EU CRA Annex III & IV: Navigating Important and Critical Software
Identify your product's classification under Class I, Class II, or Critical Annex IV and streamline your technical documentation workflow.

The Cyber Resilience Act (CRA) categorizes products with digital elements into 'Important' (Class I and II) and 'Critical' (Annex IV) tiers based on their cybersecurity risk profile. Annex III products require specific conformity assessments, while Annex IV products mandate rigorous third-party certification before market entry. Correctly identifying your software's tier is essential to determine if you can perform a self-assessment or if you must engage an accredited notified body.
Understanding CRA Product Categorization
The EU Cyber Resilience Act (Regulation 2024/2847), effective since December 2024, enforces a risk-based structure for digital products. While standard software may rely on internal production control, Annex III and IV categories demand comprehensive technical preparation, vulnerability management, and strict adherence to European security standards.
Classification Tiers and Assessment Requirements
Key distinctions across CRA product tiers and mandatory compliance pathways.
Annex III Class I (Important)
Includes identity management, password managers, and web browsers. Compliance requires adherence to harmonized European standards or third-party assessment.
Annex III Class II (Important)
Covers high-risk infrastructure such as firewalls, intrusion detection systems, and hypervisors, necessitating full third-party conformity evaluation.
Annex IV (Critical Products)
Encompasses hardware security modules and critical control components subject to mandatory EU cybersecurity certification schemes.
Technical Documentation (Annex VII)
Manufacturers across all classes must maintain detailed technical files, vulnerability handling procedures, and a comprehensive Software Bill of Materials (SBOM).
Managing Compliance for Complex Software Systems
Manufacturers must evaluate whether their core functions or embedded dependencies fall under Annex III or IV to select the correct assessment path.
- Generate precise CycloneDX SBOMs across 9 major package ecosystems
- Calculate repository security readiness scores out of 100
- Automate ENISA vulnerability reporting timelines (24h / 72h / 14d)
- Prepare pre-filled draft technical documentation aligned with Annex VII

Conformity Assessment Procedures for Annex III and IV
For standard products, vendors may apply internal control procedures. However, for Class I products, self-assessment is only valid if harmonized standards are fully applied. If standards are missing, or for Class II and Annex IV products, the involvement of an accredited notified body or an official EU certification scheme is mandatory.
Key Deadlines and Non-Compliance Risks
Vulnerability reporting obligations commence on 11 September 2026, with full product security requirements effective 11 December 2027. Non-compliance can result in administrative fines reaching EUR 15 million or 2.5% of total worldwide annual turnover, whichever is higher.
Prepare Your CRA Technical File Early
Connect your GitHub repositories to generate live SBOMs, audit dependencies, and draft pre-filled compliance documentation.
Steps to Determine and Prepare Your Product Tier
- 1
Map Product Features to Annex III & IV
Evaluate if your software provides security-critical functions like authentication, filtering, OS control, or system management.
- 2
Generate Automated SBOMs
Scan your source code repositories across npm, PyPI, Go, Rust, .NET, PHP, Ruby, Java, or CycloneDX files.
- 3
Select Assessment Route
Determine if internal production controls suffice or if third-party notified body assessment is required.
- 4
Structure Technical Documentation
Draft your Annex VII technical documentation, publish SECURITY.md guidelines, and establish ENISA reporting workflows.
Streamline CRA Readiness with CRAcheck
CRAcheck is a self-assessment support tool designed to help engineering teams prepare for the Cyber Resilience Act. By connecting your GitHub repositories, CRAcheck calculates readiness scores, monitors vulnerabilities with alerts, and generates draft compliance assets.
Please note that CRAcheck is a support tool and not an official third-party certification body. It assists teams in organizing evidence and building the technical files required for audit readiness.
Frequently Asked Questions
What is the difference between CRA Annex III Class I and Class II?+
Class I covers important products where self-assessment is permitted if fully aligned with harmonized standards. Class II covers higher-risk components like firewalls, requiring mandatory third-party assessment.
Does CRAcheck certify Annex IV critical products?+
No. CRAcheck is a self-assessment support tool. Annex IV products require formal certification from accredited notified bodies. CRAcheck assists by gathering technical documentation and SBOMs.
When do CRA requirements become mandatory?+
Vulnerability reporting obligations take effect on 11 September 2026. Full product enforcement and technical compliance take effect on 11 December 2027.
What are the financial penalties for CRA non-compliance?+
Non-compliance with essential cybersecurity requirements can trigger administrative fines up to EUR 15 million or 2.5% of annual worldwide turnover.
Get Ready for Cyber Resilience Act Compliance
Scan your repositories, generate software bills of materials, and build your technical file in minutes.
Same topic — Glossaire
New to the Cyber Resilience Act? Start with the complete guide.
The CRA guideFrom the blog
Check your CRA compliance in 1 minute
Free, no sign-up. Scan your repo and get your compliance score + pre-filled documents.