Annex III, Class I ยท Regulation (EU) 2024/2847

Are internet connected toys important products under the CRA?

Verified against the Official Journal text on

Important product, Class I (with those features) (Annex III Class I (18), Art. 7(1))

It depends on the features. Internet connected toys covered by the Toy Safety Directive (2009/48/EC) are important products under the EU Cyber Resilience Act (Annex III, Class I, item 18) when they have social interactive features, such as speaking or filming, or location tracking features. A toy with those features carries the full manufacturer obligations, and self-assessment stays available only where harmonised standards, common specifications, or eligible certification are applied in full. A connected toy without those features is still in scope, but as a default-category product with the free choice of conformity route.

Basis: Annex III Class I (18), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a toy has a "social interactive" or "location tracking" feature is the pivot, and it is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

What item 18 actually lists Annex III Class I (18), Art. 7(1), Art. 7(4)

Annex III Class I item 18 covers "Internet connected toys covered by Directive 2009/48/EC ... that have social interactive features (e.g. speaking or filming) or that have location tracking features". Two conditions stack: the product is a toy under the Toy Safety Directive, and it is internet connected, and then the feature test decides whether it is an important product.

The Commission set the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392). A product with the core functionality of the category moves to the stricter conformity assessment procedures of Article 32(2), so the presence of a qualifying feature is what tips a connected toy into Class I.

The feature test: social interaction or tracking Annex III Class I (18), Art. 32(1)

Speaking, filming, and location tracking are the features that pull a connected toy into item 18. A toy that talks with a child, records audio or video, or reports where the child is carries the kind of risk the category targets. A connected toy that merely updates firmware or shows a score, with none of those features, does not fall in item 18.

A toy outside item 18 is not outside the CRA. If it is a product with digital elements made available on the EU market, it remains in scope as a default-category product, with the ordinary free choice of conformity route, rather than the restricted Class I route. Confirm the feature question against Implementing Regulation (EU) 2025/2392 for a close call.

Judgment call: The CRA gives examples ("speaking or filming") rather than a closed definition of "social interactive features"; the technical descriptions control, and borderline toys deserve documented reasoning.

The Toy Safety Directive still applies alongside Annex III Class I (18), Art. 32(2), Annex VIII

Item 18 is scoped to toys covered by Directive 2009/48/EC. That directive continues to govern toy safety in its own right; the CRA adds cybersecurity requirements on top for connected toys with the qualifying features, rather than replacing the toy safety regime.

For a Class I connected toy, internal control (module A) stays available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial" in full. Otherwise the route is EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H) via a notified body.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Whichever route applies, the substance of the duties is the same: essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents. Toys that process children data warrant particular care on these duties.

What you must do

  • Design, develop, and produce the toy in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and, where the feature test is met, carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

My connected toy has no microphone, camera, or tracking. Is it out of scope?

Not out of scope, but not Class I either. Without a social interactive or location tracking feature it falls outside item 18. If it is a product with digital elements on the EU market it stays in scope as a default-category product with the free choice of conformity route. (Annex III Class I (18), Art. 32(1))

What counts as a "social interactive feature"?

The CRA gives speaking and filming as examples rather than a closed list. A toy that converses with a child or records audio or video is the kind of case item 18 targets. Borderline features should be resolved against the technical descriptions and documented. (Annex III Class I (18), Art. 7(4))

Does the CRA replace the Toy Safety Directive?

No. Item 18 applies to toys covered by Directive 2009/48/EC, which continues to govern toy safety. The CRA adds cybersecurity obligations for connected toys with the qualifying features on top of the existing toy safety regime. (Annex III Class I (18))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including any Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your toy lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.