Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04
important class II · product function

Tamper-resistant microprocessor

By the Annex wording, a tamper-resistant microprocessor points to the important class II class (Annex III, class II, point 3). The route that class asks for: eU-type examination (module B then C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least substantial where available (Art. 32(3)); internal control is not among them.

The Annex wording

Annex III, class II, point 3
Tamper-resistant microprocessors

Cited to the held text of Regulation (EU) 2024/2847. By the Annex wording; the Commission's technical descriptions of each category (Commission Implementing Regulation (EU) 2025/2392) are named, not quoted.

A line that places here

example

TR-MPU | tamper-resistant microprocessor | EU | businesses | notified body

Check this line

What the finder reads on these lines

8 of the 14 notes

Clauses

13 cited
RegimeClauseApplies when
CRACRA Art. 7(1) Classifying a product as important (Annex III, class I or II)sold in the EU
CRACRA Art. 32(3) Conformity assessment for important class II productssold in the EU
CRACRA Annex VIII Part II Module B: EU-type examination application and manufacturer dutiessold in the EU
CRACRA Art. 13(1) Design, development and production to Annex I Part Isold in the EU
CRACRA Annex I Part I(1) Appropriate level of cybersecurity based on the riskssold in the EU
UK PSTIUK PSTI R.1 No universal default passwordssold to UK consumers
UK PSTIUK PSTI R.2 Published point of contact for security issuessold to UK consumers
UK PSTIUK PSTI R.3 Published defined support periodsold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.1 (provision group) No universal default passwordssold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilitiessold to UK consumers
ETSI EN 303 645ETSI EN 303 645 5.3 (provision group) Keep software updatedsold to UK consumers
CaliforniaCalifornia 1798.91.04(a) Reasonable security feature or featuressold in California, as the manufacturer
CaliforniaCalifornia 1798.91.04(b) Authentication outside a local area network: unique password or forced new credentialsold in California, as the manufacturer

The route clause, set out

CRA Art. 32(3)Conformity assessment for important class II products

For an Annex III class II product, conformity must be shown by module B plus C, module H, or, where available, a European cybersecurity certification scheme at assurance level at least substantial. Internal control is not available.

What a notified body or authority asks to see: EU-type examination certificate, quality system approval or European cybersecurity certificate
Where lists usually fall short: Class II product self-assessed
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)

Other functions in important products, class ii (annex iii)