Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04

Default products

Most of what a maker of meters, trackers, sensors and gateways sells is not listed in Annex III or IV. The default class may use any Art. 32(1) procedure, including internal control; every other duty of the Act still applies.

Functions the finder reads as default

26

The route this class asks for

Art. 32(1)

Any Art. 32(1) procedure: internal control (module A), EU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme where available.

CRA Art. 32(1)Choosing a conformity assessment procedure (default products)

The manufacturer must assess the product and its processes against Annex I and demonstrate conformity by one of: internal control (module A), EU-type examination (module B) followed by conformity to type (module C), full quality assurance (module H), or, where available, a European cybersecurity certification scheme under Article 27(9).

What a notified body or authority asks to see: Conformity assessment plan naming the procedure; Completed module records
Where lists usually fall short: Procedure chosen without first confirming the product is not in Annex III or IV
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex VIII Part IModule A: internal control

Under internal control the manufacturer draws up the Annex VII technical documentation, takes all measures so that design, development, production and vulnerability handling and their monitoring ensure compliance with Annex I Parts I and II, affixes the CE marking to each conforming product, and draws up the declaration, keeping it with the technical documentation for ten years or the support period if longer. The authorised representative may handle marking and declaration under mandate.

What a notified body or authority asks to see: Internal control file: technical documentation, production and vulnerability handling monitoring records, declaration
Where lists usually fall short: Internal control treated as paperwork with no monitoring of processes
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted. A component with an Annex III function (a cellular or satellite module, a network interface, a secure microcontroller) may be important on its own; integrating it does not in itself make the product it sits in important (Art. 7(1)).