Annex III, Class I ยท Regulation (EU) 2024/2847

Is a smart home virtual assistant an important product under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (16), Art. 7(1))

Yes, most likely. Smart home general purpose virtual assistants are a listed category of important products under the EU Cyber Resilience Act (Annex III, Class I, item 16). A device or software whose core functionality is a general purpose home assistant carries the full manufacturer obligations, and self-assessment under internal control stays available only where harmonised standards, common specifications, or an eligible European cybersecurity certification scheme are applied in full. The listing turns on the "general purpose" assistant role, not on any single feature such as voice input.

Basis: Annex III Class I (16), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a product has the core functionality of a general purpose virtual assistant is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

Where the CRA places smart home assistants Annex III Class I (16), Art. 7(1), Art. 7(4)

Annex III lists the categories the CRA treats as "important products with digital elements". Item 16 of Class I names "smart home general purpose virtual assistants" directly. A product with digital elements that has the core functionality of that category is an important product and moves to the stricter conformity assessment procedures of Article 32(2).

The Commission fixed the technical description of each category in an implementing act, as Article 7(4) required by 11 December 2025 (Implementing Regulation (EU) 2025/2392). That description, not the marketing label, decides whether your assistant matches item 16, so the word "general purpose" carries real weight in a close call.

General purpose assistant versus a single-task voice feature Art. 7(1), Art. 7(4)

Classification turns on core functionality. A hub or app whose central role is acting as a general purpose assistant across many home tasks, taking open-ended requests and orchestrating other devices, has the core functionality of item 16. A narrow, single-task voice trigger baked into one appliance is a different question.

Article 7(1) is explicit that integrating an assistant component into a broader product does not in itself make that product important. A smart speaker whose assistant is its reason for existing is squarely in the category; a thermostat that merely accepts a voice command is the kind of close call the technical descriptions exist to settle. Document your reasoning either way.

Judgment call: The line between a "general purpose" assistant and a narrow voice feature is not drawn in the CRA text itself; the technical descriptions control, and borderline products deserve documented reasoning.

What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII

A default-category product can be self-assessed under internal control (module A). For a Class I important product that option narrows: internal control is available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where no such standard exists for a requirement, the route is EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H) via a notified body. For a consumer device that also processes voice and household data, plan that lead time well before 11 December 2027.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance of the duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to a home assistant exactly as to any product in scope.

What you must do

  • Design, develop, and produce the assistant in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Is the assistant software in scope even if the hardware is made by someone else?

Software with digital elements is a product in its own right. If the assistant application has the core functionality of a general purpose virtual assistant, its maker carries the manufacturer obligations, independently of who builds the speaker or hub it runs on. (Annex III Class I (16), Art. 3(1))

Does a single voice command in my appliance make it a Class I assistant?

Not on its own. Item 16 targets general purpose assistants, and integrating a narrow voice feature into a broader product does not in itself make it important. Whether your product crosses that line is settled by the technical descriptions, not the presence of voice input. (Art. 7(1), Art. 7(4))

The assistant relies on our cloud backend. Is that in scope too?

A backend you develop, without which a product function would not work, is in scope with the product as a remote data processing solution. A third-party service outside your responsibility is treated differently, so map which parts you are responsible for. (Art. 3(2), Recital 11)

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.