The situation
A company supplies a standalone proprietary firewall. Its core security function has been matched to the Class II category. The release team must choose a valid procedure and arrange the evidence for it, even if the product has already passed extensive internal security tests.
Facts that change the answer
- Is firewall functionality the core purpose of the product?
- Does a specific statutory exception apply?
- Has a qualifying procedure been selected and documented?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Class II procedure not yet selected
Hypothetical example 1
Select and document an eligible third-party conformity route before placing the product on the market.(CRA Article 32(2)–(4))
Key facts in this example
- Conformity-assessment route selected for planning
- not selected
All recorded assumptions (7)
- Product with digital elements
- Hypothetical example product
- The product’s main features and technical capabilities needed for its intended purpose are documented
- Yes
- Classification based on the product’s own core functionality
- important class ii
- Annex category and technical-description reference
- Annex III, Class II, point 2; standalone firewall core functionality assumed documented.
- Commercial free and open-source software route
- not applicable
- Conformity-assessment route selected for planning
- not selected
- The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
- Yes
Class II with module B plus C recorded
Hypothetical example 2
Key facts in this example
- Conformity-assessment route selected for planning
- module b plus c
All recorded assumptions (7)
- Product with digital elements
- Hypothetical example product
- The product’s main features and technical capabilities needed for its intended purpose are documented
- Yes
- Classification based on the product’s own core functionality
- important class ii
- Annex category and technical-description reference
- Annex III, Class II, point 2; standalone firewall core functionality assumed documented.
- Commercial free and open-source software route
- not applicable
- Conformity-assessment route selected for planning
- module b plus c
- The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
- Yes
Evaluated on 2026-09-13 using EU Cyber Resilience Act product classification and conformity route, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Category and core-function rationale
- Selected conformity procedure and scope
- Whole-product security assessment and test references
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Resolve the conformity route before presenting the product as ready for conformity review. Internal testing remains useful evidence within the chosen procedure.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 7, 8, 27 and 32; Annexes III, IV and VIII
- Commission Implementing Regulation (EU) 2025/2392Technical descriptions of Annex III and IV product categories
- European Commission CRA implementation guidance (2026)Section 6 — core functionality and conformity assessment
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.