EU Cyber Resilience Act

CRA compliance for networking products

Networking products such as routers and firewalls are products with digital elements and are in scope for the Cyber Resilience Act. Some network-defence products are classified as important, which raises the bar.

Several core networking functions are named directly in Annex III

This is one of the few sectors where the CRA names specific product functions rather than leaving classification to interpretation. Annex III, Class I lists routers and modems intended for internet connection, switches, physical and virtual network interfaces, and network management systems as important products. Firewalls and intrusion detection/prevention systems go further — they're Class II, the stricter of the two important tiers.

What Class I vs Class II actually changes

A Class I router or switch can still self-assess (internal control) if you fully apply the relevant harmonised standards; if you haven't, or none exist yet, you move to third-party assessment. A Class II product — a firewall or IDS/IPS — always needs third-party assessment, regardless of which standards you've applied. See our guide on notified bodies for the full breakdown.

Secure defaults and authenticated update channels

Two Annex I properties tend to matter most for networking gear specifically: secure-by-default configuration (Annex I, Part I, (2)(b)) — because a networking device with a well-known default credential is a disproportionately common attack vector — and a secure, authenticated update-distribution channel (Part I, (2)(c) and Part II, (7)), since a compromised firmware-update path on network infrastructure can affect everything behind it.

What to focus on

  • Routers, switches, network interfaces and management systems are named directly in Annex III, Class I.
  • Firewalls and IDS/IPS are Class II — always third-party assessed.
  • Harden default credentials and configuration before shipping.
  • Distribute updates over an authenticated channel — it's your highest-value attack surface.

Frequently asked questions

Are routers and firewalls in scope for the CRA?
Yes — they are products with digital elements. Some network-security products are classified as important, which changes the conformity route.
Is my home router different from an enterprise router under the CRA?
The Annex III listing covers routers and modems intended for internet connection generally, without a consumer/enterprise distinction — classify based on function, not market segment.

General information about the EU Cyber Resilience Act — not legal advice. Normproof provides tooling and audit-ready evidence; the manufacturer self-declares conformity. For your specific product, run the free readiness check or consult a qualified advisor.

See what the CRA requires for your networking products.

Run the free readiness check — your category, obligations, and deadlines in 60 seconds.