. 2(2)
Is this non-commercial open-source software?[ ] Yes / [ ] NoArt. 18–19

Scope Result: [ ] CRA applicable / [ ] CRA not applicable

If not applicable, state reason: ___

3. Product Classification

3.1 Annex IV Check (Critical Products)

Annex IV CategoryApplicable?
Hardware security modules (HSM)[ ] Yes / [ ] No
Smart cards and similar devices (incl. secure elements)[ ] Yes / [ ] No
Smart card readers[ ] Yes / [ ] No
Sensor and actuator components for robots and robot controllers[ ] Yes / [ ] No
Smart meters (as defined in Directive 2019/944)[ ] Yes / [ ] No

Annex IV Result: [ ] Listed (→ Critical) / [ ] Not listed (→ continue)

3.2 Annex III Check (Important Products)

Annex III CategoryClassApplicable?
Identity management systems and privileged access softwareI[ ] Yes / [ ] No
Standalone browsersI[ ] Yes / [ ] No
Password managersI[ ] Yes / [ ] No
Malware detection/removal/quarantine softwareI[ ] Yes / [ ] No
VPN productsI[ ] Yes / [ ] No
Network management systemsI[ ] Yes / [ ] No
SIEM systemsI[ ] Yes / [ ] No
Boot managersI[ ] Yes / [ ] No
Firewalls, IDS/IPS (non-industrial)I[ ] Yes / [ ] No
Routers, modems for internet accessI[ ] Yes / [ ] No
Microcontrollers with security functionsI[ ] Yes / [ ] No
Operating systems (non-server/desktop)I[ ] Yes / [ ] No
Hypervisors and container runtimesII[ ] Yes / [ ] No
Firewalls, IDS/IPS (industrial)II[ ] Yes / [ ] No
Tamper-resistant microcontrollers/microprocessorsII[ ] Yes / [ ] No
OS for servers, desktops, mobileII[ ] Yes / [ ] No
PKI and certificate issuersII[ ] Yes / [ ] No
Industrial automation and control systems (IACS)II[ ] Yes / [ ] No
Industrial IoT (not subject to other sectoral regulation)II[ ] Yes / [ ] No

Annex III Result: [ ] Class II / [ ] Class I / [ ] Not listed (→ Standard)

3.3 Classification Result

FieldValue
Product Class[ ] Standard / [ ] Class I / [ ] Class II / [ ] Critical
Conformity Path[ ] Module A / [ ] Module A + hEN / [ ] Module B+C / [ ] Module H / [ ] EUCC
Justification

4. Conformity Assessment Path

CriterionDecision
Are harmonised standards (hEN) fully applied?[ ] Yes / [ ] No / [ ] N/A
Is third-party assessment required?[ ] Yes / [ ] No
Selected assessment moduleModule ___
Notified body (if applicable)

5. Approval

RoleNameSignatureDate
Product Owner
Security Lead
Quality Manager

TIP

Use the Scope Checker for interactive guidance through the classification process.

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT