Answer the questions and see the reasoning.
Identify the security function of the product
The Class II category covers firewalls and intrusion detection or prevention systems. The implementing description addresses the relevant traffic control and security monitoring functions. A hardware appliance and a software product can both require this analysis.
Distinguish a product built around these functions from an unrelated product that embeds them. A router with ancillary firewall capability does not automatically acquire the category of a dedicated firewall.
Understand Class II conformity options
Article 32(3) provides for B+C or H, with qualifying European cybersecurity certification subject to the specified legal conditions. Merely applying harmonised standards does not provide the same Module A route available under the Class I conditions.
Article 32(5) contains a specific option for Important products qualifying as FOSS when the technical documentation is public. A proprietary firewall that includes FOSS components does not automatically qualify for that exception.
Operational evidence and changes
Document intended deployment, policy behaviour, management interfaces, updates and vulnerability handling. The product category does not establish that your particular security configuration is adequate or that the product has passed assessment.
If you substantially change traffic-processing behaviour, intended purpose or compliance with essential cybersecurity requirements, revisit the assessment. Reselling an unchanged product and shipping a modified appliance can create different responsibilities.
Dates and next actions
Article 14 reporting for manufacturers applies from 11 September 2026, including to older in-scope products. Most requirements apply from 11 December 2027, subject to the rules for products already placed on the market and subsequent substantial modifications.
If you are the manufacturer of an in-scope product, establish the product risk assessment, support-period decision, vulnerability handling and technical documentation. Select the applicable conformity route before making a compliance claim. A reseller should use the importer and distributor assessment for its distinct duties.
Frequently asked questions
Does Class II mean the firewall is non-compliant?
No. Class II identifies the regulatory category and assessment requirements. It is not a security finding.
Can an open-source firewall self-assess?
The Article 32(5) exception may apply to qualifying Important FOSS products if the technical documentation is made public. Assess the actual product and conditions, not just whether some code is open source.