How the CRA describes VPNs Annex III Class I (5), Art. 7(1), Art. 7(2), Art. 7(4)
Item 5 of Class I reads "products with digital elements with the function of virtual private network (VPN)". A consumer VPN app, a corporate VPN client, a VPN concentrator or gateway appliance, and the firmware in a VPN box all sit inside the category where providing the VPN is what the product is for.
It lands in Class I for the reason Article 7(2) gives: products that primarily perform functions critical to the cybersecurity of other products, such as network protection, are treated as important. The plain label is only the starting point; the binding scope is the technical description in the implementing act.
A VPN product versus a product with a VPN feature Art. 7(1), Art. 7(4)
The recurring question is the difference between a VPN product and a product that happens to include VPN connectivity. A router that offers a VPN passthrough, an operating system with a built-in VPN client, or an enterprise suite with a VPN module raises the question of whether the VPN is its core functionality or one feature among many.
Article 7(1) settles the general principle: integrating a component with the core functionality of a listed category does not, in itself, make the surrounding product one of those categories. So a router stays a router, judged on its own listing, and a dedicated VPN client is a VPN product. Resolve close calls against Implementing Regulation (EU) 2025/2392 and keep a record.
Judgment call: Whether a product "has the function of a VPN" as its core purpose or merely includes VPN connectivity has no bright-line rule in the CRA; the implementing act controls the match.
What Class I changes: your conformity route Art. 32(1), Art. 32(2), Annex VIII
For a default-category product a manufacturer may self-assess under internal control (module A). For a Class I important product that choice narrows: internal control remains available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial", in full, to the relevant essential requirements.
Where you do not, or where no such standard yet exists, the product must go through EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H), both involving a notified body. Plan for that lead time well before 11 December 2027.
Everything else is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
Class I status changes the conformity route, not the substance. The essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and the reporting duties for actively exploited vulnerabilities and severe incidents apply to a VPN product as they do to any product in scope.