Annex III, Class I ยท Regulation (EU) 2024/2847

Is a password manager an important product under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (3), Art. 7(1))

Yes, most likely. Password managers are a listed category of important products under the EU Cyber Resilience Act (Annex III, Class I, item 3). A product whose core functionality is that of a password manager carries the full manufacturer obligations, and its conformity assessment route is restricted: self-assessment stays available only where harmonised standards, common specifications, or an eligible European cybersecurity certification scheme are applied in full. Merely embedding password storage in a broader product does not in itself make that product an important product.

Basis: Annex III Class I (3), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a product "has the core functionality of" a password manager is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

Where the CRA puts password managers Annex III, Art. 7(1), Art. 7(4)

Annex III of the CRA lists the product categories the regulation treats as "important products with digital elements", split into Class I and Class II. "Password managers" appear by name in Class I, item 3. A product with digital elements that has the core functionality of a listed category is an important product and becomes subject to the stricter conformity assessment procedures of Article 32(2) and (3).

The Commission has specified the technical description of each category in an implementing act, as Article 7(4) required it to do by 11 December 2025 (Implementing Regulation (EU) 2025/2392). That description, not the plain-language label, decides whether your product matches the category.

The core functionality test Art. 7(1)

Classification turns on core functionality. A standalone password manager, or the password vault at the heart of a broader security suite, has the core functionality of the category. The reverse also holds: integrating a password manager into a product does not in itself make that product an important product. Article 7(1) says so explicitly for integrations.

The practical gray zone is a product that stores credentials as one feature among many, such as a browser with a built-in vault or a business app that remembers logins. Whether that crosses the line is exactly the judgment the technical descriptions exist to settle, so resolve it against Implementing Regulation (EU) 2025/2392 and record your reasoning.

Judgment call: The line between "core functionality" and "a feature" has no bright-line rule in the CRA itself; the technical descriptions control, and close calls deserve documented reasoning.

What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII

Manufacturers of default-category products choose their conformity assessment procedure freely, including plain self-assessment under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where such standards do not exist for the requirement in question, the product must go through EU-type examination followed by conformity to type (modules B and C), or full quality assurance (module H). Both involve a notified body, which means lead time and cost worth planning for well before 11 December 2027.

Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, the vulnerability handling duties including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to a password manager exactly as they do to any other product in scope.

Open-source password managers Art. 3(22), Recital 15, Recital 18, Art. 32(5)

Two distinct reliefs can matter here. First, free and open-source software supplied outside a commercial activity is not "made available on the market" at all, so the CRA does not bite; paid tiers, paid hosting, or dual licensing change that. Second, where an open-source password manager is in scope, Article 32(5) lets its manufacturer use the ordinary Article 32(1) procedures, including internal control, despite the Class I listing, provided the technical documentation is made available to the public when the product is placed on the market.

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

My app stores passwords as one feature. Is it a password manager under the CRA?

Only if storing and managing credentials is its core functionality. Integrating a vault into a broader product does not in itself make the product an important one, but a close call should be resolved against the technical descriptions in Implementing Regulation (EU) 2025/2392 and documented. (Art. 7(1), Art. 7(4))

Can I still self-assess as a Class I product?

Yes, but only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial" in full. Otherwise a notified body route applies (modules B and C, or module H). (Art. 32(2))

Does the CRA apply if my password manager is free?

Free of charge does not take you out of scope: making available on the market covers supply in the course of a commercial activity whether paid or free. Only free and open-source software supplied entirely outside a commercial activity stays out. (Art. 3(22), Recital 15)

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.