Radio Equipment Directive Cybersecurity Compliance for Connected Products

The RED cybersecurity requirements have applied since 1 August 2025. If your product transmits or receives radio waves and connects to the internet, the obligation is live now — not when the Cyber Resilience Act arrives in 2027.

Radio Equipment Directive

What Is RED Delegated Act

Delegated Regulation (EU) 2022/30 activated three previously dormant provisions of the Radio Equipment Directive (RED) — Directive 2014/53/EU — that had sat unused since 2014. Articles 3(3)(d), (e) and (f) impose cybersecurity, privacy and anti-fraud requirements on defined categories of radio equipment, and they became applicable on 1 August 2025 after a one-year postponement to allow harmonised standards to be finalised.

This is not a new regulation. It is an existing directive with its cybersecurity provisions switched on, which is precisely why so many manufacturers have missed it. There was no legislative announcement, no new CE marking regime, and no separate compliance framework. The delegated act simply made three essential requirements applicable to equipment that was already subject to RED conformity assessment for radio and EMC purposes.

For manufacturers of connected products, the RED delegated act is not a future obligation. It reaches your product today if any of the following apply:

  • Internet-connected radio equipment of any kind — Wi-Fi, Bluetooth, cellular, LPWAN
  • Equipment processing personal data, traffic data or location data
  • Childcare equipment, toys and wearables with radio functionality
  • Equipment enabling transfer of money, monetary value or virtual currency
  • Products currently CE marked under RED for radio and EMC requirements only
  • Connected devices whose manufacturers are planning for CRA in 2027

If any of these describe your product, the requirements applied on 1 August 2025 and market surveillance authorities can act now.

Radio Equipment Directive Compliance Assessment for Your Product

Regulatory assessment of which essential requirements apply to your equipment — scope determination across Articles 3(3)(d), (e) and (f), harmonised standards applicability including the Official Journal restrictions, conformity route determination, notified body requirement analysis, CRA transition mapping, and a documented compliance record your notified body, enterprise buyers and market surveillance authorities can rely on.

How the Radio Equipment Directive works for connected products

Three essential requirements. Three different scopes. One conformity assessment that most manufacturers have already completed for the wrong requirements.

Radio Equipment Directive
Radio Equipment Directive

The delegated act organises its requirements across three essential requirements, each addressing a distinct harm and each reaching a different category of equipment. A product can fall within one, two or all three, and the scope determination drives everything that follows.

Article 3(3)(d) — Network protection

Internet-connected radio equipment must not harm the network or its functioning, and must not misuse network resources causing unacceptable degradation of service. The requirement addresses the risk that compromised devices are conscripted into botnets or otherwise used to damage the networks they connect to. Its scope is broad: any radio equipment that can communicate over the internet, directly or indirectly, falls within it regardless of what the product does. A connected sensor, a smart appliance and an industrial gateway are all in scope on the same terms.

Article 3(3)(e) — Personal data and privacy

Radio equipment must incorporate safeguards ensuring the protection of the personal data and privacy of users and subscribers. The scope is defined by what the equipment processes rather than by what it connects to: internet-connected equipment, equipment processing traffic data or location data, childcare equipment, toys, and wearables all fall within it. This is a product design requirement assessed through conformity assessment, not a data protection obligation. It sits alongside GDPR rather than replacing any part of it, and a manufacturer meeting one has not thereby discharged the other.

Article 3(3)(f) — Protection against fraud

Radio equipment must incorporate features ensuring protection from fraud, and this requirement reaches equipment enabling the holder or user to transfer money, monetary value or virtual currency. Payment terminals, wearables with payment functionality, and connected devices supporting in-device transactions fall within it. The scope is narrower than the other two requirements and is frequently over-applied by manufacturers who assume all three apply to every connected product.

Harmonised standards and the Official Journal restrictions

EN 18031-1, EN 18031-2 and EN 18031-3 correspond to the three essential requirements and were cited in the Official Journal in January 2025. This is the point where most compliance positions break down. The standards were cited with restrictions, meaning specified clauses do not confer a presumption of conformity — particularly around user-defined access controls and factory default passwords. A manufacturer that applies the standards in full may still lack a complete presumption of conformity, and therefore may still require notified body involvement. Reading the OJ citation rather than the standard itself is what determines your conformity route.

Conformity assessment and CE marking

The cybersecurity requirements are assessed through the same RED conformity assessment that already applies to your product. Where the harmonised standards are applied in full and the restrictions do not affect the product, internal production control under Module A is available. Where they are not applied, or where a restricted clause is material, EU-type examination by a notified body under Module B is required. Most manufacturers already hold a RED declaration of conformity covering radio and EMC requirements only — that declaration is now incomplete, and the technical file needs the cybersecurity evidence added to it.

