On this page
- Class follows the product’s core functionality, not its technology stack or worst-case fears.
- Products outside Annexes III and IV can use internal control; this still requires a supported conformity assessment.
- Important Class I, Class II and critical products have different route conditions.
- Record the reasoning: reviewers, notified bodies, and your own next release all need it.
Class follows core functionality
The regulation sorts products by what they do, not by how they are built. Read the category definitions against the product’s intended purpose and reasonably foreseeable use: a line-of-business web app and a privileged-access-management tool are both software, but they do not sit in the same box.
Work through the categories feature by feature, and write down why each does or does not apply. Where a category plausibly matches part of the product, record that judgement instead of burying it. When the answer is genuinely unclear, that is a decision to budget specialist advice for - not one to guess in silence.
Articles 7 and 8 and Annexes III and IV establish the categories. Integrating an important component does not by itself place the whole product in that category. Check applicable category definitions and current implementing measures against the final product, not just a dependency list.
What the class changes
Under Article 32, products outside the important and critical categories can use internal control. Important Class I can retain that route when the relevant harmonised standards, common specifications or qualifying certification cover the requirements as required by Article 32(2). Otherwise the relevant requirements need EU-type examination plus conformity to type, or full quality assurance. Class II has the separate routes in Article 32(3); applying standards alone does not make it eligible for internal control.
The practical consequence is cost and calendar, not just paperwork: notified-body involvement adds lead time you cannot compress by shipping faster. Knowing the class early keeps the release plan honest.
For critical products, Article 8 provides for mandatory European cybersecurity certification where the relevant delegated act applies. Without that act, the Class II procedures apply. Record the instrument and route evidence instead of assuming one universal notified-body process.
Propose, then decide
Tools can propose a class from the product’s facts - ConformOps does exactly that, from the answers you give about what the product is and does. The decision itself stays with the manufacturer: a named person confirms the classification, and the confirmation is recorded against the assessment it was made on.
Frequently asked questions
Is software sold as a service covered?
A SaaS label does not settle scope. Standalone services and software products must be distinguished, and a product can include remote data processing needed for one of its functions. Assess distributed clients, agents and their associated backend against Articles 2 and 3.
Who decides the final class?
The manufacturer is accountable. Automated proposals and checklists help structure the reasoning, but a named person must confirm the classification and own the consequences.
Can the class change after launch?
Yes. A substantial modification - new functionality, changed attack surface, altered purpose - can move a product into a higher category and a stricter route. Re-check classification when the product materially changes.