What Annex IV lists Annex IV, Art. 7(4), Art. 8(2)
Annex IV sets out the critical products with digital elements. Item 1 is hardware devices with security boxes. Item 2 is smart meter gateways within smart metering systems as defined in Directive (EU) 2019/944, and other devices for advanced security purposes, including for secure cryptoprocessing. Item 3 is smartcards or similar devices, including secure elements.
These categories carry the highest cybersecurity risk in the CRA, typically because essential entities depend on them or because a compromise could disrupt critical supply chains. A product with the core functionality of an Annex IV category is a critical product; the Commission fixed the technical description of each in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392).
The two possible routes: certificate or Article 32(3) Art. 8(1), Art. 32(4), Art. 32(3)
Article 8(1) empowers the Commission to adopt delegated acts determining which Annex IV products must obtain a European cybersecurity certificate at assurance level at least "substantial", but only where a certification scheme has been adopted under Regulation (EU) 2019/881 and is available to manufacturers. That mandatory-certification route is therefore contingent on the Commission acting and a scheme existing.
Where no such delegated act has been adopted, Article 8(1) itself provides that Annex IV products follow the conformity assessment procedures of Article 32(3), and Article 32(4) confirms the same: a critical product uses a certification scheme under Article 8(1), or, where the Article 8(1) conditions are not met, any of the Article 32(3) procedures. As of July 2026 we are not aware of an adopted Article 8(1) delegated act, so the practical route is usually the Class II route: modules B and C, module H, or an eligible certification scheme. Check the current state before you commit to a route.
Judgment call: Which route applies depends on whether a delegated act under Article 8(1) and an available certification scheme exist for the specific category. Confirm the current state of the delegated acts before choosing a route, as this can change.
No self-assessment, in either route Art. 32(3), Art. 32(4), Annex VIII
Neither route allows internal control. The Article 32(3) procedures that apply absent a delegated act are the same notified-body or certification routes used for Class II important products, with no self-assessment option. Where a delegated act does apply, a European cybersecurity certificate at assurance level at least "substantial" is mandatory.
For manufacturers of security boxes, smart meter gateways, secure cryptoprocessors, smartcards, or secure elements, that means engaging a notified body or a certification body is effectively unavoidable, and the lead time is worth planning well before 11 December 2027.
The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
The critical-product tier changes how you prove conformity, not the substance of the duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to a critical product exactly as to any product in scope.