Which products are critical under the CRA?
Critical products under the EU Cyber Resilience Act are the three Annex IV categories. Hardware Devices with Security Boxes, smart meter gateways, and smartcards or similar devices, including secure elements, need a third-party conformity route instead of Module A self-assessment.
Critical products under the EU Cyber Resilience Act are the three Annex IV categories. Hardware Devices with Security Boxes, smart meter gateways, and smartcards or similar devices, including secure elements, need a third-party conformity route instead of Module A self-assessment.
CRA Legal TermsLast updated 4 October 2026
Key takeaways
- Annex IV lists the three categories of critical products.
- Article 8 lets the Commission mandate a European cybersecurity certification scheme for a critical product.
- Until an Article 8(1) delegated act applies, Article 32(4) directs critical products to the Class II conformity routes.
- Module A internal control is unavailable to critical products.
What Are Critical Products?
Critical products are products with digital elements whose cybersecurity risk sits at the highest tier under the EU Cyber Resilience Act. Annex IV lists these products across 3 categories. The CRA classification structure has four tiers. Default class products form the baseline. Important Class I and Important Class II products sit in Annex III. Critical products sit in Annex IV above all other tiers.
Article 8 and Article 32 govern critical products. The classification determines the conformity assessment route. Commission Implementing Regulation (EU) 2025/2392 provides the technical descriptions for the categories. The Commission may amend Annex IV by delegated act under Article 8.
Annex IV Critical Product Categories
Annex IV lists 3 categories.
- Hardware Devices with Security Boxes.
- Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing.
- Smartcards or similar devices, including secure elements.
These categories cover dedicated security hardware and critical infrastructure interfaces. Products in these categories store sensitive credentials, process cryptographic operations, or control critical data flows.
Conformity Assessment for Critical Products
Module A self-assessment is unavailable for critical products in every case. Article 32(4) and Article 8(1) establish the mandatory conformity assessment routes.
Where the European Commission adopts a delegated act under Article 8(1), manufacturers must demonstrate conformity through a European cybersecurity certification scheme. The required assurance level is at least substantial.
Where no Article 8(1) delegated act applies, Article 32(4) directs manufacturers to the assessment procedures specified for Important Class II products. These routes include EU-type examination plus conformity to type (Module B and Module C), full quality assurance (Module H), or an applicable European cybersecurity certification scheme at assurance level at least substantial. A notified body or accredited certification body must evaluate the product.
Core Functionality and Scope Boundaries
Classification depends on the core functionality of the product. The technical descriptions in Commission Implementing Regulation (EU) 2025/2392 govern the scope.
- Physical envelope. Hardware devices with security boxes require physical envelopes that provide tamper detection, tamper resistance, or tamper response.
- Gateways versus meters. The smart meter gateway category covers the communication gateway rather than the basic meter itself. Classifying a standard utility meter as a critical product is an expensive error.
- Secure elements versus host devices. The smartcard and secure element category covers the secure controller or chip. A host product that merely contains a secure element needs its own classification assessment.
CVD Portal makes Which products are critical under the CRA? compliance straightforward.
Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Create my free CVD portalCreate your free CVD portalFrequently asked
Can a critical product use Module A self-assessment?+
No. Module A self-assessment is unavailable for critical products. Article 32(4) mandates third-party conformity assessment through an Article 8(1) European cybersecurity certification scheme or through the procedures for Class II products under Module B plus Module C, Module H, or an approved certification scheme.
What is the difference between Annex III and Annex IV products?+
Annex III lists 23 important product categories across Class I and Class II. Annex IV lists 3 critical product categories. Critical products in Annex IV carry the highest risk classification and require certification under Article 8(1) schemes when mandated by the Commission.
Does adding a secure element make the entire host device a critical product?+
No. Integrating a secure element does not automatically classify the entire host device as a critical product. The secure element component itself must meet critical product requirements. The host device is classified based on its own core functionality under the CRA.
Sector checklists covering Which products are critical under the CRA?
This definition is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.
Browse the full CRA Compliance Checklist
See how Which products are critical under the CRA? fits into your complete CRA compliance programme.