Important — class I

The list (Annex III, Part I)

The categories as enumerated by the Regulation. Classification follows actual functionality.

  • Identity management systems and privileged access management software and hardware.
  • Standalone and embedded browsers.
  • Password managers.
  • Software that searches for, removes or quarantines malicious software — antivirus, endpoint protection.
  • Virtual private network (VPN) products.
  • Network management systems.
  • Security information and event management (SIEM) systems.
  • Boot managers.
  • Public key infrastructure and digital certificate issuance software.
  • Physical and virtual network interfaces.
  • Routers, modems intended for the connection to the internet, and switches.
  • Microprocessors, microcontrollers, ASICs and FPGAs with security-related functionalities.
  • Smart home general purpose virtual assistants.
  • Smart home products with security functionalities: smart locks, security cameras, alarm systems, baby monitoring systems.
  • Internet-connected toys with social interactive features or location tracking.
  • Personal wearable products intended for health monitoring or worn on the body.

The three assessment routes

Route Content Third party
Module A — internal control Full self-assessment None — but conditional, see below
Modules B + C EU type-examination by a notified body, then conformity to type based on internal control Notified body
Module H Full quality assurance of the design, development and production system, audited Notified body

A fourth possibility exists: holding a European cybersecurity certificate issued under a scheme adopted pursuant to the Cybersecurity Act, at assurance level at least “substantial”, covering the relevant essential requirements.

The condition that changes everything

Module A is open to class I products only if the manufacturer applies in full harmonised standards, common specifications or a European certification scheme covering all the relevant essential requirements.

“In full” and “all” are the two words that matter. Partial application with justified deviations is not enough: it closes the self-assessment route.

Scheduling consequence. Until the harmonised standards arising from standardisation request M/606 — work of the joint technical committee CEN/CENELEC JTC 13, working group 9 — are published and cited in the Official Journal of the European Union, the module A route is closed in practice for class I. A standard adopted but not cited in the OJ confers no presumption of conformity.

What to decide now

Two scenarios to work in parallel, and one default:

  1. Standards scenario — the harmonised standards are published and cited in time; you demonstrate full application and stay in module A. Low cost, controlled lead time, uncertain probability.
  2. Notified body scenario — you engage a body under modules B+C or H. Significant cost, several months of lead time, within your control provided you book early.

The prudent position is to treat scenario 2 as the base case and scenario 1 as a possible saving. The reverse exposes you to discovering in 2027 that no assessment slot is available.

Qualification watch points

  • An embedded browser inside another product pushes that product into class I. A web rendering component inside a desktop application must be examined on that basis.
  • A microcontroller with security-related functionalities falls under class I; if it is also tamper-resistant, it falls under class II. The boundary is technical and must be settled by engineering, not by Legal.
  • A smart home product is class I only if it has security functionalities. A connected light bulb is not; a security camera is.
  • Connected toys fall under class I only where there is social interaction or location tracking — but they remain subject to toy safety legislation regardless.