CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Reference · plain-English guide

The CRA annexes & classes, explained

CRASPACE refers to these throughout your report. This page is a quick, non-legal guide to what each one means. The authoritative text is the official Regulation (EU) 2024/2847 and its implementing regulation 2025/2392.

The four product classes

Default~90% of products

Everyday products with digital elements (memory chips, most mobile apps, smart speakers, connected toys without special functions). Self-assessment against the essential requirements - no notified body.

Important · Class IAnnex III, Part I

Security-adjacent products: password managers, VPNs, network management, browsers, antivirus/EDR, SOHO routers. Self-assessment if you apply harmonised standards; otherwise a notified body.

Important · Class IIAnnex III, Part II

Higher-impact security products: firewalls, hypervisors, industrial intrusion-detection systems, tamper-resistant microprocessors. A notified body assessment is mandatory.

CriticalAnnex IV

The highest-risk category: smart cards / secure elements, smart-meter gateways, hardware security modules. Notified body and potentially a mandatory EU cybersecurity certificate.

The annexes we cite

Annex IEssential cybersecurity requirements

What every in-scope product must satisfy. Two parts: product properties - secure by design and by default, shipped free of known exploitable vulnerabilities, minimal attack surface, protection of data - and vulnerability-handling processes - an SBOM, coordinated disclosure, and security updates across the support period (typically ~5 years).

Annex III“Important” products

The list that defines Important Class I and Class II products (above). Being on this list raises the conformity route above simple self-assessment. See the list →

Annex IV“Critical” products

The narrowest, highest-assurance list - products where a security failure has the broadest blast radius. Always requires a notified body; may require an EU cybersecurity certificate at assurance level ‘substantial’ or higher.

Annex VIITechnical documentation

The dossier you must compile and keep: product description, design/development/production details, the cybersecurity risk assessment, the vulnerability-handling processes, applied standards, and the EU Declaration of Conformity. It's the evidence behind your CE mark.

Key dates & penalties

10 Dec 2024In force

The regulation applies across the EU; the transition period begins.

11 Sep 2026Reporting duties

Actively exploited vulnerabilities & severe incidents must be reported to ENISA and your national CSIRT within 24h / 72h.

11 Dec 2027Full compliance

All essential requirements apply. CE marking & an EU Declaration of Conformity are required to sell.

€15m / 2.5%Maximum fine

Up to €15 million or 2.5% of global annual turnover, whichever is higher - plus withdrawal or recall.

This guide is indicative and simplified - not legal advice or a conformity assessment.