Critical products
The list (Annex IV)
- Hardware devices with security boxes — hardware security modules, cryptographic safes.
- Smart meter gateways within smart metering systems as defined in Directive (EU) 2019/944, and other devices for advanced security purposes, including for secure cryptoprocessing.
- Smart cards or similar devices, including secure elements.
The list is short and deliberately restrictive: it targets components whose compromise degrades the security of everything built on them.
The reinforced regime
Critical products first follow the class II regime — notified body mandatory, modules B+C or H.
On top of that sits a specific empowerment: the Commission may require, by delegated act, that a European cybersecurity certificate be obtained under a scheme adopted pursuant to Regulation (EU) 2019/881 — typically the EUCC scheme — at assurance level at least “substantial”.
That requirement is triggered category by category, according to the level of risk and the availability of a suitable scheme. Tracking the delegated acts is therefore essential for any affected manufacturer: it is a standing item in updates.
What that changes in practice
| Class II | Critical with EUCC requirement | |
|---|---|---|
| Assessor | Notified body | Evaluation laboratory (ITSEF) accredited under the scheme |
| Input deliverable | Technical documentation | Security target, description of mechanisms, design evidence |
| Method | Type examination or quality audit | Evaluation under the scheme’s methodology, close to Common Criteria |
| Typical duration | A few months | Often more than a year for a first pass |
| Cost | Significant | Substantially higher |
| Maintenance | Certificate extension | Certificate maintenance, reassessment at each evolution |
Consequences for the roadmap
For a critical product, CRA compliance is not a documentation exercise: it is a security engineering programme to be launched well ahead of the application date, with:
- a certification lead appointed, distinct from the product manager;
- the security target drafted early and the environmental assumptions identified;
- the evaluation laboratory selected and contracted;
- the product roadmap aligned with evaluation windows, including a freeze on changes during critical phases;
- the maintenance of the certificate budgeted, not only its issuance.
To put to the committee. For a critical product the question is not “how do you comply?” but “does this product stay in the portfolio given the recurring cost of certification?”. That is a portfolio decision, not a compliance decision, and it must be taken explicitly.