How broad the category is Annex III Class I (11), Art. 7(1), Art. 7(4)
Item 11 of Class I names "operating systems" without qualification, so the technical description in the implementing act does the defining. On the ordinary meaning the category reaches desktop and server operating systems, mobile operating systems, embedded operating systems, and real-time operating systems (RTOS) shipped in devices.
A commercial Linux distribution is an operating system product for these purposes where you place it on the market in the course of a commercial activity, for example a paid or supported enterprise distribution. Being built on open-source components does not remove it from the category; what it may change is the applicable relief, covered below.
Free and open-source operating systems Art. 3(22), Recital 18, Art. 32(5)
Two distinct reliefs can matter for an open-source operating system. First, free and open-source software supplied outside a commercial activity is not "made available on the market" at all, so the CRA does not bite; paid editions, paid support or hosting, or dual licensing change that. See our open-source software guide for how that line is drawn.
Second, where an open-source operating system is in scope, Article 32(5) lets its manufacturer use the ordinary Article 32(1) procedures, including internal control, despite the Class I listing, provided the technical documentation is made available to the public when the product is placed on the market. That relief is specific to free and open-source Annex III products.
What Class I changes: your conformity route Art. 32(1), Art. 32(2), Art. 32(5), Annex VIII
For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.
Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body, unless the Article 32(5) open-source relief applies. Plan for that lead time well before 11 December 2027.
Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to an operating system as they do to any product in scope. For an operating system, secure defaults and a working update mechanism are central.