Annex III, Class I ยท Regulation (EU) 2024/2847

Are smart locks, cameras, and alarms important products under the CRA?

Verified against the Official Journal text on

Important product, Class I (Annex III Class I (17), Art. 7(1))

Yes, most likely. Smart home products with security functionalities are a listed category of important products under the EU Cyber Resilience Act (Annex III, Class I, item 17), and the regulation names smart door locks, security cameras, baby monitoring systems, and alarm systems as examples. A product whose core functionality matches carries the full manufacturer obligations, and self-assessment under internal control stays available only where harmonised standards, common specifications, or an eligible European cybersecurity certification scheme are applied in full. The classifier here is the security function, not the "smart home" label alone.

Basis: Annex III Class I (17), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a device has the core functionality of a smart home product with security functionalities is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

What item 17 covers Annex III Class I (17), Art. 7(1), Art. 7(4)

Annex III Class I item 17 reads "Smart home products with security functionalities, including smart door locks, security cameras, baby monitoring systems and alarm systems". The named devices are examples of the category, not an exhaustive list, so a smart home product built around a security function can fall in item 17 even if it is not one of the four named types.

A product with digital elements that has the core functionality of this category is an important product and moves to the stricter conformity assessment procedures of Article 32(2). The Commission set the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392), and that description decides the match.

The security function is what classifies Annex III Class I (16)-(17), Art. 7(1)

The words "with security functionalities" do the classifying work. A smart home device whose core role is protecting the home, controlling physical access, or monitoring for intrusion or safety, has the core functionality of item 17. A general convenience gadget with no security role sits outside this category, though it may still be in CRA scope as a default-category product.

Distinguish item 17 from item 16 (general purpose virtual assistants). A voice hub is item 16; a connected door lock or alarm panel is item 17. A single product can raise both questions, so map its core functionality carefully and resolve close calls against Implementing Regulation (EU) 2025/2392 with documented reasoning.

Judgment call: The CRA does not define how much of a device must be a "security functionality" to fall in item 17; the technical descriptions control, and borderline devices deserve documented reasoning.

What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII

A default-category product can be self-assessed under internal control (module A). For a Class I important product that option narrows: internal control is available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.

Where you do not, or where no such standard exists for a requirement, the route is EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H) via a notified body. Security devices that gate physical access or capture household video should plan that lead time well before 11 December 2027.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Class I status changes the conformity route, not the substance. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to a smart lock or camera exactly as to any product in scope.

What you must do

  • Design, develop, and produce the device in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. Then affix the CE marking. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

My smart home device is not a lock, camera, monitor, or alarm. Is it still item 17?

Possibly. The four named devices are examples, and the category is smart home products with security functionalities generally. If your device is built around a security function, it can fall in item 17; the technical descriptions settle the match. (Annex III Class I (17), Art. 7(4))

Is a smart lightbulb or thermostat a Class I product?

Not through item 17, which targets security functionalities. A convenience device with no security role is generally a default-category product rather than an important one, though it is still a product with digital elements in CRA scope. (Annex III Class I (17), Art. 32(1))

The camera streams to our cloud. Does that come into scope too?

A backend you develop, without which a product function would not work, is in scope with the device as a remote data processing solution. Map which parts of the service you are responsible for, since a third-party backend outside your responsibility is treated differently. (Art. 3(2), Recital 11)

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your device lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.