CEMarque

What are "critical products" under the Cyber Resilience Act?

Last verified 19 September 2026 · Facts v2026.09.4

The critical tier is the narrowest in the Regulation: the three categories listed in Annex IV [1]. They are hardware devices with security boxes, smart meter gateways within smart metering systems, and smartcards or similar devices including secure elements [1].

Read that list again before worrying: it is hardware security infrastructure. If you make software, you are almost certainly not here. If you make consumer or business hardware without a dedicated secure element or security box, you are almost certainly not here either. The binding technical descriptions in the implementing regulation define each category, and classification runs on those descriptions [2].

What critical status changes

A critical product uses a European cybersecurity certification scheme where one covering it is available; where no such scheme is available, it falls back to the class II procedures — EU-type examination plus internal production control, full quality assurance, or a scheme at assurance level substantial [3] [4].

The distinctive feature of the critical tier is that mandatory certification under a European scheme can be switched on for these categories once schemes exist, which is a stronger instrument than the module-based assessment everything else uses [3]. Until such a scheme covers your category, the practical work is the same as class II: third-party assessment, with the same capacity timeline pressure before full application on 11 December 2027 [5] [3].

Common false alarms

Three products regularly self-diagnose as critical and are not.

Payment or identity apps. A mobile app that uses the phone's secure element is not itself a smartcard or secure element; the category is the hardware [1]. IoT devices generally. An ordinary connected device without a security box is not in the hardware-devices-with-security-boxes category; that category is about devices whose function is protecting other assets in a hardened enclosure [1]. Energy monitoring software. The category is smart meter gateways within smart metering systems — a specific piece of regulated metering infrastructure, not any product that reads energy data [1].

The pattern in all three: the critical categories name hardware whose purpose is security or regulated metering, per the binding descriptions [2]. Proximity to that hardware does not transfer the classification.

If you really are here

Then classification is the least of your work, and sequencing is everything: scheme availability for your category, notified-body capacity as the fallback route, and the documentation stack underneath both. Start from a precise reading of your category's technical description [2].

Check where you stand

The checker matches your product against the binding category descriptions [2] and tells you the route that is actually open today, with citations.

What to do next

Run your own product through the checker — it takes under a minute and gives you a dated, citable result you can send to a customer.

Check my product

Sources

  1. Annex IV — critical products (items 1–3). Annex IV; Implementing Regulation (EU) 2025/2392EUR-Lex
  2. Commission Implementing Regulation (EU) 2025/2392 provides technical descriptions of the Annex III and Annex IV product categories (in force 21 December 2025); the class matcher uses those descriptions, not shorthand labels. Implementing Regulation (EU) 2025/2392; Art. 7(4)EUR-Lex
  3. Conformity routes: default products may use internal control (Module A), EU-type examination plus internal production control (Modules B+C), full quality assurance (Module H) or a European cybersecurity certification scheme; important class I must use B+C or H (or a scheme at 'substantial' level) unless harmonised standards, common specifications or such a scheme are applied in full; important class II must use B+C, H or a scheme at 'substantial' level; critical products use a European scheme where available, otherwise the class II procedures. Art. 32(1)–(4), Annex VIIIEUR-Lex
  4. Annex III Class II — important products, class II (items 1–4). Annex III Class II; Implementing Regulation (EU) 2025/2392EUR-Lex
  5. The Regulation applies in full from 11 December 2027. Art. 71(2)EUR-Lex

Related

  • Does my product need third-party assessment under the CRA?

    Most products, no — default products self-assess under Module A. A notified body enters only for important class I products not applying standards in full, for class II, and for critical products without a certification scheme.

  • Is my product an important product class II under the CRA?

    Class II is the higher "important" tier — hypervisors, firewalls, tamper-resistant microprocessors and similar security-critical categories — and it removes self-assessment entirely: a notified body or certification scheme is mandatory.

  • Is my product an important product class I under the CRA?

    Class I is the first tier of "important" products — 19 categories including password managers, VPNs, browsers and smart home assistants — and it changes which conformity route you may use, not whether you are in scope.

  • What goes in a CRA declaration of conformity?

    A one-document statement, in the Annex V structure, in which the manufacturer takes sole responsibility that the product meets the essential requirements. A simplified web-linked form exists, and it travels with the product's paperwork for a decade or more.

CEMarque encodes Regulation (EU) 2024/2847 and the European Commission's published guidance as of 10 September 2026 (Facts v2026.09.4). It is not legal advice. Verify obligations for your product with qualified counsel where the stakes require it.