Classification method
Classification is a legal decision resting on technical facts. It must therefore be co-signed: engineering establishes the actual functionality, Legal settles the qualification.
The line of questioning, in order
Step 1 — Is the product a PDE?
See Scope. If not, classification stops there; a negative qualification sheet is still produced.
Step 2 — Is it excluded?
See Exclusions. If so, produce a reasoned exclusion sheet citing the applicable sectoral text.
Step 3 — What functionality does the product actually offer?
List the functions actually offered to the user, regardless of product name and marketing material. A function disabled by default but available remains a function offered.
Step 4 — Does it appear in Annex IV?
Hardware security box, smart meter gateway, secure cryptoprocessing device, smart card or secure element. If yes → Critical, stop.
Step 5 — Does it appear in Annex III, Part II?
Operating system, hypervisor, container runtime, firewall, IDS/IPS, tamper-resistant microprocessor or microcontroller. If yes → Important class II, stop.
Step 6 — Does it appear in Annex III, Part I?
The seventeen categories listed in Important class I. If yes → class I.
Step 7 — Otherwise
Default category. The sheet must demonstrate that Annexes III and IV were examined and each relevant category ruled out.
The four questions that settle borderline cases
- Tamper resistance. Does the component implement physical countermeasures against the extraction or modification of secrets — shielding, intrusion detection, encrypted memory, side-channel protection? This purely technical answer moves a microcontroller from class I to class II.
- Security-related functionality. Does the component perform a security function for the system embedding it — key generation, secret storage, access control, verified boot?
- Embedded browser. Does the product embed a web rendering engine exposed to untrusted remote content?
- Multi-function. Does the product span several categories? Then the highest class applies.
The classification sheet
A one-page document, filed with the technical documentation. It must contain:
| Field | Content |
|---|---|
| Product and versions covered | Traceable identification |
| Actual functionality | List, with the source (specification, code, documentation) |
| Annex IV | Categories examined, retained or ruled out, with reasons |
| Annex III Part II | Same |
| Annex III Part I | Same |
| Class retained | Default, I, II or Critical |
| Assessment route | Module A, B+C, H, or certification |
| Notified body | Where applicable, identity and contracting status |
| Assumptions and reservations | Points that would trigger reassessment |
| Date, signatories | Engineering and Legal |
The consolidated register
A single portfolio table, kept by Legal and reviewed at every committee: product, PDE status, any exclusion, class, assessment route, notified body, date of last classification, next review.
This register is the first document a market surveillance authority will ask for, and the first an acquirer will ask for in a transaction. Keeping it is not optional.
When to reclassify
- Addition or activation of a security function.
- Substantial modification within the meaning of Article 3.
- Update of Annexes III or IV by delegated act.
- Publication of Commission guidance clarifying the technical description of a category.
- At minimum, an annual review of the whole register.