The situation
A commercially supplied open-source security product is assessed as Class II. One release has a documented plan to satisfy the public-technical-documentation condition; another keeps that documentation private. The route decision must reflect that difference without changing the underlying product class.
Facts that change the answer
- Does the product qualify for the relevant free-and-open-source route?
- Will the required technical documentation be made public?
- Has the whole-product risk coverage been documented?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Class II FOSS with the public-documentation condition met
Hypothetical example 1
Key facts in this example
- Annex category and technical-description reference
- Hypothetical Class II FOSS product meeting Article 32(5) conditions.
- Commercial free and open-source software route
- qualifies and technical documentation will be public
All recorded assumptions (7)
- Product with digital elements
- Hypothetical example product
- The product’s main features and technical capabilities needed for its intended purpose are documented
- Yes
- Classification based on the product’s own core functionality
- important class ii
- Annex category and technical-description reference
- Hypothetical Class II FOSS product meeting Article 32(5) conditions.
- Commercial free and open-source software route
- qualifies and technical documentation will be public
- Conformity-assessment route selected for planning
- module a internal control
- The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
- Yes
Public-documentation condition not met
Hypothetical example 2
The selected route does not match the recorded classification or supporting conditions. Obtain a product-specific conformity assessment review.(CRA Article 32)
Key facts in this example
- Annex category and technical-description reference
- Hypothetical Class II FOSS product without the public-documentation condition.
- Commercial free and open-source software route
- qualifies but public documentation condition not met
All recorded assumptions (7)
- Product with digital elements
- Hypothetical example product
- The product’s main features and technical capabilities needed for its intended purpose are documented
- Yes
- Classification based on the product’s own core functionality
- important class ii
- Annex category and technical-description reference
- Hypothetical Class II FOSS product without the public-documentation condition.
- Commercial free and open-source software route
- qualifies but public documentation condition not met
- Conformity-assessment route selected for planning
- module a internal control
- The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
- Yes
Evaluated on 2026-09-13 using EU Cyber Resilience Act product classification and conformity route, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Qualification rationale under Article 32
- Publication plan and references for technical documentation
- Selected conformity procedure and complete risk coverage
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Confirm each condition before relying on the special route. If it is unavailable, assess the ordinary procedure for the documented class.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 7, 8, 27 and 32; Annexes III, IV and VIII
- Commission Implementing Regulation (EU) 2025/2392Technical descriptions of Annex III and IV product categories
- European Commission CRA implementation guidance (2026)Section 6 — core functionality and conformity assessment
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.