← CRA Glossary
CRA Legal Terms

Which products are critical under the CRA?

Critical products under the EU Cyber Resilience Act are the three Annex IV categories. Hardware Devices with Security Boxes, smart meter gateways, and smartcards or similar devices, including secure elements, need a third-party conformity route instead of Module A self-assessment.

Critical products under the EU Cyber Resilience Act are the three Annex IV categories. Hardware Devices with Security Boxes, smart meter gateways, and smartcards or similar devices, including secure elements, need a third-party conformity route instead of Module A self-assessment.

CRA Legal Terms

Last updated 4 October 2026

Key takeaways

  1. Annex IV lists the three categories of critical products.
  2. Article 8 lets the Commission mandate a European cybersecurity certification scheme for a critical product.
  3. Until an Article 8(1) delegated act applies, Article 32(4) directs critical products to the Class II conformity routes.
  4. Module A internal control is unavailable to critical products.

What Are Critical Products?

Critical products are products with digital elements whose cybersecurity risk sits at the highest tier under the EU Cyber Resilience Act. Annex IV lists these products across 3 categories. The CRA classification structure has four tiers. Default class products form the baseline. Important Class I and Important Class II products sit in Annex III. Critical products sit in Annex IV above all other tiers.

Article 8 and Article 32 govern critical products. The classification determines the conformity assessment route. Commission Implementing Regulation (EU) 2025/2392 provides the technical descriptions for the categories. The Commission may amend Annex IV by delegated act under Article 8.

CRA reference:Article 8, Annex IV, Article 32(4)

Annex IV Critical Product Categories

Annex IV lists 3 categories.

  • Hardware Devices with Security Boxes.
  • Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 and other devices for advanced security purposes, including for secure cryptoprocessing.
  • Smartcards or similar devices, including secure elements.

These categories cover dedicated security hardware and critical infrastructure interfaces. Products in these categories store sensitive credentials, process cryptographic operations, or control critical data flows.

CRA reference:Annex IV, Article 8(1)

Conformity Assessment for Critical Products

Module A self-assessment is unavailable for critical products in every case. Article 32(4) and Article 8(1) establish the mandatory conformity assessment routes.

Where the European Commission adopts a delegated act under Article 8(1), manufacturers must demonstrate conformity through a European cybersecurity certification scheme. The required assurance level is at least substantial.

Where no Article 8(1) delegated act applies, Article 32(4) directs manufacturers to the assessment procedures specified for Important Class II products. These routes include EU-type examination plus conformity to type (Module B and Module C), full quality assurance (Module H), or an applicable European cybersecurity certification scheme at assurance level at least substantial. A notified body or accredited certification body must evaluate the product.

CRA reference:Article 8(1), Article 32(4), Article 30(4)

Core Functionality and Scope Boundaries

Classification depends on the core functionality of the product. The technical descriptions in Commission Implementing Regulation (EU) 2025/2392 govern the scope.

  • Physical envelope. Hardware devices with security boxes require physical envelopes that provide tamper detection, tamper resistance, or tamper response.
  • Gateways versus meters. The smart meter gateway category covers the communication gateway rather than the basic meter itself. Classifying a standard utility meter as a critical product is an expensive error.
  • Secure elements versus host devices. The smartcard and secure element category covers the secure controller or chip. A host product that merely contains a secure element needs its own classification assessment.
CRA reference:Article 8, Annex IV

CVD Portal makes Which products are critical under the CRA? compliance straightforward.

Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.

Create my free CVD portalCreate your free CVD portal

Frequently asked

Can a critical product use Module A self-assessment?+

No. Module A self-assessment is unavailable for critical products. Article 32(4) mandates third-party conformity assessment through an Article 8(1) European cybersecurity certification scheme or through the procedures for Class II products under Module B plus Module C, Module H, or an approved certification scheme.

What is the difference between Annex III and Annex IV products?+

Annex III lists 23 important product categories across Class I and Class II. Annex IV lists 3 critical product categories. Critical products in Annex IV carry the highest risk classification and require certification under Article 8(1) schemes when mandated by the Commission.

Does adding a secure element make the entire host device a critical product?+

No. Integrating a secure element does not automatically classify the entire host device as a critical product. The secure element component itself must meet critical product requirements. The host device is classified based on its own core functionality under the CRA.

Sector checklists covering Which products are critical under the CRA?

Payment Terminals & ATMsPayment terminals and ATMs are products with digital elements that sit at the intersection of the CRA, PCI DSS, PSD2, and EBA regulatory frameworks. They are Annex III Class I due to their financial infrastructure role. ATMs and unattended payment terminals in public spaces face significant physical and cybersecurity risks. While PCI DSS compliance does not provide a CRA exclusion, the two frameworks address overlapping security domains and compliance evidence from PCI assessments can support CRA technical documentation.Smart Grid & Energy InfrastructureSmart grid systems - including advanced metering infrastructure (AMI), distribution automation systems, grid management software, and grid-connected energy storage controllers - are among the most critical products under the CRA. CRA Annex III Class II applies, requiring mandatory Notified Body assessment. The energy sector is NIS2-classified as essential infrastructure, creating overlapping obligations between CRA product requirements and NIS2 operator obligations.Access Control & Physical Security SystemsAccess control systems - including IP-connected door controllers, card readers, biometric access terminals, and integrated physical security management platforms - are products with digital elements that directly control physical access to facilities. Their compromise can enable physical security breaches with serious consequences. Most networked access control systems qualify as Annex III Class I; those securing critical infrastructure or government facilities may be Class II.

This definition is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.

Browse the full CRA Compliance Checklist

See how Which products are critical under the CRA? fits into your complete CRA compliance programme.

View checklists →