← All CRA guides

Product classes: default, important, critical

Your classification decides how demanding the conformity assessment is.

Default (most products)

Products that are not security-critical may self-assess (conformity assessment under Module A), no external body required. This covers the large majority of SME devices.

Important: Class I and II

Security-relevant products (e.g. network management, password managers, firewalls). Class I can partly self-assess against harmonised standards; Class II generally requires a notified body.

Critical

A small group of particularly critical products may require a European cybersecurity certification.

Put it into practice, instead of just reading about it.

KONFORMA walks you from the software inventory through monitoring to the Declaration of Conformity, self-service, per release, starting free.