Where the CRA puts virtualisation software Annex III Class II (1), Art. 7(1), Art. 7(4)
Annex III splits important products into Class I and the higher Class II. Item 1 of Class II reads "Hypervisors and container runtime systems that support virtualised execution of operating systems and similar environments". A product with the core functionality of that category is a Class II important product and moves to the conformity assessment procedures of Article 32(3).
The Commission fixed the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392). That description, not the plain-language label, decides whether a given product matches item 1, so it governs edge cases such as lightweight runtimes or emulators.
Why Class II removes the self-assessment route Art. 7(2), Art. 32(3), Annex VIII
The CRA treats virtualisation as a central system function whose compromise can affect a large number of workloads at once, which is why it sits in the higher class. Unlike Class I, Class II gives no internal-control option: applying harmonised standards in full does not unlock self-assessment here.
Under Article 32(3), a Class II product must demonstrate conformity through EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". Two of the three routes require a notified body, so plan lead time and cost well before 11 December 2027.
Core functionality, not a virtualisation feature Art. 7(1), Art. 7(4)
Classification turns on core functionality. A hypervisor or a container runtime whose reason for existing is running isolated workloads has the core functionality of item 1. A broader product that merely embeds a runtime as a supporting component is a different question, and Article 7(1) says integration alone does not pull the surrounding product into the Class II procedures.
Where the line is genuinely close, for example an application platform that ships an embedded sandbox, resolve it against Implementing Regulation (EU) 2025/2392 and record your reasoning. The classification decides whether a notified body is unavoidable, so it deserves care rather than a guess from the label.
Judgment call: The CRA gives no bright-line test separating a runtime product from a product that merely embeds one; the technical descriptions control, and close calls deserve documented reasoning.
The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
The Class II route changes how you prove conformity, not the underlying duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to virtualisation software exactly as to any product.