Annex IV (1)

Hardware devices with security boxes

Hardware security boxes are critical product under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. Annex IV lists products whose compromise would have systemic effects on critical infrastructure or trust services. The Commission may require European cybersecurity certification for them by delegated act.

Updated 2026-09-12 · Operational guidance, not legal advice.

Classification
Critical product
Conformity route
European certification may become mandatory
Reference
Annex IV (1) · Art. 8, Art. 32(4)

What the annex says

Hardware Devices with Security Boxes.

Paraphrase of Annex IV (1); the Official Journal text governs.

Typical products in this category

  • Hardware security modules (HSMs)
  • Payment terminals with secure enclosures
  • Key-management appliances

Where the boundary runs

Until a delegated act mandates a certification scheme, Annex IV products follow the Class II conformity routes. The category concerns the physical security enclosure and its integrated functions, not every server with a locked case.

The test is core functionality (Article 8). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.

Conformity assessment

European certification may become mandatory. Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. (Art. 8, Art. 32(4))

What to prepare operationally

  1. Track delegated acts under Article 8; certification requirements may change the conformity route.
  2. Maintain the technical file to Common Criteria or FIPS-style depth; it will be read.
  3. Prepare for Article 14 reporting with the key-compromise scenario pre-analysed.
  4. Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.

Frequently asked

Is every hardware security boxes product an critical product?
Only where the listed function is the product's core functionality (Article 8). Until a delegated act mandates a certification scheme, Annex IV products follow the Class II conformity routes. The category concerns the physical security enclosure and its integrated functions, not every server with a locked case.
What changes compared with a default product?
Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
From when?
Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.

Other critical product categories

Classify it in Vellaci — with reasoning on record.

The onboarding classifier asks which listed functions your product provides and whether they are core, cites the annex, and stores the approved decision on the product.