Critical products

The list (Annex IV)

  • Hardware devices with security boxes — hardware security modules, cryptographic safes.
  • Smart meter gateways within smart metering systems as defined in Directive (EU) 2019/944, and other devices for advanced security purposes, including for secure cryptoprocessing.
  • Smart cards or similar devices, including secure elements.

The list is short and deliberately restrictive: it targets components whose compromise degrades the security of everything built on them.

The reinforced regime

Critical products first follow the class II regime — notified body mandatory, modules B+C or H.

On top of that sits a specific empowerment: the Commission may require, by delegated act, that a European cybersecurity certificate be obtained under a scheme adopted pursuant to Regulation (EU) 2019/881 — typically the EUCC scheme — at assurance level at least “substantial”.

That requirement is triggered category by category, according to the level of risk and the availability of a suitable scheme. Tracking the delegated acts is therefore essential for any affected manufacturer: it is a standing item in updates.

What that changes in practice

Class II Critical with EUCC requirement
Assessor Notified body Evaluation laboratory (ITSEF) accredited under the scheme
Input deliverable Technical documentation Security target, description of mechanisms, design evidence
Method Type examination or quality audit Evaluation under the scheme’s methodology, close to Common Criteria
Typical duration A few months Often more than a year for a first pass
Cost Significant Substantially higher
Maintenance Certificate extension Certificate maintenance, reassessment at each evolution

Consequences for the roadmap

For a critical product, CRA compliance is not a documentation exercise: it is a security engineering programme to be launched well ahead of the application date, with:

  • a certification lead appointed, distinct from the product manager;
  • the security target drafted early and the environmental assumptions identified;
  • the evaluation laboratory selected and contracted;
  • the product roadmap aligned with evaluation windows, including a freeze on changes during critical phases;
  • the maintenance of the certificate budgeted, not only its issuance.

To put to the committee. For a critical product the question is not “how do you comply?” but “does this product stay in the portfolio given the recurring cost of certification?”. That is a portfolio decision, not a compliance decision, and it must be taken explicitly.