Annex III, Class I (13)–(14)
Microprocessors and microcontrollers with security-related functionalities
Secure MPUs & MCUs are important product, class i under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. Hardware security features are the root of trust for everything built on the chip. Flaws are expensive or impossible to patch once silicon ships.
Updated 2026-09-12 · Operational guidance, not legal advice.
- Classification
- Important product — Class I
- Conformity route
- Self-assessment only with fully applied standards
- Reference
- Annex III, Class I (13)–(14) · Art. 32(2)
What the annex says
Microprocessors with security-related functionalities; microcontrollers with security-related functionalities.
Paraphrase of Annex III, Class I (13)–(14); the Official Journal text governs.
Typical products in this category
- MCUs with hardware crypto accelerators, secure boot or trusted execution
- Application processors with TrustZone-class isolation
- Automotive and industrial MCUs marketed for security functions
Where the boundary runs
General-purpose MCUs without security-related functionality are default products. Tamper-resistant microprocessors and microcontrollers are Class II, and smartcards and secure elements are Annex IV critical.
The test is core functionality (Article 7). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.
Conformity assessment
Self-assessment only with fully applied standards. Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). (Art. 32(2))
What to prepare operationally
- The 'product' includes firmware, SDKs and reference implementations you ship; keep SBOMs for them.
- Document errata and mitigations as security advisories with clear applicability per part number.
- Coordinate disclosure with downstream device manufacturers who must in turn assess their own products.
- Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.
Frequently asked
- Is every secure mpus & mcus product an important product — class i?
- Only where the listed function is the product's core functionality (Article 7). General-purpose MCUs without security-related functionality are default products. Tamper-resistant microprocessors and microcontrollers are Class II, and smartcards and secure elements are Annex IV critical.
- What changes compared with a default product?
- Module A is permitted only where harmonised standards, common specifications or a European cybersecurity certification scheme are applied in full; otherwise EU-type examination (Module B) followed by conformity to type (Module C), or full quality assurance (Module H). The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
- From when?
- Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.