Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04
default · product function

Industrial or IoT gateway

By the Annex wording, an industrial or IoT gateway points to the default class, not listed in Annex III or IV. The route that class asks for: any Art. 32(1) procedure: internal control (module A), EU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme where available.

Where the match turns

A gateway is not listed; one that also declares a firewall, VPN or intrusion prevention function raises the question whether that is its core function (Art. 7(1)).

A line that places here

example

IG-100 | industrial IoT gateway | EU, UK | businesses | self-assessment

Check this line

What the finder reads on these lines

10 of the 14 notes

Clauses

12 cited
RegimeClauseApplies when
CRACRA Art. 32(1) Choosing a conformity assessment procedure (default products)sold in the EU
CRACRA Annex VIII Part I Module A: internal controlsold in the EU
CRACRA Art. 13(1) Design, development and production to Annex I Part Isold in the EU
CRACRA Annex I Part I(1) Appropriate level of cybersecurity based on the riskssold in the EU
UK PSTIUK PSTI R.1 No universal default passwordssold to UK consumers
UK PSTIUK PSTI R.2 Published point of contact for security issuessold to UK consumers
UK PSTIUK PSTI R.3 Published defined support periodsold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.1 (provision group) No universal default passwordssold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilitiessold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.3 (provision group) Keep software updatedsold to UK consumers
CaliforniaCalifornia 1798.91.04(a) Reasonable security feature or featuressold in California, as the manufacturer
CaliforniaCalifornia 1798.91.04(b) Authentication outside a local area network: unique password or forced new credentialsold in California, as the manufacturer

The route clause, set out

CRA Annex VIII Part IModule A: internal control

Under internal control the manufacturer draws up the Annex VII technical documentation, takes all measures so that design, development, production and vulnerability handling and their monitoring ensure compliance with Annex I Parts I and II, affixes the CE marking to each conforming product, and draws up the declaration, keeping it with the technical documentation for ten years or the support period if longer. The authorised representative may handle marking and declaration under mandate.

What a notified body or authority asks to see: Internal control file: technical documentation, production and vulnerability handling monitoring records, declaration
Where lists usually fall short: Internal control treated as paperwork with no monitoring of processes
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

Other functions in connected devices a maker sells (default class)