CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Worked example · Enterprise security

Important Class II - the self-assessment route closes entirely

A network security vendor selling appliances and virtual appliances

Worked example - a product archetype run through the CRASPACE rulebook. Not a client engagement, and not a conformity assessment.

The verdict

CRA scope
In scope
Class
Important - Class II
Basis
Annex III, Part II
Conformity route
Third-party (notified body) assessment is mandatory

Descriptor matched: Firewall

The products assessed

  • Next-generation firewall applianceFirewall · network, cloud management, API
  • Virtual firewall for hypervisorsFirewall · hypervisor, API, cloud

Why it lands there

  1. Firewalls are named in Annex III Part II. Part II is the step where conformity stops being something a manufacturer can declare alone: a notified body assessment is mandatory regardless of which harmonised standards are applied.
  2. That single fact reshapes the programme. A notified body has to be selected, engaged, scheduled and paid, and its availability - not the engineering work - is frequently what sets the date.
  3. The virtual appliance classifies the same way. Delivery as a software image does not move a firewall out of Part II.
  4. The management plane is in the assessment's scope where it is part of the product. A firewall administered by a cloud console is one product with two exposed surfaces.

What follows from it

  • Everything in the Important Class I list, plus:
  • A notified body conformity assessment - mandatory, with no self-assessment alternative
  • A technical file built to withstand third-party review rather than internal sign-off
  • Lead-time planning against notified-body capacity, which is finite and shared across every Part II manufacturer in the EU

The trap on this one

The scheduling risk is routinely underestimated. Notified-body capacity is the constraint the whole EU shares, and the December 2027 date is the same for everyone - which means demand arrives at the same time for everyone.

The questions this leaves open

A public-evidence scan cannot answer these. They are what a consultation is for, and they are deliberately questions rather than instructions.

  • Has a notified body been approached, and what is its current lead time for an Annex III Part II product?
  • Is the cloud management plane inside the declared product boundary, or documented as a separate service?
  • Does the technical file exist in a form a third party can audit, or as internal engineering documentation that has never been read by an outsider?

The realistic next step

The useful work before the notified body is pre-assessment: getting the evidence and the technical file into a state that survives third-party review. We are not a notified body and cannot perform the Part II assessment - that engagement is separate and is yours to make. CRASPACE says so here rather than blurring it.

This is an archetype. Yours is not. Run the check against your own company and get the same reasoning applied to the products you actually ship, each with a source you can open.