A product whose core functionality matches the firewall, intrusion detection or intrusion prevention description is likely Important Class II. It generally requires third-party assessment, subject to the CRA’s specific conditions and exceptions.
Apply this to your product

Answer the questions and see the reasoning.

Open product classification

Identify the security function of the product

The Class II category covers firewalls and intrusion detection or prevention systems. The implementing description addresses the relevant traffic control and security monitoring functions. A hardware appliance and a software product can both require this analysis.

Distinguish a product built around these functions from an unrelated product that embeds them. A router with ancillary firewall capability does not automatically acquire the category of a dedicated firewall.

Annex III, Class II, point 2; Regulation 2025/2392, Annex ICRA text Implementing Regulation (EU) 2025/2392

Understand Class II conformity options

Article 32(3) provides for B+C or H, with qualifying European cybersecurity certification subject to the specified legal conditions. Merely applying harmonised standards does not provide the same Module A route available under the Class I conditions.

Article 32(5) contains a specific option for Important products qualifying as FOSS when the technical documentation is public. A proprietary firewall that includes FOSS components does not automatically qualify for that exception.

Article 32(3) and (5); Annex VIIICRA text

Operational evidence and changes

Document intended deployment, policy behaviour, management interfaces, updates and vulnerability handling. The product category does not establish that your particular security configuration is adequate or that the product has passed assessment.

If you substantially change traffic-processing behaviour, intended purpose or compliance with essential cybersecurity requirements, revisit the assessment. Reselling an unchanged product and shipping a modified appliance can create different responsibilities.

Articles 3(30), 13 and 19–22; guidance section 4CRA text Commission guidance

Dates and next actions

Article 14 reporting for manufacturers applies from 11 September 2026, including to older in-scope products. Most requirements apply from 11 December 2027, subject to the rules for products already placed on the market and subsequent substantial modifications.

If you are the manufacturer of an in-scope product, establish the product risk assessment, support-period decision, vulnerability handling and technical documentation. Select the applicable conformity route before making a compliance claim. A reseller should use the importer and distributor assessment for its distinct duties.

Articles 13, 14, 19–20, 32, 69 and 71CRA text ↗

Frequently asked questions

Does Class II mean the firewall is non-compliant?

No. Class II identifies the regulatory category and assessment requirements. It is not a security finding.

Can an open-source firewall self-assess?

The Article 32(5) exception may apply to qualifying Important FOSS products if the technical documentation is made public. Assess the actual product and conditions, not just whether some code is open source.

This guide supports an initial assessment. Your result depends on the product facts and the applicable measures. Read how to use this guidance.