EU / Radio Equipment & Cybersecurity

RED cybersecurity isn't a future deadline — it's been mandatory since 1 August 2025, and CRA doesn't replace it yet.

Most compliance conversations with connected-device makers jump straight to the Cyber Resilience Act, which is still phasing in through 2027. But the Radio Equipment Directive's own cybersecurity essential requirements — Article 3(3)(d), (e) and (f) — are already live and enforceable for almost any internet-connected radio device sold in the EU, and RED won't be repealed for these products until CRA fully applies.

Last updated 11 September 2026

1 Aug 2025Mandatory date — already passed
3EN 18031 harmonised standards (-1/-2/-3)
11 Dec 2027When CRA fully applies and RED's cybersecurity Delegated Regulation is repealed

The deadline has already passed — this is a live obligation

Delegated Regulation (EU) 2022/30 took effect on 1 February 2022 and, after a 42-month transition period, became mandatory on 1 August 2025. Any covered device placed on the EU market from that date onward must meet the RED's cybersecurity essential requirements to legally carry a CE mark. There is no grace period running now — a non-compliant device shipped today is a device shipped without valid CE marking, full stop.

Source: SOS electronic, "The Delegated Act on Cybersecurity Under RED (EU) 2022/30 Comes Into Effect on 1 August 2025".

Who this actually covers

Scope is set by Article 1 of the Delegated Regulation, and it is narrower than "anything with a radio". Network protection, Article 3(3)(d), applies to any radio equipment that can communicate over the internet, directly or through other equipment: phones, tablets, smart-home devices and the broader run of Wi-Fi- or cellular-connected IoT. Personal-data protection, Article 3(3)(e), applies to that internet-connected equipment and also to three groups whether or not they connect to the internet — radio equipment for childcare, radio toys, and wearable radio equipment — in each case where the device can process personal, traffic or location data. Fraud protection, Article 3(3)(f), applies to internet-connected equipment that lets the user transfer money, monetary value or virtual currency. That is why wearables, toys and baby monitors are routinely surprised to find themselves in scope.

Two exclusions matter in practice. Medical devices and in-vitro diagnostic devices under Regulations (EU) 2017/745 and 2017/746 are excluded from all three points, because those regulations carry their own cybersecurity requirements; aviation equipment, vehicle type-approval and electronic road toll equipment are excluded from points (e) and (f). A radio product that neither connects to the internet nor falls into the childcare, toy or wearable groups is outside the cybersecurity requirements altogether, though the rest of the RED still applies to it.

Source: Commission Delegated Regulation (EU) 2022/30, Articles 1 and 2 and recital 15 (EUR-Lex); ReedSmith, "RED: EU Cybersecurity Obligations for IoT Products from August 2025".

What the three sub-requirements actually ask for

Article 3(3)(d) — network protection: the device must not harm the network it connects to, or degrade the network's functionality for other users. Article 3(3)(e) — personal data and privacy protection: the device and any accompanying software must safeguard the personal data and privacy of the device's users. Article 3(3)(f) — fraud protection: applies specifically to devices that handle monetary value or virtual currency, requiring safeguards against fraudulent use. Which apply to a given product depends on its actual functionality, not its product category label.

Source: TÜV SÜD, "5 key points about the new cybersecurity requirements for RED".

EN 18031 is the practical route to CE marking

On 28 January 2025 the European Commission published three harmonised standards: EN 18031-1:2024 for internet-connected radio equipment generally, EN 18031-2:2024 for equipment processing personal, traffic or location data, and EN 18031-3:2024 for equipment enabling transfer of money or virtual currency. Applying the relevant standard(s) grants a presumption of conformity — the standard, lower-friction path to demonstrating compliance. The standards carry some restrictions; where those apply, a notified body has to participate in the conformity assessment rather than self-assessment alone.

Source: Nemko, "EN 18031: New Cybersecurity Standard for EU Radio Equipment Compliance", Granite River Labs, "EU RED Cybersecurity Compliance: Preparing for August 1, 2025".

Why this isn't just "wait for CRA"

The Cyber Resilience Act is broader in scope and still phasing in through 2027, with full application from 11 December 2027. RED's Delegated Regulation on cybersecurity is being repealed by Commission Delegated Regulation (EU) 2026/339, published in the Official Journal on 29 April 2026 — but the repeal itself only takes effect on 11 December 2027, the same date CRA fully applies to the relevant product categories, and does not affect market surveillance for radio equipment placed on the market between 1 August 2025 and 10 December 2027. Treating CRA as the cybersecurity deadline that matters and RED as a lesser or superseded requirement gets the sequencing backwards: right now, RED is the operative, already-enforceable obligation, and CRA is the one still arriving.

Questions

Is the RED cybersecurity requirement really in force already?

Yes. Delegated Regulation (EU) 2022/30 to the Radio Equipment Directive took effect on 1 February 2022 and, after a 42-month transition period, became mandatory on 1 August 2025. Any covered device placed on the EU market from that date must meet the cybersecurity essential requirements to carry a CE mark — this is not a future or proposed deadline.

Which products are covered?

Three groups, set out in Article 1 of Delegated Regulation (EU) 2022/30. Network protection, Article 3(3)(d), applies to any radio equipment that can communicate over the internet, directly or via other equipment. Personal-data protection, Article 3(3)(e), applies to such internet-connected equipment and also to radio equipment for childcare, radio toys and wearable radio equipment, in each case if it can process personal, traffic or location data — the childcare, toy and wearable groups are covered even without an internet connection. Fraud protection, Article 3(3)(f), applies to internet-connected equipment that lets the user transfer money, monetary value or virtual currency. Not everything with a radio is covered: a radio device that neither connects to the internet nor falls in those groups is outside it, and medical devices under Regulations (EU) 2017/745 and 2017/746 are excluded from all three points (Article 2(1)), while aviation, vehicle type-approval and electronic road toll equipment are excluded from points (e) and (f) (Article 2(2)).

What do the three sub-requirements actually require?

Article 3(3)(d) requires network protection — the device must not harm the network it connects to or degrade its functionality. Article 3(3)(e) requires protection of personal data and privacy for the device and its users. Article 3(3)(f) requires protection from fraud, applying to devices that handle monetary value or virtual currency. Which of the three apply depends on the device's actual functionality.

What is EN 18031 and do we need it?

EN 18031-1/-2/-3:2024 are the harmonised standards published by the European Commission on 28 January 2025, covering internet-connected radio equipment, equipment processing personal/traffic/location data, and equipment enabling transfer of money or virtual currency respectively. Applying the relevant standard(s) grants a presumption of conformity, which is the standard route to CE marking under this requirement — without it, conformity has to be demonstrated another way, which is materially more work.

Does the Cyber Resilience Act replace this?

Not yet. The CRA's own essential requirements phase in through 2027, with full application from 11 December 2027, and the RED Delegated Regulation is being repealed by Commission Delegated Regulation (EU) 2026/339 (published in the Official Journal 29 April 2026), with the repeal itself taking effect on 11 December 2027, the same date CRA fully applies to the relevant product categories. Until then, RED's cybersecurity requirements are the operative obligation for internet-connected radio equipment — treating CRA as the only cybersecurity deadline that matters risks missing the one that is already enforceable.

Where we fit

If your product connects to the internet and you've been tracking CRA as the cybersecurity deadline that matters, RED's Article 3(3) requirements are very likely already applicable to you, right now. We fold the EN 18031 assessment into the same market-access engagement as CE marking and RoHS, so it's one process rather than a second compliance track discovered too late.

Book a scoping call