Commission Implementing Regulation (EU) 2025/2392, Technical Description of Important and Critical Products with Digital Elements
Regulation (EU) 2025/2392, Art. 2 and Annexes I and II
In force since .
A product security requirements rule binding public and private bodies.
- Obligation class
- DPIA, Security
As of .
What it requires
- This classification reaches you where you are a manufacturer placing on the EU market a product with digital elements whose core functionality meets a technical description in Annex I (important products, class I or class II) or Annex II (critical products), under Regulation (EU) 2024/2847.
- Decide by your product's core functionality, not by an incidental or integrated function, whether it meets a technical description: a product that performs additional functions can still have the core functionality of a category, and a product that can perform a category's functions but has a different core functionality does not meet that description (recitals 4 and 5).
- Where a component of your product meets a technical description, classify the product as a whole rather than treating the whole product as important or critical on that account, and still demonstrate that the whole product, including the integrated component, meets the essential cybersecurity requirements (Article 7(1) of Regulation (EU) 2024/2847 and recital 3).
- Demonstrate conformity of a product that meets a description in Annex I through the procedures of Article 32(2) and (3) of Regulation (EU) 2024/2847, and of a product that meets a description in Annex II through Article 32(4) of that Regulation.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Penalty structure
The classification in this Regulation selects the conformity assessment procedure that applies to a product under Article 32 of Regulation (EU) 2024/2847. Article 64(3) of that Regulation lists Article 32(1), (2) and (3) among the obligations whose non-compliance is subject to administrative fines of up to EUR 10,000,000 or, if the offender is an undertaking, up to 2 percent of its total worldwide annual turnover for the preceding financial year, whichever is higher. A fine for non-compliance with the essential cybersecurity requirements of Annex I to that Regulation is set separately by Article 64(2).
- Rule
- Higher of
- As of
- Currency
- EUR
- Fixed cap
- 10,000,000
- Turnover percentage cap
- 2
Who enforces it
Enforcement body
The market surveillance authority designated by each EU Member State under Article 52 of Regulation (EU) 2024/2847, with an administrative cooperation group (ADCO) established under Article 52(15) of that Regulation for its uniform application.
Settledness
- As of
What this law does
Article 2(1) provides that the technical description of the categories of products with digital elements under classes I and II listed in Annex III to Regulation (EU) 2024/2847 is as set out in Annex I to the Regulation. Article 2(2) provides that the technical description of the categories listed in Annex IV to Regulation (EU) 2024/2847 is as set out in Annex II to the Regulation.
The Commission adopted the Regulation under Article 7(4) of Regulation (EU) 2024/2847, which requires an implementing act by specifying those technical descriptions.
Regulation (EU) 2024/2847 uses the categories to decide the conformity assessment procedure: Article 7(1) makes a product whose core functionality is a category set out in Annex III an important product subject to the procedures referred to in Article 32(2) and (3).
Article 32(4) of that Regulation requires a critical product listed in Annex IV to demonstrate conformity by a European cybersecurity certification scheme under Article 8(1) or, where the conditions of Article 8(1) are not met, by a procedure of Article 32(3). Under Article 71(2), Regulation (EU) 2024/2847 applies from , with Article 14 applying from and Chapter IV from .
Annex I describes nineteen categories of important products in class I and four in class II, and Annex II describes three categories of critical products. The class I category of identity management systems and privileged access management software and hardware includes single sign-on software, federated identity management software, one-time password software and multi-factor authentication software.
The class I category of standalone and embedded browsers includes browsers with AI agent integration. Class I also lists password managers, software that searches for, removes or quarantines malicious software, products with the function of virtual private network (VPN), operating systems, and smart home general purpose virtual assistants.
Class II describes hypervisors and container runtime systems, firewalls and intrusion detection and prevention systems, tamper-resistant microprocessors and tamper-resistant microcontrollers. A tamper-resistant microprocessor or microcontroller in class II is designed to provide protection of AVA_VAN level 2 or 3, as set out in the Common Criteria and the Common Evaluation Methodology.
A secure element in Annex II is designed to provide protection of at least AVA_VAN.4, as set out in the Common Criteria or the Common Evaluation Methodology.
The recitals explain that integrating an embedded browser into a news app does not in itself make the news app subject to the conformity assessment procedure for browsers. The recitals explain that performing functions other than or additional to those in a technical description does not in itself mean a product lacks the core functionality of a category.
The recitals explain that a smartphone, whose core functionality is not that of an operating system or of a password manager, is generally not considered to meet the technical description of those categories. The recitals state that the examples they give are illustrative only and not an exhaustive list.
When LexLint raises it
When your app profile says your app distributes a software product or ships a mobile app.