Where the CRA puts tamper-resistant silicon Annex III Class II (3)-(4), Art. 7(1), Art. 7(4)
Annex III Class II lists tamper-resistant microprocessors (item 3) and tamper-resistant microcontrollers (item 4) as separate entries. A product with the core functionality of either is a Class II important product and moves to the conformity assessment procedures of Article 32(3), the strictest of the two important-product classes.
The Commission fixed the technical description of each category in an implementing act under Article 7(4) (Implementing Regulation (EU) 2025/2392). Because "tamper-resistant" is a property rather than a product name, that description does the deciding: it settles how much physical and logical hardening puts a part in items 3 or 4.
How this differs from Class I security chips Annex III Class I (13)-(15), Annex III Class II (3)-(4), Art. 32(2)-(3)
The CRA lists two related but distinct silicon groups. Microprocessors, microcontrollers, and ASICs or FPGAs with security-related functionalities sit in Class I (items 13 to 15), with the possibility of self-assessment where harmonised standards are applied in full. Tamper-resistant microprocessors and microcontrollers sit one tier higher in Class II (items 3 and 4).
The practical consequence is the conformity route. A Class I security chip can, in principle, be self-assessed under internal control with the right standards; a tamper-resistant Class II part cannot. So the first task for a hardened part is confirming which tier it falls in, since that decides whether a notified body is unavoidable.
Judgment call: The CRA does not draw a numeric boundary between a "security-related" Class I chip and a "tamper-resistant" Class II chip; the technical descriptions control, and borderline parts deserve documented reasoning.
Class II: no self-assessment route Art. 32(3), Annex VIII
Class II reflects a higher level of cybersecurity risk, so it offers no internal-control option. Applying harmonised standards in full does not unlock self-assessment for a tamper-resistant part the way it can for a Class I chip.
Under Article 32(3), conformity must be demonstrated through EU-type examination plus conformity to type (modules B and C), full quality assurance (module H), or a European cybersecurity certification scheme at assurance level at least "substantial". Two of the three require a notified body, so plan the lead time and cost well before 11 December 2027.
The rest is the ordinary manufacturer programme Art. 13, Art. 14, Annex I
The Class II route changes how you prove conformity, not the substance of the duties. Essential cybersecurity requirements, vulnerability handling including a coordinated vulnerability disclosure policy, technical documentation, CE marking, and reporting of actively exploited vulnerabilities and severe incidents apply to a tamper-resistant chip exactly as to any product.