CRA compliance for Network router
Important class II (Annex III)
About CRA compliance for Network router
A router is a high-value target because it sits at the network edge. Its CRA documentation has to cover the network stack, the management interface and the update mechanism, and the risk assessment has to reflect that a compromise of the device compromises the whole network behind it.
What the Important class II (Annex III) means for this product
Important class II products sit in the higher-risk half of the Annex III list. Conformity assessment generally requires third-party involvement: an EU-type examination by a notified body (Module B) followed by conformity to type (Module C), or a full quality assurance route (Module H). The technical documentation under Annex VII is the basis for that examination, so its completeness and traceability to the product state matters directly.
Where this device type sits in the Regulation
In the Regulation's own structure, 'routers, modems and switches intended for connection to the internet' are named in Annex III Class I (Regulation (EU) 2024/2847, Art. 32(2)). Whether THIS specific router is caught by that named category is the manufacturer's guided questionnaire answer, never an assumption of this site.
Conformity assessment
EU-type examination (Module B+C) or full quality assurance (Module H), notified body required
Annex III / IV structure
Annex III, Class II (Regulation (EU) 2024/2847, Art. 32(3))
The Regulation's own structure names these 4 categories in Annex III, Class II:
- hypervisors and container runtimes supporting virtualised execution of operating systems
- firewalls, intrusion detection or prevention systems used for security purposes
- tamper-resistant microprocessors
- tamper-resistant microcontrollers
This is the Regulation's own structure (Regulation (EU) 2024/2847, Annex III Class II), not an assessment of any specific product. Whether a particular product falls within a named category is the manufacturer's guided questionnaire answer, never an assumption of this site.
Key obligations
- Third-party conformity assessment via a notified body before placing on the market
- EU-type examination certificate, then conformity to type for each production unit
- Annex VII technical documentation complete and traceable to the assessed type
- Ongoing surveillance of the certified type where the module requires it
Typical components to document (SBOM)
Linux kernelWi-Fi driverVPN / firewall stackWeb management UITLS library
Relevant Annex I requirements
I.2(j)— limit the attack surface of the management interfaceI.2(c)— timely security updates for the router firmwareI.2(i)— minimise negative impact on other devices and networks
Get the compliance document set
Annex VII technical documentation, EU DoC and the Annex I checklist, generated from your product's SBOM. Leave an email and we will send it when the generator is open.