How the CRA describes this category Annex III Class I (4), Art. 7(1), Art. 7(2), Art. 7(4)
Item 4 of Class I is functional, not brand-based: "software that searches for, removes, or quarantines malicious software". Any of those three verbs is enough. Classic antivirus, modern EDR and XDR agents, on-access scanners, and email or web gateways whose job is catching malicious payloads all match the description.
The reason it sits in Class I is set out in Article 7(2): products that primarily perform functions critical to the cybersecurity of other products, such as endpoint security, are treated as important. The binding scope is the technical description in the implementing act, so confirm your product against that rather than against the label.
Security suites and the core-functionality test Art. 7(1), Art. 7(4)
Many products bundle a malware scanner into a larger suite: a backup tool that scans on restore, a firewall appliance with an anti-malware module, an email platform with attachment scanning. The test is core functionality. Where searching for, removing, or quarantining malware is central to what the product is, item 4 applies to it.
Where the scanner is one subordinate feature of a product that does something else entirely, Article 7(1) says integrating such a component does not, in itself, make the surrounding product an important product. That is a genuine judgment call for suites, so resolve it against Implementing Regulation (EU) 2025/2392 and document how you landed.
Judgment call: The line between an anti-malware product and a product that merely includes a scanner has no bright-line rule in the CRA; the implementing act controls, and close calls deserve documented reasoning.
What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII
For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.
Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. Plan for that lead time well before 11 December 2027.
Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to anti-malware software as they do to any product in scope. A tool that runs at high privilege makes secure update delivery especially important.