CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Annex IV, point 1

Does a hardware security module need a certificate under the CRA?

Yes, as a critical product. Annex IV point 1 covers hardware devices with security boxes. Today that means the Article 32(3) procedures - the same as Class II - because the certificate the critical class is known for becomes mandatory only once the Commission adopts a delegated act for the category.

ClassCritical
What that class requiresArt 32(3) procedures (as Class II) - plus an EU cybersecurity certificate at assurance ≥ substantial IF the Commission adopts a delegated act under Art 8(1) for the category

The category, quoted in full:

Hardware Devices with Security Boxes

Annex IV, point 1, Regulation (EU) 2024/2847

Article 8(1) empowers the Commission to require an EU cybersecurity certificate at assurance level at least substantial for an Annex IV category, and its final subparagraph says that where no such delegated act has been adopted the product takes the Article 32(3) procedures instead. None has been adopted. Being critical does not currently add a certificate - it means the Commission may add one, with a transitional period of at least six months.

Frequently confused with:

  • Smartcards or similar devices, including secure elementsCritical

    Secure elements are Annex IV point 3, and are defined by a designed AVA_VAN.4 resistance level. Both points are critical and both take the same route, so the practical answer matches - but they are different categories and an HSM is not a smartcard.

  • Tamper-resistant microprocessorsImportant - Class II

    A tamper-resistant microprocessor or microcontroller on its own is Annex III Class II. Packaging it as a hardware device with a security box moves it to Annex IV point 1 - a different category, though on the current route the procedures are the same.

Obligations that apply to every product in scope, whatever its class:

  • Essential requirements (Annex I) - secure by design & default
  • Machine-readable SBOM
  • Coordinated vulnerability disclosure policy
  • Security updates across support period (~5 yrs)
  • Technical documentation (Annex VII)
  • Conformity assessment (route depends on class)
  • CE marking + EU Declaration of Conformity
  • 24h / 72h reporting to ENISA + CSIRT (from Sep 2026)

What a manufacturer is assessed against:

  1. Cybersecurity risk assessment Art 13(2)
  2. Secure-by-design essential requirements Annex I Pt I
  3. Vulnerability-handling process Annex I Pt II
  4. Software bill of materials (SBOM) Annex I Pt II §1
  5. Coordinated vulnerability disclosure policy Art 13 · Annex I Pt II
  6. Security updates & support period Art 13(8)
  7. Technical documentation (Annex VII) Annex VII
  8. Conformity assessment & EU Declaration of Conformity Art 28 · Annex V
  9. CE marking Art 30
  10. Vulnerability & incident reporting readiness Art 14 (from 11 Sep 2026)
  11. Economic-operator & market-surveillance obligations Art 13/19–24 · Annex II

The dates that matter:

  • 11 September 2026 - reporting obligations for actively exploited vulnerabilities and severe incidents apply.
  • 11 December 2027 - full compliance applies.
  • Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.

Check your own products against this

The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.

All categories