IV

Annex IV

CRITICAL PRODUCTS WITH DIGITAL ELEMENTS

Regulation (EU) 2024/2847 — published 10 December 2024 · Last reviewed by Kunnus: March 2026

1.

Hardware Devices with Security Boxes

2.

Smart meter gateways within smart metering systems as defined in Article 2, point (23) of Directive (EU) 2019/944 of the European Parliament and of the Council (1) and other devices for advanced security purposes, including for secure cryptoprocessing

3.

Smartcards or similar devices, including secure elements

(1)

Directive (EU) 2019/944 of the European Parliament and of the Council of 5 June 2019 on common rules for the internal market for electricity and amending Directive 2012/27/EU (OJ L 158, 14.6.2019, p. 125).

European Commission Interpretation

Guidance of 27 July 2026

The EU Commission guidance of 27 July 2026 provides official interpretation notes on this provision. Each section: summary, key takeaways, and what it means for you in practice.

Section 6.1Core functionality — the key to product classification

Whether a product is 'important' (Annex III) or 'critical' (Annex IV) is determined solely by its core functionality — the main features without which it could not meet its intended purpose. Ancillary functions and integrated components do not change the classification; every product has exactly one core functionality, to be clearly identified in the technical documentation.

Key takeaways

  • Integration is not classification: a smartphone integrating an operating system does not have the core functionality of an operating system (Example 58).
  • Substantially exceeding or falling short of a category takes a product out of it: SOAR software is not a SIEM (Example 59), simple log collection tools without correlation are not either (Example 60).
  • No gaming via marketing: inconsistencies between promotional material, instructions and technical documentation may not be used to escape the stricter regime.
  • Modules of a product that are also marketed separately are classified individually (Example 61: security suite with SIEM, IDS and analytics modules).
  • The technical descriptions of the categories are laid down in Implementing Regulation (EU) 2025/2392.

In practice

Write one sentence per product: 'Without function X the product cannot meet its purpose.' X is the core functionality — match only X against the categories in Annex III/IV (or Implementing Regulation 2025/2392), not your feature list. Make sure marketing material, instructions and technical documentation tell the same story.

Section in the guidance overview
Section 6.2Conformity assessment for important and critical products

Class II and critical products require third-party assessment. Important class I products may use the internal control procedure (module A) where a relevant harmonised standard is applied in full and covers at least all risks associated with the core functionality — risks beyond that scope must be addressed through additional, documented measures.

Key takeaways

  • FOSS exception: important class I/II products placed on the market as FOSS may follow the default-category procedures (Art. 32(5)).
  • Antivirus with extra features (disk cleaning, anti-tracking): self-assessment is possible where the standard covers the core functionality's risks and additional risks are addressed and documented (Example 62).
  • An integrated critical component does not force the whole product into that component's stricter regime — the product's own core functionality remains decisive (Example 63: router integrating a firewall component).
  • Non-compliance with Art. 32 can trigger administrative fines under Art. 64(3).

In practice

For class I products, first check whether a harmonised standard covers all risks of the core functionality — that determines whether you may self-assess (module A) or need a notified body. Risks from additional functions outside the standard must be closed with your own documented measures. FOSS products of classes I/II may always self-assess.

Section in the guidance overview
Browse all guidance chapters

EU Commission Guidance (C(2026) 5252 final)The guidance reflects the European Commission's interpretation and is not legally binding. An authoritative interpretation of the EU CRA may only be given by the Court of Justice of the European Union.

This text is reproduced from Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024. It is provided for informational purposes only and does not constitute legal advice. Only the text published in the Official Journal of the European Union is legally binding. Original text on EUR-Lex