Annex IV (3)

Smartcards and similar devices, including secure elements

Smartcards & secure elements are critical product under Regulation (EU) 2024/2847 when the listed function is the product's core functionality. Secure elements anchor payment, identity and telecom trust for the whole population; the Commission may mandate European certification for them.

Updated 2026-09-12 · Operational guidance, not legal advice.

Classification
Critical product
Conformity route
European certification may become mandatory
Reference
Annex IV (3) · Art. 8, Art. 32(4)

What the annex says

Smartcards or similar devices, including secure elements.

Paraphrase of Annex IV (3); the Official Journal text governs.

Typical products in this category

  • Payment and identity smartcards
  • Embedded secure elements in phones and IoT devices
  • SIM/eSIM secure elements

Where the boundary runs

Tamper-resistant microcontrollers without the smartcard/secure-element role are Class II. The card operating system and applets are part of the product.

The test is core functionality (Article 8). Record the reasoning and the approver: the category determines the conformity assessment route and market surveillance authorities can challenge it.

Conformity assessment

European certification may become mandatory. Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. (Art. 8, Art. 32(4))

What to prepare operationally

  1. Existing Common Criteria certifications are the natural basis; monitor the EUCC scheme's adoption under the CRA.
  2. SBOMs for card OS and applets are small but mandatory; maintain them per mask/release.
  3. Coordinate disclosure with issuers and scheme operators; publication timing is sensitive.
  4. Maintain an SBOM per released version, match it continuously against vulnerability intelligence, and keep the Article 14 runbook rehearsed — these apply to every product with digital elements, listed or not.

Frequently asked

Is every smartcards & secure elements product an critical product?
Only where the listed function is the product's core functionality (Article 8). Tamper-resistant microcontrollers without the smartcard/secure-element role are Class II. The card operating system and applets are part of the product.
What changes compared with a default product?
Where the Commission adopts a delegated act, a European cybersecurity certificate at assurance level at least 'substantial' is required; until then the Class II routes apply. The essential requirements of Annex I, the vulnerability-handling duties and Article 14 reporting apply to every product with digital elements regardless of category.
From when?
Article 14 reporting obligations have applied to all manufacturers since 11 September 2026. Conformity assessment and CE marking under the CRA apply from 11 December 2027; products placed on the market before that date are not required to be re-assessed unless substantially modified.

Other critical product categories

Classify it in Vellaci — with reasoning on record.

The onboarding classifier asks which listed functions your product provides and whether they are core, cites the annex, and stores the approved decision on the product.