Annex III, Class I ยท Regulation (EU) 2024/2847

Is identity and access management software an important product under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (1), Art. 7(1))

Yes, most likely. The CRA lists "identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers" as important products (Annex III, Class I, item 1). This covers both software and hardware. A product whose core functionality is managing identities, privileged access, authentication, or access control carries the full manufacturer obligations and a restricted conformity route: self-assessment stays available only where harmonised standards, common specifications, or eligible certification are applied in full.

Basis: Annex III Class I (1), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether your product "has the core functionality of" this category is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

What the category covers Annex III Class I (1), Art. 7(1), Art. 7(2), Art. 7(4)

Item 1 of Class I is the broadest entry on the list. It names identity management systems and privileged access management (PAM) software and hardware, and it expressly reaches authentication and access control readers, including biometric readers. So an IdP, an SSO gateway, a directory service, a PAM vault, an MFA server, and the physical readers at a door can all fall inside it.

The reason it sits in Class I is spelled out in Article 7(2): products that primarily perform functions critical to the cybersecurity of other products, such as securing authentication and access, are treated as important. Identity is the classic example. The binding scope, though, is the technical description in the implementing act, not the label.

Software and hardware both count Annex III Class I (1), Art. 7(1)

This is one of the few Annex III entries that names hardware alongside software. A biometric reader, a smart-card door controller, or a hardware authentication token is squarely in view, and so is a pure-software IdP or PAM broker. If you make either, treat the Class I route as your default and confirm the match against the technical description.

A product that merely calls out to an external identity provider, without itself managing identities or access, is a different question. Consuming SSO is not the same as being an identity management system, and Article 7(1) makes clear that embedding such a component does not, on its own, reclassify the surrounding product.

Judgment call: Where a product both consumes and re-issues identity or access decisions, whether it "has the core functionality" of an IAM system is a close call the implementing act is meant to settle.

What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII

For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. For hardware readers in particular the lead time and testing cost are worth planning well before 11 December 2027.

Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to an IAM product exactly as they do to any product in scope.

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

My app just uses an external SSO provider. Is it an IAM product?

Consuming single sign-on does not make your product an identity management system. Only a product whose core functionality is managing identities, privileged access, or authentication falls in the category, and embedding such a component does not reclassify the surrounding product. (Art. 7(1))

Does a biometric reader count, or only software?

Both. Item 1 names authentication and access control readers, including biometric readers, alongside software. Hardware access control devices are within the Class I category, not outside it. (Annex III Class I (1))

Can I still self-assess as a Class I product?

Only where you apply harmonised standards, common specifications, or an eligible European cybersecurity certification scheme at assurance level at least "substantial" in full. Otherwise a notified body route applies (modules B and C, or module H). (Art. 32(2))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.