CRA Risk Classifier
Determine your product's classification under the Cyber Resilience Act. Understand whether your product falls under Default, Important (Class I or II), or Critical categories and the specific conformity assessment requirements for each.
Your Classification is Confidential
This assessment runs entirely in your browser. No data is sent to our servers or stored externally. Your product information remains completely private and secure.
CRA Risk Classification
Default Category
Products with minimal cybersecurity risks that pose no significant threat to users or infrastructure.
- Self-assessment allowed
- Basic security requirements
- Standard documentation
Important Products (Annex III)
Products listed in Annex III, split into Class I and Class II with different conformity assessment requirements.
- Class I: self-assessment if harmonised standards applied
- Class II: always requires third-party assessment
- Enhanced security testing and documentation
Critical Products (Annex IV)
Products critical for health, safety, or essential services. Highest security requirements.
- Mandatory conformity assessment
- Comprehensive security evaluation
- Ongoing monitoring required
Why Risk Classification Matters
Compliance Requirements
Different risk levels have different requirements for security testing, documentation, and third-party assessment. Knowing your classification helps you understand exactly what you need to do.
Cost Planning
Higher risk classifications require more extensive testing and documentation. Early classification helps you budget for compliance costs and timeline planning.
Need Help with CRA Compliance?
Our experts can help you navigate the complex requirements for each risk classification and ensure full CRA compliance.