CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Worked example · Critical infrastructure

Critical - the highest route, and the honest limit of what we do

A metering infrastructure vendor supplying utilities and grid operators

Worked example - a product archetype run through the CRASPACE rulebook. Not a client engagement, and not a conformity assessment.

The verdict

CRA scope
In scope
Class
Critical
Basis
Annex IV
Conformity route
Notified body and potentially a mandatory EU cybersecurity certificate at assurance level 'substantial' or higher

Descriptor matched: Smart meter gateway; hardware security module / secure element

The products assessed

  • Smart meter gatewaySmart metering · cellular, PLC, cloud, firmware
  • Hardware security moduleSecure element · firmware, API

Why it lands there

  1. Annex IV is the narrowest and highest-assurance list in the regulation - the products where a security failure has the widest blast radius. Smart-meter gateways and hardware security modules are both on it.
  2. The route is a notified body assessment plus the possibility of a mandatory EU cybersecurity certificate under the Cybersecurity Act scheme, at assurance level 'substantial' or above. That is a materially longer and more formal programme than anything in the Important tiers.
  3. Two Annex IV products in one portfolio do not share one assessment. The gateway and the HSM are separate products with separate technical files.
  4. This is also the archetype where the timeline is least forgiving: certification schemes have their own lead times, layered on top of notified-body capacity.

What follows from it

  • Everything in the Important Class II list, plus:
  • A notified body assessment against the Annex IV route
  • Potentially an EU cybersecurity certificate at assurance level 'substantial' or higher
  • Documentation and evidence built to certification-scheme standards from the start - retrofitting it is the expensive path

The trap on this one

The trap on this one is choosing a supplier who is not honest about the boundary. Annex IV needs a notified body and, potentially, a certificate. Any provider implying they can deliver the certificate themselves - unless they are the accredited body - is describing something they cannot do.

The questions this leaves open

A public-evidence scan cannot answer these. They are what a consultation is for, and they are deliberately questions rather than instructions.

  • Which certification scheme and assurance level will actually be required for this product, and what is its current queue?
  • Are the gateway and the HSM being planned as one programme, when the regulation treats them as two products with two technical files?
  • What already exists from previous grid or metering certifications that can be reused as evidence rather than rebuilt?

The realistic next step

This is where CRASPACE hands off rather than sells. We are not a notified body and we do not issue CRA certificates for Critical / Annex IV products. What we can do is guidance and pre-assessment - getting the evidence base and the technical file ready - and point you to an accredited certification body for the assessment itself. Any route description that claims more than that is wrong.

This is an archetype. Yours is not. Run the check against your own company and get the same reasoning applied to the products you actually ship, each with a source you can open.