Regulation (EU) 2024/2847
Annex III — Important products with digital elements
The important-products list: class I and class II.
LAW Official text — verbatim from the Official Journal snapshot.
Class I
1. Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
2. Standalone and embedded browsers
3. Password managers
4. Software that searches for, removes, or quarantines malicious software
5. Products with digital elements with the function of virtual private network (VPN)
6. Network management systems
7. Security information and event management (SIEM) systems
8. Boot managers
9. Public key infrastructure and digital certificate issuance software
10. Physical and virtual network interfaces
11. Operating systems
12. Routers, modems intended for the connection to the internet, and switches
13. Microprocessors with security-related functionalities
14. Microcontrollers with security-related functionalities
15. Application specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
16. Smart home general purpose virtual assistants
17. Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems
18. Internet connected toys covered by Directive 2009/48/EC of the European Parliament and of the Council that have social interactive features (e.g. speaking or filming) or that have location tracking features
19. Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children
Class II
1. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments
2. Firewalls, intrusion detection and prevention systems
3. Tamper-resistant microprocessors
4. Tamper-resistant microcontrollers
( 1 ) Directive 2009/48/EC of the European Parliament and of the Council of 18 June 2009 on the safety of toys ( OJ L 170, 30.6.2009, p. 1 ).
sha256:27b7c6c64c773001… · CELEX 32024R2847How to read this annex
Annex III is a list with legal consequences: product types here are important products, class I (nineteen categories) and class II (four) F-023 F-024. The categories read broadly — browsers, password managers, VPNs, operating systems — and the technical descriptions that decide edge cases come from Implementing Regulation (EU) 2025/2392 F-048.
Using the list honestly
Two errors dominate. Reading a category name expansively without the implementing act's description F-048, and assuming listing changes the requirements — it can change the conformity route: class I keeps internal control only where harmonised standards, common specifications or a certification scheme are applied in full, and class II uses EU-type examination plus internal production control, full quality assurance or a scheme at 'substantial' level F-026.
Verified facts this page relies on
- F-023 Annex III Class I — important products, class I (items 1–19). Annex III Class I; Implementing Regulation (EU) 2025/2392
- F-024 Annex III Class II — important products, class II (items 1–4). Annex III Class II; Implementing Regulation (EU) 2025/2392
- F-048 Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the Annex III and Annex IV product categories (in force 21 December 2025); the class matcher uses those descriptions, not shorthand labels. Implementing Regulation (EU) 2025/2392; Art. 7(4)
- F-026 Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIII
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.
Related in the reference
- Article 7 — Important products with digital elements
- Topic: Important and critical products
- Topic: Conformity assessment