CRASPACE
Scanning · scope · class · risk
CRASPACE
30 min with a CRA specialist - your classification confirmed against real specs, your open questions closed. Free, no obligation.Rulebook v0.5.1Full compliance 11 Dec 2027
Annex III, Class II, point 3 / Annex III, Class II, point 4

Are tamper-resistant microcontrollers Class II under the CRA?

Yes. Annex III Class II points 3 and 4 cover tamper-resistant microprocessors and microcontrollers, so a notified body is mandatory. Implementing Regulation (EU) 2025/2392 defines them as designed to provide protection of AVA_VAN level 2 or 3.

ClassImportant - Class II
What that class requiresThird-party (notified body) assessment mandatory

The category, quoted in full:

Tamper-resistant microprocessors

Annex III, Class II, point 3, Regulation (EU) 2024/2847

Tamper-resistant microcontrollers

Annex III, Class II, point 4, Regulation (EU) 2024/2847

AVA_VAN is what separates these two points from Class I points 13 and 14 above them and from Annex IV point 3 below: no designed tamper resistance is Class I, level 2 or 3 is Class II, and at least AVA_VAN.4 is a secure element under Annex IV. Being able to evidence the level a part was designed for is what decides whether a third party must be involved.

Frequently confused with:

  • Microprocessors with security-related functionalitiesImportant - Class I

    Class I points 13 and 14 cover the same two product types with security-related functionalities but no designed AVA_VAN 2-3 resistance. This is the boundary most often read too strictly, which over-states the burden - and it is decided by the designed resistance level, not by whether the datasheet uses the word secure. A part marketed as a secure microcontroller is therefore Class I here until a designed level says otherwise.

  • Smartcards or similar devices, including secure elementsCritical

    Annex IV point 3 is a class above, and the step up is AVA_VAN.4: a part designed for at least that level is a secure element. Note that being Annex IV does not by itself add a certificate today - absent an Article 8(1) delegated act it takes the same Article 32(3) procedures as Class II.

Obligations that apply to every product in scope, whatever its class:

  • Essential requirements (Annex I) - secure by design & default
  • Machine-readable SBOM
  • Coordinated vulnerability disclosure policy
  • Security updates across support period (~5 yrs)
  • Technical documentation (Annex VII)
  • Conformity assessment (route depends on class)
  • CE marking + EU Declaration of Conformity
  • 24h / 72h reporting to ENISA + CSIRT (from Sep 2026)

What a manufacturer is assessed against:

  1. Cybersecurity risk assessment Art 13(2)
  2. Secure-by-design essential requirements Annex I Pt I
  3. Vulnerability-handling process Annex I Pt II
  4. Software bill of materials (SBOM) Annex I Pt II §1
  5. Coordinated vulnerability disclosure policy Art 13 · Annex I Pt II
  6. Security updates & support period Art 13(8)
  7. Technical documentation (Annex VII) Annex VII
  8. Conformity assessment & EU Declaration of Conformity Art 28 · Annex V
  9. CE marking Art 30
  10. Vulnerability & incident reporting readiness Art 14 (from 11 Sep 2026)
  11. Economic-operator & market-surveillance obligations Art 13/19–24 · Annex II

The dates that matter:

  • 11 September 2026 - reporting obligations for actively exploited vulnerabilities and severe incidents apply.
  • 11 December 2027 - full compliance applies.
  • Market-surveillance authorities can order corrective action, withdrawal or recall, and fines reach €15 million or 2.5% of global annual turnover.

Check your own products against this

The same rulebook that produced this page runs the free check. It reads your products, classifies each one against Annex III and IV, and gives you an indicative verdict with the reasoning and citation for every product.

All categories