What a boot manager is, for CRA purposes Annex III Class I (8), Art. 7(1), Art. 7(2), Art. 7(4)
Item 8 of Class I names "boot managers" plainly. In practice this reaches the software that runs very early in a device start-up to select, verify, and hand control to an operating system or further firmware. Both a bootloader and a boot manager that presents a choice of boot targets are the kind of software the category is about.
It is in Class I because it performs a function critical to the security of everything above it, in the sense of Article 7(2): whatever runs before the operating system anchors the chain of trust, and a compromise there undermines every later defence. The binding scope is the technical description in the implementing act, not the label.
When a boot manager is a product placed on the market Art. 7(1), Art. 3(1)
A boot manager is often shipped inside a larger product: it is embedded in device firmware, in an operating system image, or on a hardware board. Where you place a boot manager on the market as a product with digital elements in its own right, item 8 applies to it directly.
Where a boot manager is a component integrated into a wider product, Article 7(1) is explicit that integrating a listed component does not, in itself, make the surrounding product an important product. The surrounding operating system or device is assessed on its own listing. Confirm which case you are in and record the reasoning.
Judgment call: Whether early-boot code is placed on the market as its own product or only integrated into another product turns on how you actually supply it; the implementing act settles the category match.
What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII
For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.
Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. Plan for that lead time well before 11 December 2027.
Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to a boot manager as they do to any product in scope. Integrity of updates to early-boot code deserves particular care.