Classification method

Classification is a legal decision resting on technical facts. It must therefore be co-signed: engineering establishes the actual functionality, Legal settles the qualification.

The line of questioning, in order

Step 1 — Is the product a PDE?

See Scope. If not, classification stops there; a negative qualification sheet is still produced.

Step 2 — Is it excluded?

See Exclusions. If so, produce a reasoned exclusion sheet citing the applicable sectoral text.

Step 3 — What functionality does the product actually offer?

List the functions actually offered to the user, regardless of product name and marketing material. A function disabled by default but available remains a function offered.

Step 4 — Does it appear in Annex IV?

Hardware security box, smart meter gateway, secure cryptoprocessing device, smart card or secure element. If yes → Critical, stop.

Step 5 — Does it appear in Annex III, Part II?

Operating system, hypervisor, container runtime, firewall, IDS/IPS, tamper-resistant microprocessor or microcontroller. If yes → Important class II, stop.

Step 6 — Does it appear in Annex III, Part I?

The seventeen categories listed in Important class I. If yes → class I.

Step 7 — Otherwise

Default category. The sheet must demonstrate that Annexes III and IV were examined and each relevant category ruled out.

The four questions that settle borderline cases

  1. Tamper resistance. Does the component implement physical countermeasures against the extraction or modification of secrets — shielding, intrusion detection, encrypted memory, side-channel protection? This purely technical answer moves a microcontroller from class I to class II.
  2. Security-related functionality. Does the component perform a security function for the system embedding it — key generation, secret storage, access control, verified boot?
  3. Embedded browser. Does the product embed a web rendering engine exposed to untrusted remote content?
  4. Multi-function. Does the product span several categories? Then the highest class applies.

The classification sheet

A one-page document, filed with the technical documentation. It must contain:

Field Content
Product and versions covered Traceable identification
Actual functionality List, with the source (specification, code, documentation)
Annex IV Categories examined, retained or ruled out, with reasons
Annex III Part II Same
Annex III Part I Same
Class retained Default, I, II or Critical
Assessment route Module A, B+C, H, or certification
Notified body Where applicable, identity and contracting status
Assumptions and reservations Points that would trigger reassessment
Date, signatories Engineering and Legal

The consolidated register

A single portfolio table, kept by Legal and reviewed at every committee: product, PDE status, any exclusion, class, assessment route, notified body, date of last classification, next review.

This register is the first document a market surveillance authority will ask for, and the first an acquirer will ask for in a transaction. Keeping it is not optional.

When to reclassify

  • Addition or activation of a security function.
  • Substantial modification within the meaning of Article 3.
  • Update of Annexes III or IV by delegated act.
  • Publication of Commission guidance clarifying the technical description of a category.
  • At minimum, an annual review of the whole register.