Cyber Resilience Act

Critical products with digital elements

Practical term

Critical products with digital elements are products carrying the core functionality of one of the three categories listed in Annex IV to the Cyber Resilience Act (CRA). It is the smallest product group in the Regulation and the only one for which certification can be made compulsory.

The classification does not change which requirements a product has to meet. The Essential cybersecurity requirements in Annex I apply to every product with digital elements alike. What it changes is the route by which compliance is demonstrated, and for critical products that route always runs through a third party.

The three Annex IV categories

  • hardware devices with security boxes
  • smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944, and other devices for advanced security purposes, including for secure cryptoprocessing
  • smartcards or similar devices, including secure elements

Annex IV has no division into classes. The category names alone do not settle the classification, though. Article 7(4) obliges the Commission to adopt, by 11 December 2025, an implementing act setting out the technical description of these three categories as well. In borderline cases that description decides whether a device counts as a smartcard or as a secure element.

What “critical” means here

It refers neither to critical infrastructure nor to how important the product is to your own business. Article 8(2) sets out when a category belongs in Annex IV at all. It must meet at least one of two criteria:

  • essential entities within the meaning of Article 3 of Directive (EU) 2022/2555 (the NIS-2 Directive) have a critical dependency on the product category
  • incidents and exploited vulnerabilities concerning the category could lead to serious disruptions of critical supply chains across the internal market

On top of that the Commission takes into account the criteria in Article 7(2), the same ones that govern important products with digital elements. Critical is therefore an escalation rather than a separate logic. A cybersecurity function or a central system function is joined by critical dependency or supply chain effect.

Recital 46 also grounds the selection in market reality. The three categories already make wide use of various forms of certification and are covered by the European Common Criteria-based cybersecurity certification scheme (EUCC) set out in Commission Implementing Regulation (EU) 2024/482.

Core functionality, not mere presence

Article 8(1) turns on the core functionality of a category. A device that merely contains a secure element does not thereby acquire the core functionality of that category. The secure element remains one once it is placed on the market in its own right.

The text spells this out only for Annex III. Article 7(1), second sentence, states there that integrating such a product does not by itself pull the host product into the relevant procedures. Article 8 carries no equivalent sentence. Anyone building in a security box, a smart meter gateway or a secure element should therefore document the reasoning behind their own classification rather than treat it as obvious.

The route under Article 32(4)

The CRA offers two routes for critical products. The first is a European cybersecurity certification scheme under Article 8(1). Where its conditions are not met, the second applies, namely one of the procedures in Article 32(3):

Internal control under module A is not open to critical products in any configuration. The relief for Free and open-source software does not help either, since Article 32(5) names only the Annex III categories.

When certification becomes compulsory

Article 8(1) empowers the Commission to require, by delegated act, a European cybersecurity certificate at assurance level at least “substantial”. Several conditions attach. A suitable scheme under Regulation (EU) 2019/881 must have been adopted and be available to manufacturers, and the Commission must assess the potential market impact and consult stakeholders, among them the European Cybersecurity Certification Group.

The assurance level required has to be proportionate to the cybersecurity risk and must take account of the intended purpose, including critical dependency on the product by essential entities. Under recital 47, a sensitive or critical environment may call for the highest level. Such acts must provide a transitional period of at least six months, unless imperative urgency justifies less.

The list itself is movable too. Article 8(2) lets the Commission add or withdraw categories; there is no moving between classes, because Annex IV has none. The same six-month minimum applies to those acts, and stakeholders are consulted beforehand under Article 9.

What this means for planning

The Regulation applies from 11 December 2027. Chapter IV on the notification of conformity assessment bodies (Articles 35–51) applies from 11 June 2026, so that bodies are designated in time.

For critical products that is precisely the bottleneck. Anyone who needs a Notified body or a conformity assessment body under a certification scheme depends on its capacity. Scheduling should therefore start well before 11 December 2027 rather than from it.

Practical questions

This glossary is for orientation and does not constitute legal advice. The wording of Regulation (EU) 2024/2847 prevails.