How item 19 is worded Annex III Class I (19), Art. 7(1), Art. 7(4)
Annex III Class I item 19 covers "Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children". There are two limbs: a health-monitoring limb with a medical-device carve-out, and a children limb with no such carve-out.
A product with the core functionality of this category is an important product and moves to the stricter conformity assessment procedures of Article 32(2). The Commission set the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392), which decides the match.
Where the medical device rules take over Art. 2(2)(a), Art. 2(2)(b), Annex III Class I (19)
The health-monitoring limb of item 19 explicitly stops where MDR (EU) 2017/745 or IVDR (EU) 2017/746 applies. This lines up with the CRA scope exclusion: products with digital elements to which the MDR or IVDR applies are excluded from the CRA, and their cybersecurity obligations live in those regimes instead. A regulated medical wearable is therefore out of CRA scope, not merely out of Class I.
Because of that, the first question for a health wearable is its medical device status, not its CRA class. If MDR or IVDR classification is itself uncertain, resolve that before applying the CRA, since the exclusion only bites where those rules actually apply. A children wearable, by contrast, falls in item 19 without any medical device carve-out.
Judgment call: Whether a wearable is a regulated medical device under MDR or IVDR is frequently a hard call in its own right; that determination, not the CRA, controls whether the product is excluded.
When a wearable is a Class I important product Art. 32(1), Art. 32(2), Annex VIII
A health-monitoring wearable that is not a regulated medical device, or a wearable intended for use by and for children, is a Class I important product. For it, internal control (module A) stays available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial" in full.
Where you do not, or where no such standard exists for a requirement, the route is EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H) via a notified body. Wearables that collect body or location data from children warrant early planning for that route ahead of 11 December 2027.
The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
Where a wearable is in CRA scope, the substance of the duties is the same as for any product: essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents.