Important — class I
The list (Annex III, Part I)
The categories as enumerated by the Regulation. Classification follows actual functionality.
- Identity management systems and privileged access management software and hardware.
- Standalone and embedded browsers.
- Password managers.
- Software that searches for, removes or quarantines malicious software — antivirus, endpoint protection.
- Virtual private network (VPN) products.
- Network management systems.
- Security information and event management (SIEM) systems.
- Boot managers.
- Public key infrastructure and digital certificate issuance software.
- Physical and virtual network interfaces.
- Routers, modems intended for the connection to the internet, and switches.
- Microprocessors, microcontrollers, ASICs and FPGAs with security-related functionalities.
- Smart home general purpose virtual assistants.
- Smart home products with security functionalities: smart locks, security cameras, alarm systems, baby monitoring systems.
- Internet-connected toys with social interactive features or location tracking.
- Personal wearable products intended for health monitoring or worn on the body.
The three assessment routes
| Route | Content | Third party |
|---|---|---|
| Module A — internal control | Full self-assessment | None — but conditional, see below |
| Modules B + C | EU type-examination by a notified body, then conformity to type based on internal control | Notified body |
| Module H | Full quality assurance of the design, development and production system, audited | Notified body |
A fourth possibility exists: holding a European cybersecurity certificate issued under a scheme adopted pursuant to the Cybersecurity Act, at assurance level at least “substantial”, covering the relevant essential requirements.
The condition that changes everything
Module A is open to class I products only if the manufacturer applies in full harmonised standards, common specifications or a European certification scheme covering all the relevant essential requirements.
“In full” and “all” are the two words that matter. Partial application with justified deviations is not enough: it closes the self-assessment route.
Scheduling consequence. Until the harmonised standards arising from standardisation request M/606 — work of the joint technical committee CEN/CENELEC JTC 13, working group 9 — are published and cited in the Official Journal of the European Union, the module A route is closed in practice for class I. A standard adopted but not cited in the OJ confers no presumption of conformity.
What to decide now
Two scenarios to work in parallel, and one default:
- Standards scenario — the harmonised standards are published and cited in time; you demonstrate full application and stay in module A. Low cost, controlled lead time, uncertain probability.
- Notified body scenario — you engage a body under modules B+C or H. Significant cost, several months of lead time, within your control provided you book early.
The prudent position is to treat scenario 2 as the base case and scenario 1 as a possible saving. The reverse exposes you to discovering in 2027 that no assessment slot is available.
Qualification watch points
- An embedded browser inside another product pushes that product into class I. A web rendering component inside a desktop application must be examined on that basis.
- A microcontroller with security-related functionalities falls under class I; if it is also tamper-resistant, it falls under class II. The boundary is technical and must be settled by engineering, not by Legal.
- A smart home product is class I only if it has security functionalities. A connected light bulb is not; a security camera is.
- Connected toys fall under class I only where there is social interaction or location tracking — but they remain subject to toy safety legislation regardless.