Every verdict is produced by a deterministic, versioned rulebook rather than by a model. This page is that rulebook: the scoping flow, the four classes, the conformity route each one carries, and the eleven checkpoints a manufacturer is assessed against - each with the Article or Annex it rests on.
Product discovery uses AI: it reads a company's own site to find out what that company sells. Classification does not. The verdict comes from descriptors matched against Annex III and Annex IV, so the same inputs always produce the same output, every verdict carries the methodology version that produced it, and a cached report is regenerated when that version changes.
The practical test of that separation: a page on this site cannot state a class the tool would not give, because both read the same file.
Six steps, in order. Steps 1 and 4 are decided by the engine. Steps 0, 2, 3 and 6 depend on facts that are not in a product description - who manufactures it, whether a sectoral regime already governs it - so they are recorded as reasoning and sensitivities rather than auto-decided. A hypothesis is labelled as one.
Annex III lists 19 Class I and 4 Class II categories; Annex IV lists 3 critical ones. Everything else with digital elements is Default. 24 pages cover those 26 categories one by one.
| Class | Annex | Conformity route |
|---|---|---|
| Critical | Annex IV | Art 32(3) procedures (as Class II) - plus an EU cybersecurity certificate at assurance ≥ substantial IF the Commission adopts a delegated act under Art 8(1) for the category |
| Important - Class II | Annex III, Part II | Third-party (notified body) assessment mandatory |
| Important - Class I | Annex III, Part I | Self-assessment only if harmonised standards applied; else notified body |
| Default | n/a | Self-assessment (Module A) |
What a manufacturer is assessed against, each with its basis in the regulation. A checkpoint with public evidence is met, with partial evidence is partial, and with none is unknown - not failed. Absence of public evidence is not evidence of a gap, and a maturity score built from silence would be a number we invented.
Where none of the eleven is evidenced, the report shows 0 of 11 · NOT SCORED rather than a score. That is deliberate and is not a defect to fix.
Class decides the conformity route. It does not decide whether these apply.
The assessment identifies; it does not prescribe. It gives scope, classification per product, a readiness checklist and the open questions that would change the answer. It deliberately does not produce a remediation roadmap - that depends on your architecture, your suppliers and your release process, none of which is visible from outside.
On the boundary of what we can do: CRASPACE is not a notified body and does not issue CRA certificates. Where a product is Critical under Annex IV, the honest next step is guidance plus a hand-off to an accredited certification body, and that is what the tool says.
Key dates: reporting obligations from 11 September 2026, full compliance from 11 December 2027. Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.
The check applies exactly this methodology and shows the reasoning and the citation for every product it classifies.
Indicative assessment - not legal advice and not a conformity assessment.