Press Release

The CRA's new chip categories, and why they don't change your class

Sep 8, 2026
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
,
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
,
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
No items found.

As the CRA steadily becomes a major influence in designing the next generation of embedded hardware, let’s take a look at a major regulation that will influence conformity assessments from 11 December 2027. In December 2025 the European Commission filled in a gap in the Cyber Resilience Act. Its implementing regulation (EU) 2025/2392 explain what the CRA's categories of important and critical products actually cover. Security chips are now defined precisely, and secure elements sit in the regulation’s critical tier.

If you build devices with a secure element inside, the reasonable first worry is that this drags your product up with it. It does not.

Your class follows your product, not your components

The implementing regulation is direct about this. Integrating a component that has the core functionality of an important product category does not in itself make your product subject to that component's conformity assessment procedure. Classification runs on your own core functionality. 

Let’s imagine we’re developing an industrial sensor gateway with a secure element holding the device keys. The secure element is a critical product. The gateway does not become critical because of it. But, the CRA lists product types that face more outside checking, and one entry covers routers, internet-facing modems and switches (Annex III, class I, point 12). A gateway routing traffic to the internet has a case for landing there. 

A device that only reads sensors and forwards telemetry has a case for the default tier, but the above two lines of description certainly will not settle which tier it really falls to. That call needs the technical description in the implementing regulation read against what your device actually does, and specialists disagree about devices near the boundary. A higher tier means more external checking, so it is worth getting right rather than assuming.

This is the whole point. Your own device’s functionality sets the tier. The passage that spares you a stronger component's conformity route also says you must evaluate the security of the whole product, taking into account the security of the components integrated into it. A comprehensive cybersecurity risk assessment also applies whatever tier you end up in.

Which raises a practical question. How do you assess what a secure element contributes to your product's risk posture?

This is where the number comes in

The new definitions sort security chips using AVA_VAN, a scale from Common Criteria that expresses how much effort it takes to break something. Chips with tamper protection designed to resist AVA_VAN level 2 or 3 are important, class II. Designed for at least AVA_VAN.4 and the chip is a secure element, which is critical. So a designed AVA_VAN level is the compact answer to what a chip was built to withstand. It is the input your risk assessment needs.

Each category describes a chip "designed to provide protection of" a level, so a level in a datasheet or marketing positioning can become a vendor's statement of intent. A level on a Common Criteria or EUCC certificate is an assessed finding. Those are different kinds of things and they are easy to confuse.

Ask which one you have been given, and if it is a certificate, ask for the AVA_VAN level rather than the assurance level, because EUCC's "high" covers AVA_VAN 3, 4 and 5 and so straddles the CRA's line at 4. EUCC certification is not currently mandatory under the CRA (although it’s possible the European Commission could add it as a requirement in the future), even for critical products, so plenty of parts will only have the first.

Where the CRA currently stands

None of this is finished. The technical descriptions themselves only arrived in December 2025. Harmonised standards for the CRA are still drafts, none cited in the Official Journal, so none of them yet give you a presumption of conformity. Whether critical products will end up needing mandatory certification is unresolved and waits on a delegated act. The Commission is still publishing guidance.

What has been settled since the CRA’s passage is that the essential requirements, conformity assessment and technical documentation obligations bite from 11 December 2027. This shows that starting the supplier conversation now rather than waiting for the picture to clear.

Also read

Blogs
CRA: Beyond the Chip

Read more
Blogs
We’re in This Together: Why Radical Transparency Makes CRA Reporting Easier

Read more
No items found.
Blogs
Who updates the security chip in an EV charging station?

Read more
Blogs
We’re in This Together: Why Radical Transparency Makes CRA Reporting Easier

Read more
Blogs
Reflections from TechWorks Semiconductor to Systems Summit: Why CRA Compliance Starts in Silicon

Read more

Get Tropic Square updates, blogs, and resources right to your mailbox

Subscribe to Tropic Square newsletter

For Technical Support

Talk to Technical Team

Get TROPIC01 Devboard

Order Devboard / Samples