Smart meter (no gateway role declared)
By the Annex wording, a smart meter (no gateway role declared) points to the default class, not listed in Annex III or IV. The route that class asks for: any Art. 32(1) procedure: internal control (module A), EU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme where available.
Where the match turns
A meter is not listed; a meter that also acts as the gateway of a smart metering system reads as Annex IV, point 2, so declare the gateway role where it has one.
A line that places here
exampleSM-400 | smart electricity meter | EU, UK | businesses | self-assessment
What the finder reads on these lines
10 of the 14 notes- 4. No process to report an actively exploited vulnerability or a severe incident: Who notifies the CSIRT and ENISA within 24 hours when this product carries an actively exploited vulnerability, and where is the process written down?
- 5. No support period stated, or under five years with no reason recorded: What is the support period, how was it set, and where is its end date shown to buyers?
- 6. A universal default password: When will each unit ship with a unique password, or require the user to set one at first use?
- 7. No published vulnerability contact: Where does a researcher report a vulnerability in this product, and is that address published?
- 8. No security update mechanism, or unsigned updates: How does a security fix reach units already sold, and how does the device check the update is genuine?
- 9. No software bill of materials kept, or partial: Where is the machine-readable SBOM for this product, and does it cover at least the top-level dependencies?
- 10. Sold to UK consumers with no statement of compliance: Where is the statement of compliance for this product, and does it travel with every unit sold to UK consumers?
- 11. Manufacturer outside the EU with no authorised representative: Will the company appoint an EU authorised representative, and if not, which importer holds the documentation for the market surveillance authorities?
- 12. Still on sale for 11 December 2027 with no conformity route planned: Which route will this product take, and by when, so units made available from 11 December 2027 carry the declaration?
- 13. Sold in California with no reasonable security feature recorded: Which reasonable security feature does this device carry for California, and is it unique per device or set by the user at first use?
Clauses
12 cited| Regime | Clause | Applies when |
|---|---|---|
| CRA | CRA Art. 32(1) Choosing a conformity assessment procedure (default products) | sold in the EU |
| CRA | CRA Annex VIII Part I Module A: internal control | sold in the EU |
| CRA | CRA Art. 13(1) Design, development and production to Annex I Part I | sold in the EU |
| CRA | CRA Annex I Part I(1) Appropriate level of cybersecurity based on the risks | sold in the EU |
| UK PSTI | UK PSTI R.1 No universal default passwords | sold to UK consumers |
| UK PSTI | UK PSTI R.2 Published point of contact for security issues | sold to UK consumers |
| UK PSTI | UK PSTI R.3 Published defined support period | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.1 (provision group) No universal default passwords | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilities | sold to UK consumers |
| ETSI EN 303 645 | ETSI EN 303 645 5.3 (provision group) Keep software updated | sold to UK consumers |
| California | California 1798.91.04(a) Reasonable security feature or features | sold in California, as the manufacturer |
| California | California 1798.91.04(b) Authentication outside a local area network: unique password or forced new credential | sold in California, as the manufacturer |
The route clause, set out
CRA Annex VIII Part IModule A: internal controlUnder internal control the manufacturer draws up the Annex VII technical documentation, takes all measures so that design, development, production and vulnerability handling and their monitoring ensure compliance with Annex I Parts I and II, affixes the CE marking to each conforming product, and draws up the declaration, keeping it with the technical documentation for ten years or the support period if longer. The authorised representative may handle marking and declaration under mandate.
Other functions in connected devices a maker sells (default class)
- In-home display
- Asset or vehicle tracker
- NFC or RFID tag with no software
- Sensor
- Data logger
- Telematics unit
- Industrial or IoT gateway
- Industrial controller
- Operator panel
- Smart thermostat or heating controller
- Smart plug or switch
- Smart lighting
- Electric vehicle charger
- Printer
- Connected appliance
- Smart TV, set-top box or streaming device
- Payment terminal
- Machine vision or dashboard camera
- Smart home hub
- Wearable
- Camera, purpose not declared
- Microcontroller or microprocessor, security functions not declared