Annex III, Class I ยท Regulation (EU) 2024/2847

Are health and childrens wearables important products under the CRA?

Verified against the Official Journal text on

Important product, Class I (unless MDR/IVDR applies) (Annex III Class I (19), Art. 2(2)(a)-(b))

Often yes, unless the medical device rules apply. Personal wearables with a health monitoring purpose are important products under the EU Cyber Resilience Act (Annex III, Class I, item 19), as are wearables intended for use by and for children. But item 19 carves out wearables to which the Medical Device Regulation (EU) 2017/745 or the IVDR (EU) 2017/746 applies, and any product to which those regimes apply is excluded from the CRA entirely. So a health wearable that is a regulated medical device is out of CRA scope; one that is not is a Class I important product.

Basis: Annex III Class I (19), Art. 2(2)(a)-(b), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether MDR or IVDR applies to a given wearable is the pivot, and it can be a hard classification question. Resolve the medical device status first, since the CRA exclusion only bites where those rules actually apply.

How item 19 is worded Annex III Class I (19), Art. 7(1), Art. 7(4)

Annex III Class I item 19 covers "Personal wearable products to be worn or placed on a human body that have a health monitoring (such as tracking) purpose and to which Regulation (EU) 2017/745 or (EU) No 2017/746 do not apply, or personal wearable products that are intended for the use by and for children". There are two limbs: a health-monitoring limb with a medical-device carve-out, and a children limb with no such carve-out.

A product with the core functionality of this category is an important product and moves to the stricter conformity assessment procedures of Article 32(2). The Commission set the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392), which decides the match.

Where the medical device rules take over Art. 2(2)(a), Art. 2(2)(b), Annex III Class I (19)

The health-monitoring limb of item 19 explicitly stops where MDR (EU) 2017/745 or IVDR (EU) 2017/746 applies. This lines up with the CRA scope exclusion: products with digital elements to which the MDR or IVDR applies are excluded from the CRA, and their cybersecurity obligations live in those regimes instead. A regulated medical wearable is therefore out of CRA scope, not merely out of Class I.

Because of that, the first question for a health wearable is its medical device status, not its CRA class. If MDR or IVDR classification is itself uncertain, resolve that before applying the CRA, since the exclusion only bites where those rules actually apply. A children wearable, by contrast, falls in item 19 without any medical device carve-out.

Judgment call: Whether a wearable is a regulated medical device under MDR or IVDR is frequently a hard call in its own right; that determination, not the CRA, controls whether the product is excluded.

When a wearable is a Class I important product Art. 32(1), Art. 32(2), Annex VIII

A health-monitoring wearable that is not a regulated medical device, or a wearable intended for use by and for children, is a Class I important product. For it, internal control (module A) stays available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial" in full.

Where you do not, or where no such standard exists for a requirement, the route is EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H) via a notified body. Wearables that collect body or location data from children warrant early planning for that route ahead of 11 December 2027.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

Where a wearable is in CRA scope, the substance of the duties is the same as for any product: essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents.

What you must do

  • Design, develop, and produce the wearable in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and, where the wearable is in scope, carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

My fitness band tracks heart rate. Is it in CRA scope or medical device scope?

It turns on whether MDR (EU) 2017/745 applies. If your band is a regulated medical device, it is excluded from the CRA and its cybersecurity duties live in the MDR. If it is a general health monitor outside the MDR, it is a Class I important product under item 19. (Art. 2(2)(a), Annex III Class I (19))

Is a smartwatch made for children a Class I product?

Yes, on the face of item 19. Wearables intended for use by and for children fall in the category without any medical device carve-out, so a childrens wearable that is a product with digital elements on the EU market is a Class I important product. (Annex III Class I (19))

The MDR classification of my wearable is unclear. What do I do first?

Resolve the medical device status first. The CRA exclusion only applies where the MDR or IVDR actually applies, so an uncertain medical classification has to be settled before you can conclude whether the product is in or out of CRA scope. (Art. 2(2)(a), Art. 2(2)(b))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including any Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your wearable lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.