Regulation (EU) 2024/2847 · Chapter
Article 7 — Important products with digital elements
What being an Annex III important product changes, and what it does not.
LAW Official text — verbatim from the Official Journal snapshot; only the Official Journal is authentic.
1.1. Products with digital elements which have the core functionality of a product category set out in Annex III shall be considered to be important products with digital elements and shall be subject to the conformity assessment procedures referred to in Article 32(2) and (3). The integration of a product with digital elements which has the core functionality of a product category set out in Annex III shall not in itself render the product in which it is integrated subject to the conformity assessment procedures referred to in Article 32(2) and (3).
2.2. The categories of products with digital elements referred to in paragraph 1 of this Article, divided into classes I and II as set out in Annex III, meet at least one of the following criteria:
(a) the product with digital elements primarily performs functions critical to the cybersecurity of other products, networks or services, including securing authentication and access, intrusion prevention and detection, end-point security or network protection;
(b) the product with digital elements performs a function which carries a significant risk of adverse effects in terms of its intensity and ability to disrupt, control or cause damage to a large number of other products or to the health, security or safety of its users through direct manipulation, such as a central system function, including network management, configuration control, virtualisation or processing of personal data.
3.3. The Commission is empowered to adopt delegated acts in accordance with Article 61 to amend Annex III by including in the list a new category within each class of the categories of products with digital elements and specifying its definition, moving a category of products from one class to the other or withdrawing an existing category from that list. When assessing the need to amend the list set out in Annex III, the Commission shall take into account the cybersecurity-related functionalities or the function and the level of cybersecurity risk posed by the products with digital elements as set out by the criteria referred to in paragraph 2 of this Article.
The delegated acts referred to in the first subparagraph of this paragraph shall, where appropriate, provide for a minimum transitional period of 12 months, in particular where a new category of important products with digital elements is added to class I or II or is moved from class I to II as set out in Annex III, before the relevant conformity assessment procedures as referred to in Article 32(2) and (3) start applying, unless a shorter transitional period is justified on imperative grounds of urgency.
4.4. By 11 December 2025, the Commission shall adopt an implementing act specifying the technical description of the categories of products with digital elements under classes I and II as set out in Annex III and the technical description of the categories of products with digital elements as set out in Annex IV. That implementing act shall be adopted in accordance with the examination procedure referred to in Article 62(2).
sha256:27b7c6c64c773001… · CELEX 32024R2847What this article does
Article 7 attaches consequences to a list. Products whose core functionality is that of a product category listed in Annex III are important products, split into class I and class II F-023 F-024, and the practical consequence is the conformity assessment route: class I can use internal control only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full, while class II goes through EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme at 'substantial' level F-026.
The category descriptions are sharpened by Implementing Regulation (EU) 2025/2392, which supplies the technical descriptions for the Annex III and Annex IV categories F-048 — check it before concluding a borderline product is in or out of a category F-048. Integrating an Annex III product into another product does not by itself put the host product through the important-product procedures.
The common misreading
Important does not mean extra essential requirements: classification changes who checks conformity, not what conformity means F-026.
Verified facts this page relies on
- F-023 Annex III Class I — important products, class I (items 1–19). Annex III Class I; Implementing Regulation (EU) 2025/2392
- F-024 Annex III Class II — important products, class II (items 1–4). Annex III Class II; Implementing Regulation (EU) 2025/2392
- F-026 Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIII
- F-048 Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the Annex III and Annex IV product categories (in force 21 December 2025); the class matcher uses those descriptions, not shorthand labels. Implementing Regulation (EU) 2025/2392; Art. 7(4)
Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).
Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.