The situation
A supplier sells a network router. The team has documented its core function and Class I classification but has not established that it applies a complete relevant presumption-of-conformity basis. A test report covering only one security feature cannot stand in for that route assessment.
Facts that change the answer
- Does the core function match the implementing regulation’s router description?
- Is the relevant conformity basis available and fully applied?
- Does the assessment cover the whole product and its risks?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Class I with an incomplete conformity basis
Hypothetical example 1
Select and document an eligible third-party conformity route before placing the product on the market.(CRA Article 32(2)–(4))
Key facts in this example
- Annex category and technical-description reference
- Annex III, Class I, point 12; Regulation 2025/2392 router description, assumed matched by this example.
- For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
- no or partial
- Conformity-assessment route selected for planning
- not selected
All recorded assumptions (8)
- Product with digital elements
- Hypothetical example product
- The product’s main features and technical capabilities needed for its intended purpose are documented
- Yes
- Classification based on the product’s own core functionality
- important class i
- Annex category and technical-description reference
- Annex III, Class I, point 12; Regulation 2025/2392 router description, assumed matched by this example.
- Commercial free and open-source software route
- not applicable
- For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
- no or partial
- Conformity-assessment route selected for planning
- not selected
- The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
- Yes
Hypothetical complete relevant conformity basis
Hypothetical example 2
Key facts in this example
- Annex category and technical-description reference
- Annex III, Class I, point 12; complete relevant basis assumed for illustration, availability must be checked.
- For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
- yes
- Conformity-assessment route selected for planning
- module a internal control
All recorded assumptions (8)
- Product with digital elements
- Hypothetical example product
- The product’s main features and technical capabilities needed for its intended purpose are documented
- Yes
- Classification based on the product’s own core functionality
- important class i
- Annex category and technical-description reference
- Annex III, Class I, point 12; complete relevant basis assumed for illustration, availability must be checked.
- Commercial free and open-source software route
- not applicable
- For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
- yes
- Conformity-assessment route selected for planning
- module a internal control
- The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
- Yes
Evaluated on 2026-09-13 using EU Cyber Resilience Act product classification and conformity route, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Core-function mapping to Annex III and Regulation 2025/2392
- Coverage matrix for the selected conformity basis
- Documented procedure and assessment-body arrangements where needed
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Confirm current standards and route availability when making the real assessment. A hypothetical fully covered route is not a claim that a particular standard is available today.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Articles 7, 8, 27 and 32; Annexes III, IV and VIII
- Commission Implementing Regulation (EU) 2025/2392Technical descriptions of Annex III and IV product categories
- European Commission CRA implementation guidance (2026)Section 6 — core functionality and conformity assessment
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.