Annex IV (1)
Hardware devices with security boxes
Hardware security boxes are critical product under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. Annex IV lists products whose compromise would have systemic effects on critical infrastructure or trust services. The Commission may require European cybersecurity certification for them by delegated act.
Updated 2026-09-12 · Operational guidance, not legal advice.
- Classification
- Critical product
- Conformity route
- European certification may become mandatory
- Reference
- Annex IV (1) · Art. 8, Art. 32(4)
What the annex says
Hardware Devices with Security Boxes.
Paraphrase of Annex IV (1); the Official Journal text governs.
Typical products in this category
- Hardware security modules (HSMs)
- Payment terminals with secure enclosures
- Key-management appliances
Where the boundary runs
Until a delegated act mandates a certification scheme, Annex IV products follow the Class II conformity routes. The category concerns the physical security enclosure and its integrated functions, not every server with a locked case.
The test is core functionality (Article 8). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.
Conformity assessment
European certification may become mandatory. Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. (Art. 8, Art. 32(4))
What to prepare operationally
- Track delegated acts under Article 8; certification requirements may change the conformity route.
- Maintain the technical file to Common Criteria or FIPS-style depth; it will be read.
- Prepare for Article 14 reporting with the key-compromise scenario pre-analysed.
- Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.
Frequently asked
- Is every hardware security boxes product an critical product?
- Only where the listed function is the product's core functionality (Article 8). Until a delegated act mandates a certification scheme, Annex IV products follow the Class II conformity routes. The category concerns the physical security enclosure and its integrated functions, not every server with a locked case.
- What changes compared with a default product?
- Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
- From when?
- Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.