30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Annex III, Class I, point 7
Is a SIEM Class I or Class II under the CRA?
Class I. Annex III lists security information and event management systems at Class I point 7, separately from intrusion detection and prevention at Class II point 2. A SIEM is an important product, but the mandatory notified body that applies to Class II does not follow from being a SIEM.
ClassImportant - Class I
What that class requiresSelf-assessment only if harmonised standards applied; else notified body
The category, quoted in full:
Security information and event management (SIEM) systems
This is the single most commonly mis-stated classification in the CRA, including by tools. Getting it wrong in either direction changes whether a third party must be involved at all.
IDS and IPS are Class II point 2. A SIEM ingests and correlates events; an IPS sits in the traffic path and blocks. A platform that does both has a Class II component, and that component decides the route for it.
Obligations that apply to every product in scope, whatever its class:
Essential requirements (Annex I) - secure by design & default
Economic-operator & market-surveillance obligations Art 13/19–24 · Annex II
The dates that matter:
11 September 2026 - reporting obligations for actively exploited vulnerabilities and severe incidents apply.
11 December 2027 - full compliance applies.
Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.
Check your own products against this
The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.