Physical and virtual, both named Annex III Class I (10), Art. 7(1), Art. 7(2), Art. 7(4)
Item 10 of Class I reads "physical and virtual network interfaces". The wording deliberately covers both sides: a physical network interface card or adapter you build into or supply for a device, and a virtual interface implemented in software, such as a virtualised or software-defined adapter presented to a guest operating system or workload.
It sits in Class I because the Annex III listing puts it there; Article 7(2) states the general criteria the listed categories meet (a cybersecurity-critical function, or a function with a significant risk of adverse effects) without attaching a rationale to each item. The binding scope is the technical description in the implementing act, so assess your product against that rather than the label.
When the interface is a component of a larger product Art. 7(1), Art. 3(1)
Network interfaces are frequently embedded: a NIC integrated on a motherboard, a virtual adapter built into a hypervisor, an interface baked into an appliance. Where you place a network interface on the market as a product with digital elements in its own right, item 10 applies to it directly.
Where the interface is only a component of a wider product, Article 7(1) is explicit that integrating a listed component does not, in itself, make the surrounding product an important product. The host device is assessed on its own listing. Confirm which case you are in against Implementing Regulation (EU) 2025/2392 and record the reasoning.
Judgment call: Whether a network interface is placed on the market as its own product or only integrated into another product turns on how you supply it; the implementing act settles the category match.
What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII
For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.
Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. For hardware interfaces the testing lead time is worth planning well before 11 December 2027.
Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to a network interface as they do to any product in scope. Firmware and driver update integrity matter here.