Annex III, Class I ยท Regulation (EU) 2024/2847

Are microprocessors and microcontrollers important products under the CRA?

Verified against the Official Journal text on

Important product, Class I (if security-related) (Annex III Class I (13)-(15), Art. 7(1))

It depends on the qualifier. Microprocessors, microcontrollers, and ASICs or FPGAs are listed as important products under the EU Cyber Resilience Act only where they have security-related functionalities (Annex III, Class I, items 13, 14, and 15). A general-purpose chip without such functionality is still in scope as a product with digital elements, but as a default-category product with the free choice of conformity route. Where the security qualifier applies, self-assessment stays available only with harmonised standards, common specifications, or eligible certification applied in full. Tamper-resistant variants sit one tier higher, in Class II.

Basis: Annex III Class I (13)-(15), Art. 7(1), Art. 32(1)-(2)

Judgment call: Whether a chip has "security-related functionalities" is the pivot, and it is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

The three chip entries and their shared qualifier Annex III Class I (13)-(15), Art. 7(1)

Annex III Class I lists three silicon categories in a row: microprocessors with security-related functionalities (item 13), microcontrollers with security-related functionalities (item 14), and ASICs and FPGAs with security-related functionalities (item 15). The phrase "with security-related functionalities" is doing the classifying work in all three.

That qualifier is the pivot. A processor or microcontroller that carries out security functions, such as key storage, cryptographic acceleration, secure boot, or a hardware root of trust, falls in the category. A plain compute part without such functionality does not, and stays a default-category product with the ordinary free choice of conformity route.

Where the technical descriptions do the deciding Art. 7(4)

The Commission fixed the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392). Because "security-related functionalities" has no self-evident boundary, that description, not the datasheet marketing, decides whether a given part is in items 13 to 15.

This matters most for parts that blur the line, such as a general-purpose microcontroller with an optional crypto peripheral, or an FPGA sold for mixed workloads. Resolve those against the implementing regulation and document the reasoning; a wrong call changes your conformity route, not just your paperwork.

Judgment call: The CRA text does not define how much security capability makes a chip "security-related"; the technical descriptions control, and borderline parts deserve a documented classification.

Class I here, Class II for tamper-resistant parts Annex III Class II (3)-(4), Art. 32(2), Annex VIII

The security-chip entries in Class I are distinct from the tamper-resistant microprocessors and microcontrollers listed separately in Class II (items 3 and 4). A part designed to resist physical tampering and extraction is treated as a higher-tier product with a stricter route, so confirm which tier your part sits in before choosing a procedure.

For a Class I security chip, internal control (module A) stays available only where you apply harmonised standards, common specifications, or a European cybersecurity certification scheme at assurance level at least "substantial" in full. Otherwise the route is EU-type examination plus conformity to type (modules B and C) or full quality assurance (module H) via a notified body.

The rest of the manufacturer programme still applies Art. 13, Art. 14, Annex I

Whichever tier applies, the substance of the duties is the same: essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents. Silicon vendors should also plan for the information duties toward integrators.

What you must do

  • Design, develop, and produce the chip in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and, if the security qualifier applies, carry out the Class I conformity assessment: internal control only with harmonised standards, common specifications, or eligible certification applied in full, otherwise modules B and C or module H via a notified body. (Art. 13(12), Art. 32(2), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

Is a plain general-purpose microcontroller a Class I important product?

Not on its own. Items 13 to 15 apply to chips with security-related functionalities. A plain microcontroller is still in CRA scope as a product with digital elements, but as a default-category product with the free choice of conformity route, unless the security qualifier is met. (Annex III Class I (13)-(15), Art. 32(1))

What counts as a "security-related functionality" in a chip?

The CRA does not define it in the article text, and the technical descriptions in Implementing Regulation (EU) 2025/2392 control. Typical examples are key storage, cryptographic acceleration, secure boot, or a hardware root of trust. Borderline parts deserve a documented classification. (Art. 7(4))

How is this different from tamper-resistant chips?

Tamper-resistant microprocessors and microcontrollers are listed separately in Class II (items 3 and 4), a higher tier with a stricter route and no internal-control option. Confirm which tier your part sits in before choosing a conformity procedure. (Annex III Class II (3)-(4), Art. 32(3))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including any Class I conformity route, apply from 11 December 2027. (Art. 71(2))

Check where your silicon lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.