Annex III, Class I ยท Regulation (EU) 2024/2847

Is a SIEM system an important product under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (7), Art. 7(1))

Yes, most likely. The CRA lists "security information and event management (SIEM) systems" as important products (Annex III, Class I, item 7). A product whose core functionality is SIEM carries the full manufacturer obligations and a restricted conformity route: self-assessment stays available only where harmonised standards, common specifications, or eligible certification are applied in full. A general log analytics or search platform that is not built around security event correlation and alerting may sit outside the category, but that is a technical-description judgment.

Basis: Annex III Class I (7), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a product "has the core functionality of" a SIEM, as opposed to general log analytics, is a classification judgment the technical descriptions in Implementing Regulation (EU) 2025/2392 control.

Where the CRA puts SIEM Annex III Class I (7), Art. 7(1), Art. 7(2), Art. 7(4)

Item 7 of Class I names "security information and event management (SIEM) systems". The category exists for the reason Article 7(2) gives: products that primarily perform functions critical to the cybersecurity of other products, such as detecting threats across an estate, are treated as important because their compromise or failure degrades everyone relying on them.

A SIEM in the ordinary sense collects security-relevant events from many sources, normalises and correlates them, and raises alerts an analyst acts on. Where that is what your product is for, item 7 applies. As always, the binding scope is the technical description in the implementing act, not the marketing term.

Log analytics versus SIEM core functionality Art. 7(1), Art. 7(4)

The judgment here is the difference between a SIEM and a general-purpose log analytics or search platform. Many products ingest logs and let you query them, but a generic observability or business-analytics tool is not built around security event correlation, detection rules, and incident alerting the way a SIEM is.

Where security monitoring is the core functionality, the product is a SIEM for item 7. Where log search is a general capability used for operations, cost, or product analytics, the fit is weaker. The CRA does not draw this line in words, so resolve it against Implementing Regulation (EU) 2025/2392 and record how you reasoned, especially for a platform marketed across both uses.

Judgment call: The boundary between a SIEM and general log analytics is not fixed by the CRA text; the implementing act controls, and a dual-purpose platform is a documented close call.

What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII

For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. Plan for that lead time well before 11 December 2027.

Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to a SIEM as they do to any product in scope.

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Is a general log analytics platform a SIEM under the CRA?

Only where security event correlation, detection, and alerting is its core functionality. A general-purpose log search or observability tool used for operations or product analytics leans outside item 7, but a dual-purpose platform is a close call for the technical description to settle. (Art. 7(1), Art. 7(4))

We offer SIEM only as a managed service. Does the CRA apply?

The CRA covers products with digital elements placed on the market. A pure managed service with no installable component leans toward NIS2 rather than the CRA, but any agent, collector, or on-premises component you ship is a product in scope. Confirm on the facts of what you deliver. (Recital 12, Art. 3(1), Art. 3(2))

Can I still self-assess as a Class I product?

Only where you apply harmonised standards, common specifications, or an eligible European cybersecurity certification scheme at assurance level at least "substantial" in full. Otherwise a notified body route applies (modules B and C, or module H). (Art. 32(2))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.