Default (most products)
Products that are not security-critical may self-assess (conformity assessment under Module A), no external body required. This covers the large majority of SME devices.
Important: Class I and II
Security-relevant products (e.g. network management, password managers, firewalls). Class I can partly self-assess against harmonised standards; Class II generally requires a notified body.
Critical
A small group of particularly critical products may require a European cybersecurity certification.