Critical products are a separate CRA category from Class I and Class II important products. They are listed in Annex IV and interpreted using Commission Implementing Regulation (EU) 2025/2392. Depending on the Article 8 certification framework, they use a European cybersecurity certification scheme or the stricter Article 32 procedures used for Class II products.
Critical Products Are Defined Through Article 8 and Annex IV
The CRA separates critical products from important products. Important products are governed by Article 7 and Annex III, while critical products are governed by Article 8 and Annex IV. The practical starting point is again core functionality. A manufacturer should first determine the product boundary and confirm that the product is within CRA scope. It then asks whether the product's core functionality matches one of the Annex IV categories using the technical descriptions provided by Commission Implementing Regulation (EU) 2025/2392. Critical classification is deliberately narrow. A product should not be described as critical merely because it is commercially important, used in a critical industry or considered high risk by the manufacturer. The CRA category depends on the legal list and the product's actual functionality.
- Article 8 addresses critical products.
- Annex IV contains the critical-product categories.
- Core functionality remains central.
- Commercial importance does not determine legal classification.
Annex IV Currently Contains Three Categories
Annex IV currently contains three categories. The first is hardware devices with security boxes. The second is smart meter gateways within smart metering systems as defined by the referenced electricity-market legislation and other devices for advanced security purposes, including for secure cryptoprocessing. The third is smartcards or similar devices, including secure elements. The list is much shorter than Annex III, reflecting the specialised nature of the critical-product framework. The names still need technical interpretation, which is why the 2025 implementing regulation matters. A manufacturer should map its product against the relevant technical description rather than assume that any tamper-resistant or cryptographic hardware automatically belongs in Annex IV.
- Hardware devices with security boxes.
- Smart meter gateways and certain advanced-security devices.
- Smartcards or similar devices including secure elements.
Hardware Devices With Security Boxes Have a Specific Technical Meaning
Commission Implementing Regulation (EU) 2025/2392 describes hardware devices with security boxes as hardware products with digital elements that securely store, process or manage sensitive data or perform cryptographic operations and that consist of multiple discrete components within a hardware physical envelope providing tamper evidence, resistance or response against physical attacks. The implementing regulation gives examples including physical payment terminals, hardware security modules that generate and manage cryptographic elements, and tachographs where they meet the description. These examples help illustrate the category, but they do not replace the functional test. A manufacturer should examine physical architecture, tamper protections, cryptographic role and the complete product boundary before reaching a classification conclusion.
- Look for secure handling of sensitive data or cryptographic operations.
- Consider the multi-component hardware construction.
- Examine the physical tamper-protection envelope.
- Use examples as illustrations rather than a closed list.
Smart Meter Gateways and Advanced Security Devices Form the Second Category
The second Annex IV category combines smart meter gateways with other devices for advanced security purposes, including secure cryptoprocessing. For smart meter gateways, the implementing regulation focuses on products that control communication between components in or connected to smart metering systems and authorised third parties such as utility providers. The wider advanced-security wording means classification should not stop with the product name. Manufacturers of cryptographic or specialised security devices should examine the implementing regulation's technical description and determine whether the product's core functionality fits the category. Products that merely use cryptography as one ordinary security control are not automatically Annex IV critical products. The legal question concerns the product's defining advanced-security function.
- Smart meter gateways have a defined communications-control role.
- The category also reaches specified advanced-security devices.
- Secure cryptoprocessing can be relevant.
- Ordinary use of cryptography does not alone determine classification.
Smartcards and Secure Elements Form the Third Critical Category
The third Annex IV category covers smartcards or similar devices, including secure elements. These products can provide trusted storage, processing and cryptographic functions inside wider systems. The classification of the component itself should be kept separate from the classification of a larger product into which it is integrated. A secure element installed inside another device can have its own CRA classification while the larger product still needs its own core-functionality assessment. This distinction avoids treating every connected device containing a secure element as an Annex IV critical product. Manufacturers and integrators should maintain component identity, supplier information, product boundaries and classification conclusions so that the critical component can be handled correctly without automatically transferring its legal category to the complete system.
Article 8 Creates a Specific Certification Mechanism
Article 8 empowers the Commission to determine, through delegated acts and where the statutory conditions are satisfied, which products with the core functionality of an Annex IV category must obtain a European cybersecurity certificate under a European cybersecurity certification scheme. The required assurance level must be at least substantial and proportionate to the cybersecurity risk. The mechanism depends on an applicable certification scheme being adopted and available to manufacturers. Article 8 therefore should not be simplified into the statement that every Annex IV product automatically has the same certificate requirement in every circumstance. Compliance teams need to check the current delegated acts, certification schemes and assurance levels that apply to the exact product at the time of conformity assessment.
- Article 8 can make European cybersecurity certification mandatory.
- An applicable certification scheme must exist and be available.
- The required assurance level is at least substantial.
- Check current delegated acts before selecting the route.
Article 32 Provides the Critical-Product Conformity Route
Article 32(4) connects critical classification to conformity assessment. A critical product listed in Annex IV demonstrates conformity through a European cybersecurity certification scheme in accordance with Article 8(1), or, where the Article 8(1) conditions are not met, through one of the procedures available to Class II products under Article 32(3). Those procedures are EU-type examination under module B followed by conformity to EU-type under module C, full quality assurance under module H, or, where available and applicable, a European cybersecurity certification scheme at assurance level at least substantial. This creates a stricter assurance structure than the default CRA product route and makes classification, certification availability and conformity planning closely connected.
- Check first whether Article 8 certification applies.
- If Article 8 conditions are not met, Article 32(3) procedures apply.
- Plan external assessment and certification dependencies early.
- Keep the classification and selected conformity route separately documented.
Critical Does Not Mean the Same Thing as Class II
Critical products and Class II products can end up using similar assessment procedures, but they remain different legal categories. Class II belongs to Annex III and Article 7. Critical products belong to Annex IV and Article 8. The separate Article 8 certification mechanism is an important reason to preserve that distinction. A compliance inventory should therefore avoid a single high-risk classification field that combines Class II and critical products. It should record the Annex, category, technical description, core-functionality reasoning and applicable Article 32 route separately. This becomes especially important if future delegated acts change the certification requirements for Annex IV products without changing the Class II list.
- Class II is an important-product class.
- Critical is a separate Annex IV classification.
- Assessment routes can overlap.
- Certification rules can differ.
Maintain a Product-Specific Critical Classification Record
A critical-product record should identify the exact product and version, its product boundary, intended purpose, principal security functions, candidate Annex IV category and the corresponding description from Commission Implementing Regulation (EU) 2025/2392. It should then state whether any Article 8 delegated act and certification scheme applies and identify the Article 32 procedure selected. For components such as secure elements, the record should also explain the relationship between the classified component and the larger integrating product. Technical documentation, certification evidence, notified-body records and release controls can then reference the same classification record. This approach provides a repeatable basis for product changes and future legal updates rather than relying on an informal statement that the product is critical.
- Identify the Annex IV category.
- Reference the 2025/2392 technical description.
- Check current Article 8 certification measures.
- Record the Article 32 route.
- Separate component and host-product classification.
- Review the conclusion when functionality or law changes.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.