CRA compliance for Network router
Important class I (Annex III)
About CRA compliance for Network router
A router is a high-value target because it sits at the network edge. Its CRA documentation has to cover the network stack, the management interface and the update mechanism, and the risk assessment has to reflect that a compromise of the device compromises the whole network behind it.
What the Important class I (Annex III) means for this product
Important class I products are listed in Annex III. Module A (internal control) is available for them ONLY where the manufacturer fully applied harmonised standards, common specifications or a European cybersecurity certification scheme of at least substantial level (Art. 32(2)). The CRA harmonised standards are largely not yet published, so in practice most class I products cannot use Module A today and must use EU-type examination with a notified body (Module B+C) or full quality assurance (Module H). The route is established by the guided classification questionnaire, never assumed.
Where this device type sits in the Regulation
In the Regulation's own structure, 'routers, modems and switches intended for connection to the internet' are named in Annex III Class I (Regulation (EU) 2024/2847, Art. 32(2)). Whether THIS specific router is caught by that named category is the manufacturer's guided questionnaire answer, never an assumption of this site.
Conformity assessment
EU-type examination (Module B+C) or full quality assurance (Module H); Module A only with full harmonised standards / ECS scheme (Art. 32(2))
Annex III / IV structure
Annex III, Class I (Regulation (EU) 2024/2847, Art. 32(2))
The Regulation's own structure names these 19 categories in Annex III, Class I:
- identity management systems and privileged access management (PAM) software and hardware
- standalone and embedded browsers
- password managers
- software that searches for, removes or quarantines malicious software
- virtual private network (VPN) products
- network management systems
- security information and event management (SIEM) systems
- boot managers
- public key infrastructure (PKI) and digital certificate issuing software
- physical and virtual network interfaces
- operating systems
- routers, modems and switches intended for connection to the internet
- microprocessors with security-related functionalities and microcontrollers
- application-specific integrated circuits (ASIC) and field-programmable gate arrays (FPGA) with security-related functionalities
- smart home products with security functionalities, including smart home gateways, smart home hubs and smart home central points of control
- internet-connected toys
- personal wearables for health tracking and smart textiles
- internet-connected cameras, smart door locks and baby monitors
- smart speakers, smart displays and virtual assistants
This is the Regulation's own structure (Regulation (EU) 2024/2847, Annex III Class I), not an assessment of any specific product. Whether a particular product falls within a named category is the manufacturer's guided questionnaire answer, never an assumption of this site.
Key obligations
- All default-class obligations, plus the stricter documentation duties of the important class
- Verification against the review criteria of Article 7(2) and the Annex III categories
- Notification of the market surveillance authority after placing on the market where required
- Conformity assessment route confirmed during the compliance assessment, not assumed
Typical components to document (SBOM)
Linux kernelWi-Fi driverVPN / firewall stackWeb management UITLS library
Relevant Annex I requirements
I.2(j)— limit the attack surface of the management interfaceI.2(c)— timely security updates for the router firmwareI.2(i)— minimise negative impact on other devices and networks
Get the compliance document set
Annex VII technical documentation, EU DoC and the Annex I checklist, generated from your product's SBOM. Leave an email and we will send it when the generator is open.