CRA compliance for Smart home gateway / hub
All other products (default class)
About CRA compliance for Smart home gateway / hub
A smart home gateway aggregates a local network of connected devices, runs the firmware that brokers control commands, and often exposes a remote access surface. Because it sits between the local network and the internet, its security posture directly affects every device behind it. CRA documentation for a gateway therefore starts from the gateway's own components and update mechanism, and covers the remote-access surface explicitly.
What the All other products (default class) means for this product
The Cyber Resilience Act applies to a wide range of products with digital elements. Products that are not on the Annex III (important) or Annex IV (critical) lists fall under the default class. Conformity is typically assessed under Module A, the manufacturer's internal control, without a notified body. The full set of Annex VII technical documentation, an EU Declaration of Conformity and the Annex I requirements still apply.
Where this device type sits in the Regulation
In the Regulation's own structure, 'smart home products with security functionalities, including smart home gateways, smart home hubs and smart home central points of control' are named in Annex III Class I (Regulation (EU) 2024/2847, Art. 32(2)). Whether THIS specific gateway has such security functionalities and therefore falls in that named category is the manufacturer's guided questionnaire answer, never an assumption of this site.
Conformity assessment
Module A (internal control, self-assessment)
Annex III / IV structure
Not listed in Annex III or Annex IV (Regulation (EU) 2024/2847, Art. 32(1)(a))
Products in this class are those NOT named in Annex III or Annex IV:
- No categories from Annex III or Annex IV are named for this class.
This is the Regulation's own structure (Regulation (EU) 2024/2847, Art. 32(1)(a)): everything that is not named in Annex III or Annex IV sits here. Whether a particular product is actually excluded from those annexes is the manufacturer's guided questionnaire answer, never an assumption of this site.
Key obligations
- Annex VII technical documentation for the product and its vulnerability handling
- EU Declaration of Conformity (Annex V) under the sole responsibility of the manufacturer
- Annex I essential requirements: secure by default, update mechanism, access control, data protection, incident resilience
- Annex I Part II vulnerability handling: SBOM, CVD policy, security contact, coordinated vulnerability disclosure
- Support period determination per Article 13(8) and support-period information
- Reporting actively exploited vulnerabilities and severe incidents per Article 14
Typical components to document (SBOM)
Zigbee / Matter stackMQTT brokerLinux kernel / RTOSWeb/control APITLS library
Relevant Annex I requirements
I.2(d)— protect the remote access surface and the local devices behind itI.2(c)— automated, user-notified security updates for the gateway firmwareI.2(e)— encrypt control traffic and stored configurationII.7— secure distribution of updates to the gateway fleet
Get the compliance document set
Annex VII technical documentation, EU DoC and the Annex I checklist, generated from your product's SBOM. Leave an email and we will send it when the generator is open.