Annex III, Class I ยท Regulation (EU) 2024/2847

Are routers, modems, and switches important products under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (12), Art. 7(1))

Yes, most likely. Routers, modems intended for the connection to the internet, and switches are a listed category of important products under the EU Cyber Resilience Act (Annex III, Class I, item 12). A product whose core functionality is any of these carries the full manufacturer obligations, and self-assessment under internal control stays available only where harmonised standards, common specifications, or an eligible European cybersecurity certification scheme are applied in full. Read the wording carefully: the internet-connection qualifier appears to attach only to modems, while routers and switches are listed without any such limitation.

Basis: Annex III Class I (12), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a device has the core functionality of a router, an internet modem, or a switch is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

How the CRA words item 12 Annex III Class I (12), Art. 7(1), Art. 7(4)

Annex III lists the product categories the CRA treats as "important products with digital elements", split into Class I and Class II. Item 12 of Class I reads "Routers, modems intended for the connection to the internet, and switches". The qualifying phrase sits with modems, so a modem is in the category when it is intended for connecting to the internet, whereas routers and switches are named without a comparable restriction.

A product with digital elements that has the core functionality of a listed category is an important product and moves to the stricter conformity assessment procedures of Article 32(2). The Commission fixed the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392), and that description, not the label, decides the match.

Core functionality, not a networking feature Art. 7(1), Art. 7(4)

Classification turns on core functionality. A consumer or business router, a cable or fibre modem, or a managed Ethernet switch has the core functionality of the category. A device that merely includes routing or switching as a supporting feature, such as a server with a built-in NIC or an appliance that happens to bridge traffic, is a different question.

Article 7(1) is explicit that integrating a listed component into a broader product does not in itself pull that broader product into the Class I procedures. Where the line is genuinely close for a combined device, resolve it against Implementing Regulation (EU) 2025/2392 and record your reasoning rather than guessing from the plain-language label.

Judgment call: The CRA gives no bright-line test separating a router or switch from a device that merely forwards traffic; the technical descriptions control, and close calls deserve documented reasoning.

What Class I does to your conformity route Art. 32(1), Art. 32(2), Annex VIII

For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that option narrows: internal control remains open only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where no such standard exists for a given requirement, the device must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), each involving a notified body. For network hardware with long design cycles, that lead time is worth planning well before 11 December 2027.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance of the duties. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to networking hardware exactly as to any product in scope.

What you must do

  • Design, develop, and produce the device in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Is a home Wi-Fi router in scope even though it is a consumer product?

Yes. Consumer and business network hardware are both products with digital elements, and a router has the core functionality of Annex III Class I item 12. Being aimed at households does not remove the manufacturer obligations or the Class I conformity route. (Annex III Class I (12), Art. 7(1))

The list says "modems intended for the connection to the internet". Does that limit routers too?

Most likely not. The qualifier is worded around modems: routers and switches appear in item 12 without that restriction, so they look in-category regardless of whether their primary link is to the internet. This is a plain reading of the item, not settled law, so do not rely on the qualifier to exempt a device without checking the technical description in Implementing Regulation (EU) 2025/2392 and documenting the outcome. (Annex III Class I (12), Art. 7(4))

My product bundles a switch inside a larger appliance. Is the whole appliance Class I?

Not automatically. Integrating a switch into a broader product does not in itself make that product important. Whether the appliance itself has the core functionality of item 12 is the judgment the technical descriptions exist to settle. (Art. 7(1), Art. 7(4))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your hardware lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.