Annex III, Class I ยท Regulation (EU) 2024/2847

Is antivirus or EDR software an important product under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (4), Art. 7(1))

Yes, most likely. The CRA lists "software that searches for, removes, or quarantines malicious software" as an important product (Annex III, Class I, item 4). Antivirus, anti-malware, and endpoint detection and response (EDR) tools whose core functionality is detecting or removing malware fall inside it. That carries the full manufacturer obligations and a restricted conformity route: self-assessment stays available only where harmonised standards, common specifications, or eligible certification are applied in full.

Basis: Annex III Class I (4), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a product "has the core functionality of" malware detection or removal is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

How the CRA describes this category Annex III Class I (4), Art. 7(1), Art. 7(2), Art. 7(4)

Item 4 of Class I is functional, not brand-based: "software that searches for, removes, or quarantines malicious software". Any of those three verbs is enough. Classic antivirus, modern EDR and XDR agents, on-access scanners, and email or web gateways whose job is catching malicious payloads all match the description.

The reason it sits in Class I is set out in Article 7(2): products that primarily perform functions critical to the cybersecurity of other products, such as endpoint security, are treated as important. The binding scope is the technical description in the implementing act, so confirm your product against that rather than against the label.

Security suites and the core-functionality test Art. 7(1), Art. 7(4)

Many products bundle a malware scanner into a larger suite: a backup tool that scans on restore, a firewall appliance with an anti-malware module, an email platform with attachment scanning. The test is core functionality. Where searching for, removing, or quarantining malware is central to what the product is, item 4 applies to it.

Where the scanner is one subordinate feature of a product that does something else entirely, Article 7(1) says integrating such a component does not, in itself, make the surrounding product an important product. That is a genuine judgment call for suites, so resolve it against Implementing Regulation (EU) 2025/2392 and document how you landed.

Judgment call: The line between an anti-malware product and a product that merely includes a scanner has no bright-line rule in the CRA; the implementing act controls, and close calls deserve documented reasoning.

What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII

For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. Plan for that lead time well before 11 December 2027.

Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to anti-malware software as they do to any product in scope. A tool that runs at high privilege makes secure update delivery especially important.

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

My product only scans files as a side feature. Is it anti-malware under the CRA?

Only if searching for, removing, or quarantining malicious software is its core functionality. A subordinate scanner inside a product that does something else does not, on its own, place the whole product in item 4, but a close call should be resolved against the implementing act and documented. (Art. 7(1), Art. 7(4))

Does EDR or XDR count as anti-malware?

Where the product searches for, removes, or quarantines malicious software as its core job, it matches item 4 regardless of the marketing label. EDR and XDR agents that do this are in the Class I category. (Annex III Class I (4))

Can I still self-assess as a Class I product?

Only where you apply harmonised standards, common specifications, or an eligible European cybersecurity certification scheme at assurance level at least "substantial" in full. Otherwise a notified body route applies (modules B and C, or module H). (Art. 32(2))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.