Annex III, Class I ยท Regulation (EU) 2024/2847

Is a network management system an important product under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (6), Art. 7(1))

Yes, most likely. The CRA lists "network management systems" as important products (Annex III, Class I, item 6). A product whose core functionality is managing or controlling a network carries the full manufacturer obligations and a restricted conformity route: self-assessment stays available only where harmonised standards, common specifications, or eligible certification are applied in full. A passive monitoring or observability tool that only reads telemetry, without configuring or controlling the network, may sit outside the category, but that is a technical-description judgment.

Basis: Annex III Class I (6), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a product "has the core functionality of" a network management system, versus plain observability, is a classification judgment the technical descriptions in Implementing Regulation (EU) 2025/2392 control.

Why network management is on the list Annex III Class I (6), Art. 7(1), Art. 7(2), Art. 7(4)

Item 6 of Class I names "network management systems" without further wording, so the technical description in the implementing act does the defining. Article 7(2) explains the placement: it names network management directly as an example of a central system function that can carry a significant risk of adverse effects if compromised, precisely because it can control or disrupt a large number of other products.

That framing matters for interpretation. The category is aimed at software that exercises control over a network, network configuration managers, controllers, orchestration and provisioning platforms, rather than at every tool that merely touches a network.

Where the line to plain observability may sit Art. 7(1), Art. 7(4)

The judgment most teams face is the boundary between a network management system and an observability or monitoring tool. A platform that pushes configuration, changes routing, applies policy, or controls devices looks like network management. A dashboard that only ingests metrics, flows, and logs to show you what is happening, with no ability to change the network, is closer to plain observability.

The CRA text does not draw that line for you, and the label a vendor uses does not decide it. The technical description in Implementing Regulation (EU) 2025/2392 controls the match, so assess your product against it on the facts of what it actually does, and write down the reasoning behind a close call.

Judgment call: Whether a monitoring or observability product crosses into "network management" is unsettled on the CRA text alone; the implementing act controls, and the distinction turns on control versus observation.

What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII

For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. Plan for that lead time well before 11 December 2027.

Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to a network management system as they do to any product in scope.

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Is my monitoring dashboard a network management system?

Not necessarily. A tool that only reads telemetry to show network state, with no ability to change the network, leans toward observability rather than management. Where it configures or controls the network, it looks like item 6. The technical description in the implementing act decides the match. (Art. 7(1), Art. 7(4))

Why is network management treated as high-risk?

Article 7(2) names network management as a central system function that can disrupt or control a large number of other products if compromised, which is why the category sits in Class I with a stricter conformity route. (Art. 7(2))

Can I still self-assess as a Class I product?

Only where you apply harmonised standards, common specifications, or an eligible European cybersecurity certification scheme at assurance level at least "substantial" in full. Otherwise a notified body route applies (modules B and C, or module H). (Art. 32(2))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.