Who Radio Equipment Directive applies to

The delegated act applies to manufacturers placing radio equipment on the EU market, with verification duties on importers and distributors. Non-EU manufacturers face the same obligations as EU-established ones.

Entity typeIn scope?Key obligation
Manufacturer of internet-connected radio equipmentYes — Article 3(3)(d)Network protection safeguards, conformity assessment, updated DoC
Manufacturer of wearables or connected toysYes — Articles 3(3)(d) and (e)Network and privacy safeguards regardless of internet connection
Manufacturer of payment-enabled devicesYes — Articles 3(3)(d), (e) and (f)All three requirements, including fraud protection
Manufacturer of equipment processing location dataYes — Article 3(3)(e)Privacy safeguards, assessed at product level
Non-EU manufacturer placing product on EU marketYes — extraterritorialSame obligations; authorised representative where required
Importer of radio equipmentYes — verification dutyMust verify conformity assessment performed and documentation exists
DistributorYes — verification dutyMust verify CE marking and accompanying documentation
Manufacturer of medical devices with radioNo — excludedGoverned by MDR and its own cybersecurity requirements
Manufacturer of motor vehicles, aviation or road toll equipmentNo — excludedGoverned by sector-specific legislation
Radio equipment with no internet connection, no personal data, no paymentLikely noNot in scope — but document this determination

RED cybersecurity obligations manufacturers miss

The most common compliance failure is not a technical one. It is a timing assumption: that the Cyber Resilience Act is the relevant deadline and the RED requirements can be absorbed into that work in 2027.

Three things manufacturers consistently misunderstand:

The RED requirements are in force now and the CRA is not. The CRA’s reporting obligations apply from 11 September 2026 and its main obligations from 11 December 2027. The RED cybersecurity requirements applied on 1 August 2025. A product placed on the EU market today must meet them today, and the CE marking on that product is a declaration that it does. The delegated act is expected to be repealed once the CRA applies, which creates a window of more than two years in which the RED requirements govern and the CRA does not exist as an obligation.

Applying the harmonised standards is not the same as holding a presumption of conformity. The OJ restrictions on EN 18031 mean specified clauses confer no presumption, and a manufacturer relying on self-assessment through full application of the standards may have no valid basis for doing so. This is the single most consequential detail in the regime and it appears in the Official Journal citation rather than in the standards themselves. Manufacturers who bought the standards and worked through them, without reading the citation, have frequently reached the wrong conformity route.

An existing RED declaration of conformity is now incomplete. Manufacturers holding CE marking under RED for radio spectrum and EMC requirements have a declaration of conformity that does not cover Articles 3(3)(d), (e) and (f). The product is CE marked, the file exists, and the position is nonetheless non-conforming for equipment placed on the market after 1 August 2025. Updating the technical file and the declaration is a smaller exercise than a fresh conformity assessment, but it is not automatic and it is not optional.

What Radio Equipment Directive cybersecurity compliance requires from your product

These are the Radio Equipment Directive requirements that apply most directly to manufacturers of connected radio equipment.

Scope determination — establishing which of Articles 3(3)(d), (e) and (f) apply to your equipment, on what facts, and recording the reasoning for any requirement determined not to apply.

Cybersecurity risk assessment — a risk assessment structured against the applicable essential requirements, covering assets, threats, and the safeguards implemented, in a form that supports the conformity assessment rather than sitting alongside it.

Harmonised standards applicability record — assessment of EN 18031-1, -2 and -3 against your product, including which restricted clauses are material, what presumption of conformity you actually hold, and what that means for your conformity route.

Conformity route determination — whether internal production control is available or whether EU-type examination by a notified body is required, with the reasoning recorded before the assessment is commissioned.

Technical documentation — the file demonstrating conformity with the applicable essential requirements, structured so a notified body or market surveillance authority can follow the evidence from requirement to safeguard to test result.

EU declaration of conformity — updated to list the cybersecurity essential requirements and the standards applied, replacing the radio-and-EMC-only declaration most manufacturers currently hold.

Cross-framework mapping — identification of where the Radio Equipment Directive requirements interact with the Cyber Resilience Act from 2027, with GDPR where Article 3(3)(e) applies, and with the EU AI Act where the equipment incorporates an AI system.

CRA transition record — mapping which Radio Equipment Directive cybersecurity evidence carries forward to CRA conformity from 11 December 2027, so the work done now reduces the work required then rather than being repeated.

Living Compliance File™ — audit-ready compliance record structured by essential requirement and product variant, formatted so a notified body, market surveillance authority, enterprise buyer or investor’s legal team can open it and find what they need.

