Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04

Critical products

Annex IV lists three categories: hardware devices with security boxes; smart meter gateways within smart metering systems and other devices for advanced security purposes, including for secure cryptoprocessing; and smartcards or similar devices, including secure elements. A product whose core function is one of these follows Art. 32(4).

The Annex wording

3 categories
PointCategory, as the Annex words itFunctions here
point 1Hardware Devices with Security BoxesHardware device with a security box (hardware security module)
point 2Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessingSmart meter gateway
Device for advanced security purposes, including secure cryptoprocessing
point 3Smartcards or similar devices, including secure elementsSmartcard or similar device
Secure element

The route this class asks for

Art. 32(4)

A European cybersecurity certification scheme where a delegated act under Art. 8(1) requires one; where Art. 8(1)'s conditions are not met, one of the Art. 32(3) procedures (EU-type examination or full quality assurance) (Art. 32(4)); internal control is not among them.

CRA Art. 8(1)Critical products and European cybersecurity certification

For products whose core functionality matches an Annex IV category, the Commission may require by delegated act a European cybersecurity certificate at assurance level at least substantial under a scheme adopted under Regulation (EU) 2019/881. Until such an act applies, a critical product must use one of the third-party routes of Article 32(3). The delegated act gives at least six months of transition.

What a notified body or authority asks to see: Determination whether the product falls in Annex IV; Tracking of delegated acts naming a required EUCC or other scheme and assurance level; Plan for certification or for the Article 32(3) route in the meantime
Where lists usually fall short: Critical product treated as class II with no watch on the certification delegated act
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 32(4)Conformity assessment for critical products

A critical product in Annex IV must show conformity through a European cybersecurity certification scheme required under Article 8(1), or, where those conditions are not met, through one of the Article 32(3) procedures.

What a notified body or authority asks to see: European cybersecurity certificate at the required assurance level, or third-party procedure record
Where lists usually fall short: Certification route assumed available before the delegated act applies
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer duties

For EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.

What a notified body or authority asks to see: Application to the notified body with the no-parallel-application declaration; EU-type examination certificate and additions; Records of modifications notified to the body
Where lists usually fall short: Type modified after certification without notifying the body
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted. A component with an Annex III function (a cellular or satellite module, a network interface, a secure microcontroller) may be important on its own; integrating it does not in itself make the product it sits in important (Art. 7(1)).