Critical products
Annex IV lists three categories: hardware devices with security boxes; smart meter gateways within smart metering systems and other devices for advanced security purposes, including for secure cryptoprocessing; and smartcards or similar devices, including secure elements. A product whose core function is one of these follows Art. 32(4).
The Annex wording
3 categories| Point | Category, as the Annex words it | Functions here |
|---|---|---|
| point 1 | Hardware Devices with Security Boxes | Hardware device with a security box (hardware security module) |
| point 2 | Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 of the European Parliament and of the Council and other devices for advanced security purposes, including for secure cryptoprocessing | Smart meter gateway Device for advanced security purposes, including secure cryptoprocessing |
| point 3 | Smartcards or similar devices, including secure elements | Smartcard or similar device Secure element |
The route this class asks for
Art. 32(4)A European cybersecurity certification scheme where a delegated act under Art. 8(1) requires one; where Art. 8(1)'s conditions are not met, one of the Art. 32(3) procedures (EU-type examination or full quality assurance) (Art. 32(4)); internal control is not among them.
CRA Art. 8(1)Critical products and European cybersecurity certificationFor products whose core functionality matches an Annex IV category, the Commission may require by delegated act a European cybersecurity certificate at assurance level at least substantial under a scheme adopted under Regulation (EU) 2019/881. Until such an act applies, a critical product must use one of the third-party routes of Article 32(3). The delegated act gives at least six months of transition.
CRA Art. 32(4)Conformity assessment for critical productsA critical product in Annex IV must show conformity through a European cybersecurity certification scheme required under Article 8(1), or, where those conditions are not met, through one of the Article 32(3) procedures.
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer dutiesFor EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.
By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted. A component with an Annex III function (a cellular or satellite module, a network interface, a secure microcontroller) may be important on its own; integrating it does not in itself make the product it sits in important (Art. 7(1)).