30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Annex III, Class I, point 4
Is antivirus or endpoint protection software an important product under the CRA?
Yes. Annex III Class I covers software that searches for, removes, or quarantines malicious software, which is what antivirus, anti-malware and endpoint detection and response products do.
ClassImportant - Class I
What that class requiresSelf-assessment only if harmonised standards applied; else notified body
The category, quoted in full:
Software that searches for, removes, or quarantines malicious software
Intrusion detection and prevention is Class II point 2, where a notified body is mandatory; software that searches for, removes or quarantines malicious software is Class I point 4. An EDR product doing both answers to whichever is its core functionality - integrating the other does not in itself move it, per recital 4 of Implementing Regulation (EU) 2025/2392.
Obligations that apply to every product in scope, whatever its class:
Essential requirements (Annex I) - secure by design & default
Economic-operator & market-surveillance obligations Art 13/19–24 · Annex II
The dates that matter:
11 September 2026 - reporting obligations for actively exploited vulnerabilities and severe incidents apply.
11 December 2027 - full compliance applies.
Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.
Check your own products against this
The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.