Article 6 + Annex III defines Important PDEs (Class I and Class II) including identity-management systems, password managers, browser plug-ins, operating systems, microcontrollers with security functionality, routers/modems/switches, network management systems, and similar critical infrastructure components. Article 7 + Annex IV defines Critical PDEs including hardware devices with security boxes, smart-meter gateways with cybersecurity functionality, and smartcards with security elements. Important PDEs trigger third-party conformity assessment by a notified body (Module B+C or Module H per Article 32). Critical PDEs require mandatory European cybersecurity certification under (EU) 2019/881.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.