Yes. Annex III Class II point 2 covers firewalls, intrusion detection and prevention systems, and Class II makes third-party assessment by a notified body mandatory rather than optional.
Firewalls, intrusion detection and prevention systems
Annex III, Class II, point 2, Regulation (EU) 2024/2847
Firewalls and IDS or IPS are one category, so a product that is only one of them carries the same route as a product that is both.
SIEM is Class I point 7, not Class II. The mandatory notified body does not follow from a product being security monitoring - it follows from being in the traffic path as an IDS or IPS, or being a firewall.
VPN function is Class I point 5. An appliance doing both is read on its core functionality - and per recital 4 of Implementing Regulation (EU) 2025/2392, a product does not lose its own core functionality merely by integrating that of another category.
The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.
Indicative assessment - not legal advice and not a conformity assessment.