CRA compliance for IoT sensor
Important class II (Annex III)
About CRA compliance for IoT sensor
An IoT sensor collects measurement data and transmits it over a network. Its attack surface is small but real: firmware update path, wireless communication, and any stored configuration. The CRA documentation set for a sensor is comparatively light, which makes it a fast demonstration of the motor: SBOM, a short Annex VII file, and the Annex I checklist.
What the Important class II (Annex III) means for this product
Important class II products sit in the higher-risk half of the Annex III list. Conformity assessment generally requires third-party involvement: an EU-type examination by a notified body (Module B) followed by conformity to type (Module C), or a full quality assurance route (Module H). The technical documentation under Annex VII is the basis for that examination, so its completeness and traceability to the product state matters directly.
Where this device type sits in the Regulation
In the Regulation's own structure, a generic sensing device is NOT named in Annex III or Annex IV, so it would fall in the default class under Art. 32(1)(a) (Regulation (EU) 2024/2847), unless a specific product matches a named category for another reason. Whether THIS specific sensor is actually outside the annexes is the manufacturer's guided questionnaire answer, never an assumption of this site.
Conformity assessment
EU-type examination (Module B+C) or full quality assurance (Module H), notified body required
Annex III / IV structure
Annex III, Class II (Regulation (EU) 2024/2847, Art. 32(3))
The Regulation's own structure names these 4 categories in Annex III, Class II:
- hypervisors and container runtimes supporting virtualised execution of operating systems
- firewalls, intrusion detection or prevention systems used for security purposes
- tamper-resistant microprocessors
- tamper-resistant microcontrollers
This is the Regulation's own structure (Regulation (EU) 2024/2847, Annex III Class II), not an assessment of any specific product. Whether a particular product falls within a named category is the manufacturer's guided questionnaire answer, never an assumption of this site.
Key obligations
- Third-party conformity assessment via a notified body before placing on the market
- EU-type examination certificate, then conformity to type for each production unit
- Annex VII technical documentation complete and traceable to the assessed type
- Ongoing surveillance of the certified type where the module requires it
Typical components to document (SBOM)
Sensor driverWireless stack (BLE / Zigbee / LoRa)Low-power MCU firmwareTLS library
Relevant Annex I requirements
I.2(e)— encrypt the transmitted measurement dataI.2(c)— a reliable, user-notified firmware update pathII.1— document components in a machine-readable SBOM
Get the compliance document set
Annex VII technical documentation, EU DoC and the Annex I checklist, generated from your product's SBOM. Leave an email and we will send it when the generator is open.