Cyber Resilience Act
Critical products with digital elements
Practical term
Critical products with digital elements are products carrying the core functionality of one of the three categories listed in Annex IV to the Cyber Resilience Act (CRA). It is the smallest product group in the Regulation and the only one for which certification can be made compulsory.
The classification does not change which requirements a product has to meet. The Essential cybersecurity requirements in Annex I apply to every product with digital elements alike. What it changes is the route by which compliance is demonstrated, and for critical products that route always runs through a third party.
The three Annex IV categories
- hardware devices with security boxes
- smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944, and other devices for advanced security purposes, including for secure cryptoprocessing
- smartcards or similar devices, including secure elements
Annex IV has no division into classes. The category names alone do not settle the classification, though. Article 7(4) obliges the Commission to adopt, by 11 December 2025, an implementing act setting out the technical description of these three categories as well. In borderline cases that description decides whether a device counts as a smartcard or as a secure element.
What “critical” means here
It refers neither to critical infrastructure nor to how important the product is to your own business. Article 8(2) sets out when a category belongs in Annex IV at all. It must meet at least one of two criteria:
- essential entities within the meaning of Article 3 of Directive (EU) 2022/2555 (the NIS-2 Directive) have a critical dependency on the product category
- incidents and exploited vulnerabilities concerning the category could lead to serious disruptions of critical supply chains across the internal market
On top of that the Commission takes into account the criteria in Article 7(2), the same ones that govern important products with digital elements. Critical is therefore an escalation rather than a separate logic. A cybersecurity function or a central system function is joined by critical dependency or supply chain effect.
Recital 46 also grounds the selection in market reality. The three categories already make wide use of various forms of certification and are covered by the European Common Criteria-based cybersecurity certification scheme (EUCC) set out in Commission Implementing Regulation (EU) 2024/482.
Core functionality, not mere presence
Article 8(1) turns on the core functionality of a category. A device that merely contains a secure element does not thereby acquire the core functionality of that category. The secure element remains one once it is placed on the market in its own right.
The text spells this out only for Annex III. Article 7(1), second sentence, states there that integrating such a product does not by itself pull the host product into the relevant procedures. Article 8 carries no equivalent sentence. Anyone building in a security box, a smart meter gateway or a secure element should therefore document the reasoning behind their own classification rather than treat it as obvious.
The route under Article 32(4)
The CRA offers two routes for critical products. The first is a European cybersecurity certification scheme under Article 8(1). Where its conditions are not met, the second applies, namely one of the procedures in Article 32(3):
- EU type-examination under module B, followed by conformity to type based on internal production control under module C
- conformity assessment based on full quality assurance under module H
- where available and applicable, a European cybersecurity certification scheme under Article 27(9), at assurance level at least “substantial”
Internal control under module A is not open to critical products in any configuration. The relief for Free and open-source software does not help either, since Article 32(5) names only the Annex III categories.
When certification becomes compulsory
Article 8(1) empowers the Commission to require, by delegated act, a European cybersecurity certificate at assurance level at least “substantial”. Several conditions attach. A suitable scheme under Regulation (EU) 2019/881 must have been adopted and be available to manufacturers, and the Commission must assess the potential market impact and consult stakeholders, among them the European Cybersecurity Certification Group.
The assurance level required has to be proportionate to the cybersecurity risk and must take account of the intended purpose, including critical dependency on the product by essential entities. Under recital 47, a sensitive or critical environment may call for the highest level. Such acts must provide a transitional period of at least six months, unless imperative urgency justifies less.
The list itself is movable too. Article 8(2) lets the Commission add or withdraw categories; there is no moving between classes, because Annex IV has none. The same six-month minimum applies to those acts, and stakeholders are consulted beforehand under Article 9.
What this means for planning
The Regulation applies from 11 December 2027. Chapter IV on the notification of conformity assessment bodies (Articles 35–51) applies from 11 June 2026, so that bodies are designated in time.
For critical products that is precisely the bottleneck. Anyone who needs a Notified body or a conformity assessment body under a certification scheme depends on its capacity. Scheduling should therefore start well before 11 December 2027 rather than from it.
Practical questions
-
Only if it comes from a European scheme adopted pursuant to Regulation (EU) 2019/881. The presumption of conformity in Article 27(8) attaches to a certificate issued under such a scheme, not to a purely national certificate. For the Annex IV categories, the EUCC is the obvious candidate. And the presumption reaches only as far as the certificate actually covers the Annex I requirements. Vulnerability handling under Annex I, Part II is frequently absent from a pure product certification.
-
The delegated act must provide a transitional period of at least six months, unless imperative urgency justifies a shorter one. The duty attaches to placing on the market, so it governs your future shipments rather than reaching back into every unit already sold. Watch for Substantial modification all the same. If the product is substantially modified afterwards, its conformity has to be verified again and, where applicable, it has to undergo a new conformity assessment, then under the route in force at that moment. Six months is a tight window for a first certification.
-
The Regulation states no express rule of precedence. In practice the question resolves through the scope of the procedures. Article 32(4) points to the procedures in Article 32(3), and those are at least as demanding as the ones in Article 32(2). Taking the route for critical products therefore covers the other classification as well. Record both classifications in the technical documentation so that market surveillance can follow your choice of procedure.
This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.