Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04
critical · product function

Smartcard or similar device

By the Annex wording, a smartcard or similar device points to the critical class (Annex IV, point 3). The route that class asks for: a European cybersecurity certification scheme where a delegated act under Art. 8(1) requires one; where Art. 8(1)'s conditions are not met, one of the Art. 32(3) procedures (EU-type examination or full quality assurance) (Art. 32(4)); internal control is not among them.

The Annex wording

Annex IV, point 3
Smartcards or similar devices, including secure elements

Cited to the held text of Regulation (EU) 2024/2847. By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted.

A line that places here

example

SC-5 | smartcard | EU | businesses | notified body

Check this line

What the finder reads on these lines

8 of the 14 notes

Clauses

13 cited
RegimeClauseApplies when
CRACRA Art. 8(1) Critical products and European cybersecurity certificationsold in the EU
CRACRA Art. 32(4) Conformity assessment for critical productssold in the EU
CRACRA Annex VIII Part II Module B: EU-type examination application and manufacturer dutiessold in the EU
CRACRA Art. 13(1) Design, development and production to Annex I Part Isold in the EU
CRACRA Annex I Part I(1) Appropriate level of cybersecurity based on the riskssold in the EU
UK PSTIUK PSTI R.1 No universal default passwordssold to UK consumers
UK PSTIUK PSTI R.2 Published point of contact for security issuessold to UK consumers
UK PSTIUK PSTI R.3 Published defined support periodsold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.1 (provision group) No universal default passwordssold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilitiessold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.3 (provision group) Keep software updatedsold to UK consumers
CaliforniaCalifornia 1798.91.04(a) Reasonable security feature or featuressold in California, as the manufacturer
CaliforniaCalifornia 1798.91.04(b) Authentication outside a local area network: unique password or forced new credentialsold in California, as the manufacturer

The route clause, set out

CRA Art. 32(4)Conformity assessment for critical products

A critical product in Annex IV must show conformity through a European cybersecurity certification scheme required under Article 8(1), or, where those conditions are not met, through one of the Article 32(3) procedures.

What a notified body or authority asks to see: European cybersecurity certificate at the required assurance level, or third-party procedure record
Where lists usually fall short: Certification route assumed available before the delegated act applies
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

Other functions in critical products (annex iv)