InsideCRA
InsideCRA › Articles › Article 7

Regulation (EU) 2024/2847 · Chapter

Article 7 — Important products with digital elements

What being an Annex III important product changes, and what it does not.

LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.

1.1. Products with digital elements which have the core functionality of a product category set out in Annex III shall be considered to be important products with digital elements and shall be subject to the conformity assessment procedures referred to in Article 32(2) and (3). The integration of a product with digital elements which has the core functionality of a product category set out in Annex III shall not in itself render the product in which it is integrated subject to the conformity assessment procedures referred to in Article 32(2) and (3).

2.2. The categories of products with digital elements referred to in paragraph 1 of this Article, divided into classes I and II as set out in Annex III, meet at least one of the following criteria:
(a) the product with digital elements primarily performs functions critical to the cybersecurity of other products, networks or services, including securing authentication and access, intrusion prevention and detection, end-point security or network protection;
(b) the product with digital elements performs a function which carries a significant risk of adverse effects in terms of its intensity and ability to disrupt, control or cause damage to a large number of other products or to the health, security or safety of its users through direct manipulation, such as a central system function, including network management, configuration control, virtualisation or processing of personal data.

3.3. The Commission is empowered to adopt delegated acts in accordance with Article 61 to amend Annex III by including in the list a new category within each class of the categories of products with digital elements and specifying its definition, moving a category of products from one class to the other or withdrawing an existing category from that list. When assessing the need to amend the list set out in Annex III, the Commission shall take into account the cybersecurity-related functionalities or the function and the level of cybersecurity risk posed by the products with digital elements as set out by the criteria referred to in paragraph 2 of this Article.
The delegated acts referred to in the first subparagraph of this paragraph shall, where appropriate, provide for a minimum transitional period of 12 months, in particular where a new category of important products with digital elements is added to class I or II or is moved from class I to II as set out in Annex III, before the relevant conformity assessment procedures as referred to in Article 32(2) and (3) start applying, unless a shorter transitional period is justified on imperative grounds of urgency.

4.4. By 11 December 2025, the Commission shall adopt an implementing act specifying the technical description of the categories of products with digital elements under classes I and II as set out in Annex III and the technical description of the categories of products with digital elements as set out in Annex IV. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 62(2).

BINDING Source: Regulation (EU) 2024/2847 (Cyber Resilience Act) · publisher European Union · captured 2026-09-16 · snapshot sha256:27b7c6c64c773001… · CELEX 32024R2847

What this article does

Article 7 attaches consequences to a list. Products whose core functionality is that of a product category listed in Annex III are important products, split into class I and class II F-023 F-024, and the practical consequence is the conformity assessment route: class I can use internal control only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full, while class II goes through EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme at 'substantial' level F-026.

The category descriptions are sharpened by Implementing Regulation (EU) 2025/2392, which supplies the technical descriptions for the Annex III and Annex IV categories F-048 — check it before concluding a borderline product is in or out of a category F-048. Integrating an Annex III product into another product does not by itself put the host product through the important-product procedures.

The common misreading

Important does not mean extra essential requirements: classification changes who checks conformity, not what conformity means F-026.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Not sure whether this applies to your product? Check if the CRA applies to you on CRARequired.