Annex III, Class II ยท Regulation (EU) 2024/2847

Are tamper-resistant chips important products under the CRA?

Verified against the Official Journal text on

Important product, Class II (Annex III Class II (3)-(4), Art. 7(1))

Yes, most likely, and at the higher tier. Tamper-resistant microprocessors and tamper-resistant microcontrollers are listed as important products in Class II of the EU Cyber Resilience Act (Annex III, Class II, items 3 and 4). A part whose core functionality matches is a Class II important product, and Class II gives no self-assessment route: conformity must go through EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". This is a tier above the Class I security chips listed in items 13 to 15.

Basis: Annex III Class II (3)-(4), Art. 7(1), Art. 32(3)

Judgment call: Whether a chip is "tamper-resistant" within the category is a classification judgment. The technical descriptions in Implementing Regulation (EU) 2025/2392 control the match.

Where the CRA puts tamper-resistant silicon Annex III Class II (3)-(4), Art. 7(1), Art. 7(4)

Annex III Class II lists tamper-resistant microprocessors (item 3) and tamper-resistant microcontrollers (item 4) as separate entries. A product with the core functionality of either is a Class II important product and moves to the conformity assessment procedures of Article 32(3), the strictest of the two important-product classes.

The Commission fixed the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392). Because "tamper-resistant" is a property rather than a product name, that description does the deciding: it settles how much physical and logical hardening puts a part in items 3 or 4.

How this differs from Class I security chips Annex III Class I (13)-(15), Annex III Class II (3)-(4), Art. 32(2)-(3)

The CRA lists two related but distinct silicon groups. Microprocessors, microcontrollers, and ASICs or FPGAs with security-related functionalities sit in Class I (items 13 to 15), with the possibility of self-assessment where harmonised standards are applied in full. Tamper-resistant microprocessors and microcontrollers sit one tier higher in Class II (items 3 and 4).

The practical consequence is the conformity route. A Class I security chip can, in principle, be self-assessed under internal control with the right standards; a tamper-resistant Class II part cannot. So the first task for a hardened part is confirming which tier it falls in, since that decides whether a notified body is unavoidable.

Judgment call: The CRA does not draw a numeric boundary between a "security-related" Class I chip and a "tamper-resistant" Class II chip; the technical descriptions control, and borderline parts deserve documented reasoning.

Class II: no self-assessment route Art. 32(3), Annex VIII

Class II reflects a higher level of cybersecurity risk, so it offers no internal-control option. Applying harmonised standards in full does not unlock self-assessment for a tamper-resistant part the way it can for a Class I chip.

Under Article 32(3), conformity must be demonstrated through EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". Two of the three require a notified body, so plan the lead time and cost well before 11 December 2027.

The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I

The Class II route changes how you prove conformity, not the substance of the duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to a tamper-resistant chip exactly as to any product.

What you must do

  • Design, develop, and produce the chip in line with the essential cybersecurity requirements. (Art. 13(1), Annex I Part I)
  • Handle vulnerabilities during the support period, including putting in place and enforcing a coordinated vulnerability disclosure policy. (Art. 13(8), Annex I Part II (5))
  • Draw up technical documentation and carry out the Class II conformity assessment: modules B and C, module H, or a European cybersecurity certification scheme at assurance level at least "substantial". There is no internal-control option. Then affix the CE marking. (Art. 13(12), Art. 32(3), Annex VIII)
  • Report actively exploited vulnerabilities and severe incidents once reporting duties start. (Art. 14)

The dates that decide your planning

11 September 2026
Reporting duties start. Actively exploited vulnerabilities and severe incidents must be reported via the single reporting platform: early warning within 24 hours, notification within 72 hours, then a final report (within 14 days after a corrective measure is available for vulnerabilities, within one month after the notification for severe incidents). (Art. 14, Art. 16, Art. 71(2))
11 December 2027
The full obligations apply: essential cybersecurity requirements, technical documentation, conformity assessment, and CE marking. (Art. 71(2))

Frequently asked

How is a tamper-resistant chip different from a Class I security chip?

Both are silicon categories, but they sit in different tiers. Security-related microprocessors, microcontrollers, and ASICs or FPGAs are Class I (items 13 to 15). Tamper-resistant microprocessors and microcontrollers are Class II (items 3 and 4), which removes the self-assessment route. (Annex III Class I (13)-(15), Annex III Class II (3)-(4))

Can I self-assess a tamper-resistant microcontroller?

No. Self-assessment on the strength of harmonised standards is a Class I mechanism. A tamper-resistant part is Class II, and Article 32(3) offers no internal-control route: you need modules B and C, module H, or an eligible European cybersecurity certification scheme. (Art. 32(3))

How do I know if my chip is "tamper-resistant" within the category?

The CRA does not set a numeric threshold in the article text. The technical descriptions in Implementing Regulation (EU) 2025/2392 control which parts fall in items 3 and 4, so a borderline part should be classified against those descriptions and the reasoning documented. (Art. 7(4))

When does this start applying?

Reporting duties start 11 September 2026. The full obligations, including the Class II conformity route through a notified body or certification, apply from 11 December 2027. (Art. 71(2))

Check where your silicon lands, free

The Vexwatch Scope Checker walks the same cited decision tree in about three minutes: whether you are in scope, in which role, in which category, and which obligations hit on which date.

Check your scope, free See the Blueprint

This page is general information about Regulation (EU) 2024/2847, the EU Cyber Resilience Act. It is compliance tooling, not legal advice, and creates no client relationship. It may not reflect your specific circumstances or the most recent regulatory guidance. Verify conclusions against the regulation or qualified counsel before relying on them.