Annex IV of the EU Cyber Resilience Act identifies Critical Products - those whose compromise would have the most severe societal or infrastructure impact. Products in Annex IV take the most rigorous conformity route: a European cybersecurity certification scheme where the Commission has mandated one, and otherwise the third-party routes that apply to Annex III Class II. These products cannot self-certify under any circumstance.
What Makes a Product 'Critical' Under the CRA?
Critical products are those whose cybersecurity failure could have the most severe systemic impact - affecting critical infrastructure, large populations, or fundamental societal functions. Annex IV is a closed list of three categories:
- Hardware devices with security boxes - HSMs (Hardware Security Modules), secure cryptoprocessors, trusted execution environments
- Smart meter gateways - Gateways within smart metering systems as defined in the Electricity Market Directive, and other devices for advanced security purposes including secure cryptoprocessing
- Smartcards and similar devices - Including secure elements
Anything outside those three is not Annex IV. Industrial control systems, automotive microcontrollers, and tamper-resistant microprocessors are not critical products under the CRA. Tamper-resistant microprocessors and microcontrollers sit in Annex III Class II, and the Commission can add categories to either annex by delegated act.
Conformity Assessment for Critical Products
Article 32(4) sets the route for Annex IV Critical Products, and it has two branches:
- Where the Commission has mandated certification - by delegated act under Article 8(1), the manufacturer must demonstrate conformity through a European cybersecurity certification scheme at assurance level at least substantial
- Where no such scheme is mandated or available - the manufacturer uses the same third-party routes as Annex III Class II: EU type-examination followed by conformity to type (Module B + C), or full quality assurance (Module H)
Self-assessment under Module A is unavailable in both branches. Where a notified body is involved it must be designated for the CRA and for the relevant product category.
No delegated act mandating a certification scheme has been adopted yet, so in practice a Critical product today follows the Class II routes. Plan for the scheme requirement to arrive, because it changes the evidence and the lead time.
Timeline and Cost Implications
Third-party conformity assessment for Annex IV products can take 6–18 months and cost significantly more than other conformity routes. For manufacturers whose products may be classified as Critical:
- Start notified body engagement immediately - lead times are long and capacity is limited
- Budget for iterative testing - the first examination often identifies non-conformities requiring remediation and re-test
- Allow time for documentation review - notified bodies will scrutinise the security risk assessment, technical file, and vulnerability management processes
Conformity is due by 11 December 2027, when the CRA applies in full. Working back from that date with a 6-18 month assessment, and with the Article 14 reporting duty already live from 11 September 2026, a Critical-product manufacturer that has not yet engaged a notified body is behind.
Reading the categories after the Commission guidance
The technical descriptions of the categories are set out in Commission Implementing Regulation (EU) 2025/2392. Commission guidance C(2026) 5252 explains how to apply them.
A product belongs to a category where it has the core functionality of that category, meaning its main features and technical capabilities without which it could not meet its intended purpose. A product has only one core functionality for classification purposes, and it must be identified in the technical documentation.
Additional functions do not change the classification, and merely integrating a listed product does not pull the host product into the category. A smartphone that contains an operating system does not thereby have the core functionality of an operating system.
Where a product substantially exceeds or substantially falls short of a category, it is outside it. Security orchestration, automation and response software generally exceeds the SIEM category, because incident response forms a core part of its capabilities. A log collection and visualisation tool that performs no correlation and provides no actionable security insight falls short of it. This is judged objectively on the product's actual technical characteristics rather than on how it is marketed.
Where the manufacturer also offers modules of an integrated product separately, for separate purchase, licensing or subscription, each module is a standalone product classified on its own core functionality. A suite sold with separately available SIEM, intrusion detection and analytics modules yields a class I product, a class II product and a default-category product respectively.
CVD Portal helps you comply with Annex IV automatically.
Public submission portal, 48-hour acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Start your free portalFrequently asked
What happens if my product falls into both Annex III and Annex IV?+
If a product meets the criteria for Annex IV Critical classification, that classification takes precedence over Annex III Important classification, and the Article 32(4) route applies.
Are HSMs used in cloud infrastructure covered by Annex IV?+
HSMs (Hardware Security Modules) are explicitly listed as critical products in Annex IV. Cloud-delivered HSM services (HSM as a Service) may be outside CRA scope as a cloud service, but physical HSM appliances sold to customers are in scope.
Need a CVD policy that satisfies Annex IV?
Download a free CRA-compliant template and deploy it in minutes.