Annex IV ยท Regulation (EU) 2024/2847

What is a critical product with digital elements under the CRA?

Verified against the Official Journal text on

Critical product, Annex IV (Annex IV, Art. 8(1))

Critical products are the strictest tier of the EU Cyber Resilience Act. Annex IV lists three categories: hardware devices with security boxes; smart meter gateways and other devices for advanced security purposes, including secure cryptoprocessing; and smartcards or similar devices, including secure elements. Where the Commission adopts a delegated act under Article 8(1), such a product must obtain a European cybersecurity certificate at assurance level at least "substantial". Where no such delegated act exists yet, the product instead follows the Class II conformity procedures of Article 32(3), through a notified body or certification.

Basis: Annex IV, Art. 8(1), Art. 32(4), Art. 32(3)

Judgment call: Whether a product has the core functionality of an Annex IV category is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

What Annex IV lists Annex IV, Art. 7(4), Art. 8(2)

Annex IV sets out the critical products with digital elements. Item 1 is hardware devices with security boxes. Item 2 is smart meter gateways within smart metering systems as defined in Directive (EU) 2019/944, and other devices for advanced security purposes, including for secure cryptoprocessing. Item 3 is smartcards or similar devices, including secure elements.

These categories carry the highest cybersecurity risk in the CRA, typically because essential entities depend on them or because a compromise could disrupt critical supply chains. A product with the core functionality of an Annex IV category is a critical product; the Commission fixed the technical description of each in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392).

The two possible routes: certificate or Article 32(3) Art. 8(1), Art. 32(4), Art. 32(3)

Article 8(1) empowers the Commission to adopt delegated acts determining which Annex IV products must obtain a European cybersecurity certificate at assurance level at least "substantial", but only where a certification scheme has been adopted under Regulation (EU) 2019/881 and is available to manufacturers. That mandatory-certification route is therefore contingent on the Commission acting and a scheme existing.

Where no such delegated act has been adopted, Article 8(1) itself provides that Annex IV products follow the conformity assessment procedures of Article 32(3), and Article 32(4) confirms the same: a critical product uses a certification scheme under Article 8(1), or, where the Article 8(1) conditions are not met, any of the Article 32(3) procedures. As of July 2026 we are not aware of an adopted Article 8(1) delegated act, so the practical route is usually the Class II route: modules B and C, module H, or an eligible certification scheme. Check the current state before you commit to a route.

Judgment call: Which route applies depends on whether a delegated act under Article 8(1) and an available certification scheme exist for the specific category. Confirm the current state of the delegated acts before choosing a route, as this can change.

No self-assessment, in either route Art. 32(3), Art. 32(4), Annex VIII

Neither route allows internal control. The Article 32(3) procedures that apply absent a delegated act are the same notified-body or certification routes used for Class II important products, with no self-assessment option. Where a delegated act does apply, a European cybersecurity certificate at assurance level at least "substantial" is mandatory.

For manufacturers of security boxes, smart meter gateways, secure cryptoprocessors, smartcards, or secure elements, that means engaging a notified body or a certification body is effectively unavoidable, and the lead time is worth planning well before 11 December 2027.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

The critical-product tier changes how you prove conformity, not the substance of the duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to a critical product exactly as to any product in scope.

What you must do

  • Design, develop, and produce the product in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out conformity assessment: a mandatory European cybersecurity certificate where a delegated act under Article 8(1) applies, otherwise the Article 32(3) procedures (modules B and C, module H, or an eligible certification scheme). Then affix the CE marking. (Art. 13(12), Art. 8(1), Art. 32(4), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Do critical products always need European cybersecurity certification?

Not always. Mandatory certification applies only where the Commission has adopted a delegated act under Article 8(1) and a scheme exists. Where no such act applies, Article 32(4) routes the product to the Article 32(3) procedures instead, through a notified body or certification. (Art. 8(1), Art. 32(4))

Is a secure element inside a larger device a critical product?

The category (item 3) covers smartcards or similar devices including secure elements. Whether a component embedded in a larger product makes that product a critical one is a core-functionality question the technical descriptions settle; integration alone does not reclassify the host product. (Annex IV, Art. 7(1), Art. 7(4))

Can I ever self-assess a critical product?

No. Both routes exclude internal control. Either a mandatory European cybersecurity certificate applies, or the Article 32(3) procedures do (modules B and C, module H, or an eligible certification scheme), each involving a notified body or certification body. (Art. 32(3), Art. 32(4))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the critical-product conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your product lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.