Annex IV (3)
Smartcards and similar devices, including secure elements
Smartcards & secure elements are critical product under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. Secure elements anchor payment, identity and telecom trust for the whole population; the Commission may mandate European certification for them.
Updated 2026-09-12 · Operational guidance, not legal advice.
- Classification
- Critical product
- Conformity route
- European certification may become mandatory
- Reference
- Annex IV (3) · Art. 8, Art. 32(4)
What the annex says
Smartcards or similar devices, including secure elements.
Paraphrase of Annex IV (3); the Official Journal text governs.
Typical products in this category
- Payment and identity smartcards
- Embedded secure elements in phones and IoT devices
- SIM/eSIM secure elements
Where the boundary runs
Tamper-resistant microcontrollers without the smartcard/secure-element role are Class II. The card operating system and applets are part of the product.
The test is core functionality (Article 8). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.
Conformity assessment
European certification may become mandatory. Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. (Art. 8, Art. 32(4))
What to prepare operationally
- Existing Common Criteria certifications are the natural basis; monitor the EUCC scheme's adoption under the CRA.
- SBOMs for card OS and applets are small but mandatory; maintain them per mask/release.
- Coordinate disclosure with issuers and scheme operators; publication timing is sensitive.
- Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.
Frequently asked
- Is every smartcards & secure elements product an critical product?
- Only where the listed function is the product's core functionality (Article 8). Tamper-resistant microcontrollers without the smartcard/secure-element role are Class II. The card operating system and applets are part of the product.
- What changes compared with a default product?
- Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
- From when?
- Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.