Annex III, Class II ยท Regulation (EU) 2024/2847

Are firewalls and intrusion detection systems important under the CRA?

Verified against the Official Journal text on

Important product, Class II (Annex III Class II (2), Art. 7(1))

Yes, most likely, and at the higher tier. Firewalls, intrusion detection systems, and intrusion prevention systems are listed as important products in Class II of the EU Cyber Resilience Act (Annex III, Class II, item 2). The regulation uses firewalls as its own worked example: a product whose core functionality is a firewall is subject to mandatory third-party conformity assessment, while a product that merely integrates a firewall is not (Recital 45). Class II gives no self-assessment route, so conformity must go through a notified body or an eligible certification scheme.

Basis: Annex III Class II (2), Art. 7(1), Art. 32(3), Recital 45

Judgment call: Whether a product has the core functionality of a firewall, IDS, or IPS is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

The regulation uses firewalls as its own example Annex III Class II (2), Recital 45, Art. 7(1)

Annex III Class II item 2 reads "Firewalls, intrusion detection and prevention systems". This is the exact category the CRA reaches for when it explains what "core functionality" means. Recital 45 says firewalls and intrusion detection or prevention systems are defined by their core functionality and are subject to mandatory third-party conformity assessment as a result.

The same recital draws the opposite conclusion for products that only integrate such a component: that is not the case for other products with digital elements which merely integrate firewalls or intrusion detection or prevention systems. Article 7(1) states the same rule in operative terms.

Core functionality versus a bundled firewall Art. 7(1), Art. 7(4), Recital 45

The firewall example makes the boundary unusually concrete. A dedicated firewall appliance, an IDS or IPS sensor, or a security product whose reason for existing is filtering or detecting network traffic, has the core functionality of item 2. An operating system, router, or application suite that ships a built-in packet filter as one feature among many does not thereby become a Class II product.

That distinction is doing real work here, because it decides whether a notified body is unavoidable. Where a product genuinely straddles the line, resolve it against Implementing Regulation (EU) 2025/2392 and document the reasoning rather than inferring from the marketing name.

Judgment call: Recital 45 illustrates the core-functionality test but does not give a numeric threshold; the technical descriptions control, and close calls deserve documented reasoning.

Class II: no self-assessment route Recital 44, Art. 32(3), Annex VIII

Class II reflects a higher level of cybersecurity risk than Class I, because an incident in these products can have greater negative impact (Recital 44). Unlike Class I, there is no internal control option: applying harmonised standards in full does not unlock self-assessment for a firewall or IDS/IPS.

Under Article 32(3), conformity must be demonstrated through EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". Two of the three require a notified body, so plan the lead time well before 11 December 2027.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

The Class II route changes how you prove conformity, not the substance of the duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to a firewall or IDS/IPS exactly as to any product.

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class II conformity assessment: modules B and C, module H, or a European cybersecurity certification scheme at assurance level at least "substantial". There is no internal-control option. Then affix the CE marking. (Art. 13(12), Art. 32(3), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

My operating system ships a built-in firewall. Is the OS now Class II?

No. Recital 45 is explicit that a product which merely integrates a firewall is not thereby an important product. A firewall as a bundled feature does not pull the surrounding product into Class II; the question is whether the product has the core functionality of item 2. (Recital 45, Art. 7(1))

Can I self-assess a firewall if I apply harmonised standards in full?

No. Self-assessment on the strength of harmonised standards is a Class I mechanism. Firewalls and IDS/IPS are Class II, and Article 32(3) offers no internal-control route: you need modules B and C, module H, or an eligible European cybersecurity certification scheme. (Art. 32(3))

Are intrusion detection and prevention systems treated the same as firewalls?

Yes. Item 2 lists firewalls together with intrusion detection and prevention systems, and Recital 45 names both in the same worked example. A product with the core functionality of an IDS or IPS sits in the same Class II category as a firewall. (Annex III Class II (2), Recital 45)

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class II conformity route through a notified body or certification, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.