Yes. Identity management and privileged access management are Annex III Class I, so an IAM or PAM product is an important product with digital elements. The category explicitly covers hardware as well as software, including biometric readers.
Identity management systems and privileged access management software and hardware, including authentication and access control readers, including biometric readers
Annex III, Class I, point 1, Regulation (EU) 2024/2847
The category names hardware readers outright, so an access-control or biometric reader is in it even though nothing about the product looks like software.
A password manager is its own category (point 3), not a sub-type of IAM. Same class, so the conformity route is identical - but the report should cite the point that actually applies.
Issuing certificates is point 9. A PAM product that stores SSH keys is still point 1; a product whose job is to mint X.509 certificates is point 9.
The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.
Indicative assessment - not legal advice and not a conformity assessment.