One engagement. Every Radio Equipment Directive obligation mapped for your digital product.

RED cybersecurity assessment covering scope determination across all three essential requirements, harmonised standards applicability including the Official Journal restrictions, conformity route determination, technical documentation structure, declaration of conformity updating, and cross-framework mapping against your CRA, GDPR and EU AI Act position where all apply.

Frequently Asked Questions About RED Compliance

When did the RED cybersecurity requirements start applying?

The cybersecurity requirements under Delegated Regulation (EU) 2022/30 applied from 1 August 2025. The original date was 1 August 2024, postponed by one year to allow harmonised standards to be developed and cited. Radio equipment placed on the EU market from 1 August 2025 must meet the essential requirements in Articles 3(3)(d), (e) and (f) of the Radio Equipment Directive.

What do Articles 3(3)(d), (e) and (f) actually require?

Article 3(3)(d) requires radio equipment not to harm the network or misuse network resources. Article 3(3)(e) requires safeguards protecting the personal data and privacy of users and subscribers. Article 3(3)(f) requires protection against fraud for equipment enabling transfer of money, monetary value or virtual currency. Each has its own scope, and a product may fall within one, two or all three.

Is Radio Equipment Directive the same as the Cyber Resilience Act?

No. The RED delegated act applies now to radio equipment. The Cyber Resilience Act, Regulation (EU) 2024/2847, applies to products with digital elements with reporting obligations from 11 September 2026 and main obligations from 11 December 2027. The delegated act is expected to be repealed once the CRA applies, but until then it governs — which means connected device manufacturers have enforceable obligations today rather than in 2027.

Can I wait for the CRA and address both together?

No. A product placed on the EU market now must meet the Radio Equipment Directive cybersecurity requirements now, and the CE marking on that product is a declaration that it does. Market surveillance authorities can already act. Waiting for the CRA leaves a two-year window in which products are placed on the market non-conforming under a directive that is already enforceable.

Are there harmonised standards, and can I rely on them?

EN 18031-1, EN 18031-2 and EN 18031-3 correspond to the three essential requirements and were cited in the Official Journal in January 2025 — but with restrictions. Specified clauses do not confer a presumption of conformity, particularly around user-defined access controls and factory default passwords. A manufacturer applying the standards in full may still lack a complete presumption, which changes the conformity route. The restrictions are in the OJ citation, not in the standards.

Do I need a notified body?

It depends on whether the harmonised standards give you a presumption of conformity for your product. Where they are applied in full and the restrictions are not material, internal production control is available. Where the standards are not applied, or a restricted clause bites, EU-type examination by a notified body is required. Because of the OJ restrictions, more manufacturers need notified body involvement than initially expected.

My product is already CE marked under RED. Am I compliant?

Probably not. Most existing Radio Equipment Directive declarations of conformity cover radio spectrum efficiency and EMC requirements only, because Articles 3(3)(d), (e) and (f) were dormant until August 2025. The technical file needs the cybersecurity evidence added and the declaration of conformity updated to list the newly applicable essential requirements.

Does the RED delegated act apply to non-EU manufacturers?

Yes. The Radio Equipment Directive applies to equipment placed on the EU market regardless of where the manufacturer is established. Importers and distributors carry verification duties before placing the product on the market, and a non-EU manufacturer needs an authorised representative in the Union where the Directive requires one.

How does Article 3(3)(e) interact with GDPR?

They are separate obligations with separate mechanisms. Article 3(3)(e) is a product safety essential requirement, assessed through conformity assessment, requiring the equipment to incorporate privacy safeguards by design. GDPR governs the processing of personal data and applies in full regardless. A manufacturer meeting the essential requirement has not thereby discharged its GDPR obligations, and a GDPR-compliant controller has not thereby met the essential requirement.

Which products are excluded?

Medical devices, in vitro diagnostic medical devices, civil aviation equipment, motor vehicles, and electronic road toll systems are excluded, because each is governed by sector-specific legislation containing its own cybersecurity requirements. Exclusion is not automatic from the product category alone — the determination should be recorded like any other scope conclusion.

How do I start RED cybersecurity compliance for my product?

First, determine which of the three essential requirements apply to your equipment and record the reasoning for any that do not.
Second, assess EN 18031-1, -2 and -3 against your product, including which restricted clauses are material to it, and establish what presumption of conformity you actually hold.
Third, determine your conformity route — internal production control or EU-type examination — before commissioning any assessment.
Fourth, update the technical documentation and the declaration of conformity to cover the cybersecurity essential requirements, and map which evidence carries forward to CRA conformity in December 2027. A lawyer-built assessment covers all four steps and delivers a documented compliance position specific to your product.