Hardware device with a security box (hardware security module)
By the Annex wording, a hardware device with a security box (hardware security module) points to the critical class (Annex IV, point 1). The route that class asks for: a European cybersecurity certification scheme where a delegated act under Art. 8(1) requires one; where Art. 8(1)'s conditions are not met, one of the Art. 32(3) procedures (EU-type examination or full quality assurance) (Art. 32(4)); internal control is not among them.
The Annex wording
Annex IV, point 1Hardware Devices with Security Boxes
Cited to the held text of Regulation (EU) 2024/2847. By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted.
A line that places here
exampleHSM-mini | hardware security module | EU | businesses | notified body
What the finder reads on these lines
8 of the 14 notes- 1. Declared function points to a critical product, and the route planned is not one Art. 32(4) sets: Which Art. 32(4) procedure will this product go through, and which notified body or scheme is it planned with?
- 4. No process to report an actively exploited vulnerability or a severe incident: Who notifies the CSIRT and ENISA within 24 hours when this product carries an actively exploited vulnerability, and where is the process written down?
- 5. No support period stated, or under five years with no reason recorded: What is the support period, how was it set, and where is its end date shown to buyers?
- 7. No published vulnerability contact: Where does a researcher report a vulnerability in this product, and is that address published?
- 8. No security update mechanism, or unsigned updates: How does a security fix reach units already sold, and how does the device check the update is genuine?
- 9. No software bill of materials kept, or partial: Where is the machine-readable SBOM for this product, and does it cover at least the top-level dependencies?
- 11. Manufacturer outside the EU with no authorised representative: Will the company appoint an EU authorised representative, and if not, which importer holds the documentation for the market surveillance authorities?
- 12. Still on sale for 11 December 2027 with no conformity route planned: Which route will this product take, and by when, so units made available from 11 December 2027 carry the declaration?
Clauses
13 cited| Regime | Clause | Applies when |
|---|---|---|
| CRA | CRA Art. 8(1) Critical products and European cybersecurity certification | sold in the EU |
| CRA | CRA Art. 32(4) Conformity assessment for critical products | sold in the EU |
| CRA | CRA Annex VIII Part II Module B: EU-type examination application and manufacturer duties | sold in the EU |
| CRA | CRA Art. 13(1) Design, development and production to Annex I Part I | sold in the EU |
| CRA | CRA Annex I Part I(1) Appropriate level of cybersecurity based on the risks | sold in the EU |
| UK PSTI | UK PSTI R.1 No universal default passwords | sold to UK consumers |
| UK PSTI | UK PSTI R.2 Published point of contact for security issues | sold to UK consumers |
| UK PSTI | UK PSTI R.3 Published defined support period | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.1 (provision group) No universal default passwords | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilities | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.3 (provision group) Keep software updated | sold to UK consumers |
| California | California 1798.91.04(a) Reasonable security feature or features | sold in California, as the manufacturer |
| California | California 1798.91.04(b) Authentication outside a local area network: unique password or forced new credential | sold in California, as the manufacturer |
The route clause, set out
CRA Art. 32(4)Conformity assessment for critical productsA critical product in Annex IV must show conformity through a European cybersecurity certification scheme required under Article 8(1), or, where those conditions are not met, through one of the Article 32(3) procedures.