Annex III, Class II ยท Regulation (EU) 2024/2847

Are hypervisors and container runtimes important products under the CRA?

Verified against the Official Journal text on

Important product, Class II (Annex III Class II (1), Art. 7(1))

Yes, most likely, and at the higher tier. Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments are listed as important products in Class II of the EU Cyber Resilience Act (Annex III, Class II, item 1). Class II removes the self-assessment option entirely: there is no internal-control route. Conformity must go through EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". Each of those involves a notified body or a certification scheme.

Basis: Annex III Class II (1), Art. 7(1), Art. 32(3)

Judgment call: Whether a product has the core functionality of a hypervisor or container runtime is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

Where the CRA puts virtualisation software Annex III Class II (1), Art. 7(1), Art. 7(4)

Annex III splits important products into Class I and the higher Class II. Item 1 of Class II reads "Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments". A product with the core functionality of that category is a Class II important product and moves to the conformity assessment procedures of Article 32(3).

The Commission fixed the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392). That description, not the plain-language label, decides whether a given product matches item 1, so it governs edge cases such as lightweight runtimes or emulators.

Why Class II removes the self-assessment route Art. 7(2), Art. 32(3), Annex VIII

The CRA treats virtualisation as a central system function whose compromise can affect a large number of workloads at once, which is why it sits in the higher class. Unlike Class I, Class II gives no internal-control option: applying harmonised standards in full does not unlock self-assessment here.

Under Article 32(3), a Class II product must demonstrate conformity through EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". Two of the three routes require a notified body, so plan lead time and cost well before 11 December 2027.

Core functionality, not a virtualisation feature Art. 7(1), Art. 7(4)

Classification turns on core functionality. A hypervisor or a container runtime whose reason for existing is running isolated workloads has the core functionality of item 1. A broader product that merely embeds a runtime as a supporting component is a different question, and Article 7(1) says integration alone does not pull the surrounding product into the Class II procedures.

Where the line is genuinely close, for example an application platform that ships an embedded sandbox, resolve it against Implementing Regulation (EU) 2025/2392 and record your reasoning. The classification decides whether a notified body is unavoidable, so it deserves care rather than a guess from the label.

Judgment call: The CRA gives no bright-line test separating a runtime product from a product that merely embeds one; the technical descriptions control, and close calls deserve documented reasoning.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

The Class II route changes how you prove conformity, not the underlying duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to virtualisation software exactly as to any product.

What you must do

  • Design, develop, and produce the software in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class II conformity assessment: modules B and C, module H, or a European cybersecurity certification scheme at assurance level at least "substantial". There is no internal-control option. Then affix the CE marking. (Art. 13(12), Art. 32(3), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Can I self-assess a hypervisor if I apply harmonised standards in full?

No. Applying harmonised standards unlocks self-assessment only for Class I. A hypervisor is Class II, and Article 32(3) offers no internal-control route: you must use modules B and C, module H, or an eligible European cybersecurity certification scheme. (Art. 32(3))

Is a container runtime treated the same as a hypervisor?

Item 1 lists both hypervisors and container runtime systems that support virtualised execution. A runtime whose core functionality is running isolated workloads falls in the same Class II category, subject to the technical descriptions that control the match. (Annex III Class II (1), Art. 7(4))

My application platform embeds a sandbox. Is the whole platform Class II?

Not automatically. Integrating a runtime does not in itself make the surrounding product a Class II important product. Whether the platform has the core functionality of item 1 is the judgment the technical descriptions exist to settle, and it deserves documented reasoning. (Art. 7(1), Art. 7(4))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class II conformity route through a notified body or certification, apply from 11 December 2027. (Art. 71(2))

Check where your software lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.