Classification

Which CRA conformity route applies to a router?

First match the core routing function to the legal category. For a Class I example, the available internal-control route depends on the applicable conformity basis and its coverage.

Prepared by CRA Operations · Updated 2026-09-13 · Hypothetical worked examples

The situation

A supplier sells a network router. The team has documented its core function and Class I classification but has not established that it applies a complete relevant presumption-of-conformity basis. A test report covering only one security feature cannot stand in for that route assessment.

Facts that change the answer

  • Does the core function match the implementing regulation’s router description?
  • Is the relevant conformity basis available and fully applied?
  • Does the assessment cover the whole product and its risks?

Compare the worked results

These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.

Class I with an incomplete conformity basis

Hypothetical example 1

Assessment resultthird party route required

Select and document an eligible third-party conformity route before placing the product on the market.(CRA Article 32(2)–(4))

Key facts in this example
Annex category and technical-description reference
Annex III, Class I, point 12; Regulation 2025/2392 router description, assumed matched by this example.
For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
no or partial
Conformity-assessment route selected for planning
not selected
All recorded assumptions (8)
Product with digital elements
Hypothetical example product
The product’s main features and technical capabilities needed for its intended purpose are documented
Yes
Classification based on the product’s own core functionality
important class i
Annex category and technical-description reference
Annex III, Class I, point 12; Regulation 2025/2392 router description, assumed matched by this example.
Commercial free and open-source software route
not applicable
For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
no or partial
Conformity-assessment route selected for planning
not selected
The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
Yes

Hypothetical complete relevant conformity basis

Hypothetical example 2

Assessment resultmodule a available
Key facts in this example
Annex category and technical-description reference
Annex III, Class I, point 12; complete relevant basis assumed for illustration, availability must be checked.
For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
yes
Conformity-assessment route selected for planning
module a internal control
All recorded assumptions (8)
Product with digital elements
Hypothetical example product
The product’s main features and technical capabilities needed for its intended purpose are documented
Yes
Classification based on the product’s own core functionality
important class i
Annex category and technical-description reference
Annex III, Class I, point 12; complete relevant basis assumed for illustration, availability must be checked.
Commercial free and open-source software route
not applicable
For an important class I product, all applicable requirements of the relevant harmonised standard, common specification or qualifying certification are applied and its scope covers all cybersecurity risks associated with the product’s core functionality
yes
Conformity-assessment route selected for planning
module a internal control
The conformity plan covers the product as a whole, including cybersecurity risks from ancillary functions and integrated components
Yes

Evaluated on 2026-09-13 using EU Cyber Resilience Act product classification and conformity route, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.

Evidence to keep

  • Core-function mapping to Annex III and Regulation 2025/2392
  • Coverage matrix for the selected conformity basis
  • Documented procedure and assessment-body arrangements where needed

Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.

Your next step

Confirm current standards and route availability when making the real assessment. A hypothetical fully covered route is not a claim that a particular standard is available today.

Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.

Sources and application dates

Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.

These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.

Related situations