iotpentest

The RED cybersecurity requirements: who is caught, and until when

Updated 9 min read

If you place a wireless product on the EU market, three essential requirements have applied to it since 1 August 2025. They are short, they are vague, and the standards written to satisfy them arrive with restrictions attached. This is what they actually require and what a test has to produce.

What Delegated Regulation (EU) 2022/30 did

Directive 2014/53/EU, the Radio Equipment Directive, has always contained a set of dormant essential requirements in its Article 3(3). They only become applicable when the Commission activates them for named categories of equipment. In October 2021 the Commission did exactly that for three of them, in Commission Delegated Regulation (EU) 2022/30.

The three requirements are quoted here in full, because the whole regime rests on about forty words:

(d) radio equipment does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service; (e) radio equipment incorporates safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected; (f) radio equipment supports certain features ensuring protection from fraud.Directive 2014/53/EU, Article 3(3)

None of that reads like a security specification, and it is not meant to. The delegated regulation supplies the scope, the harmonised standards supply the detail, and the manufacturer supplies the evidence. Where the standards do not fully cover the product, the manufacturer also supplies a notified body.

Which products are caught

Article 1 of Delegated Regulation (EU) 2022/30 scopes each requirement separately, and the scoping is worth reading closely because it is broader than most product teams expect.

Point (d): anything that reaches the internet

Point (d) applies to any radio equipment that can communicate itself over the internet, whether it communicates directly or via any other equipment. The phrase “or via any other equipment” is what makes this so wide. A Zigbee sensor with no IP stack of its own is still caught if it reaches the internet through a hub. So is a Bluetooth accessory that only ever talks to a phone, if the phone relays its data onward.

Point (e): anything that handles personal, traffic or location data

Point (e) applies to radio equipment capable of processing personal data or traffic or location data. The regulation then names four categories explicitly: internet-connected radio equipment, equipment designed or intended exclusively for childcare, equipment covered by the toy safety Directive 2009/48/EC, and wearable equipment worn on, strapped to, or hung from the human body or clothing. A baby monitor, a connected toy and a fitness band are in scope by name rather than by argument.

Point (f): anything that moves value

Point (f) applies to internet-connected radio equipment that enables the user to transfer money, monetary value or virtual currency. This is the narrowest of the three and catches payment terminals, wallets in hardware and similar products.

The dates, and the repeal that is not an amnesty

Three instruments set the timeline, and the third one is the reason this regime is regularly described wrongly.

The RED cybersecurity timeline, from the instruments themselves
InstrumentDateEffect
Delegated Regulation (EU) 2022/3029 Oct 2021Made Article 3(3)(d), (e) and (f) applicable to the named categories; originally to apply from 1 August 2024.
Delegated Regulation (EU) 2023/244420 Jul 2023Amended the date of application to 1 August 2025, after CEN and CENELEC asked for nine more months to finish the harmonised standards.
Implementing Decision (EU) 2025/13828 Jan 2025Cited EN 18031-1, -2 and -3 in the Official Journal, with restrictions, as the harmonised standards supporting the three requirements.
Delegated Regulation (EU) 2026/33916 Feb 2026Repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, the day Regulation (EU) 2024/2847 applies in full.
Published in the Official Journal on 12 January 2022, 2 November 2023, 29 January 2025 and 29 April 2026 respectively.

The repeal exists to prevent double regulation. Recital 3 of Delegated Regulation (EU) 2026/339 says that the essential cybersecurity requirements in Annex I of the Cyber Resilience Act include all the elements of Article 3(3), points (d), (e) and (f), so keeping both alive would subject the same product to two overlapping cybersecurity regimes. Recital 4 says the repeal is needed so that does not happen.

What the repeal does not do is erase the obligation retrospectively. Recital 5 states that the repeal does not affect Union market surveillance and control, under Directive 2014/53/EU, of compliance with those essential requirements for radio equipment that was or is placed on the Union market between 1 August 2025 and 10 December 2027. A product shipped this year carries a RED cybersecurity file, and an authority can still ask for it in 2029.

Why the conformity route is the real cost

The interesting money in this regime is not in the requirements. It is in Article 17 of Directive 2014/53/EU, which decides who signs off on them.

For the Article 3(3) requirements, a manufacturer may use internal production control – module A, a self-declaration route with no third party involved – only where the relevant harmonised standards have been applied in full. Where the manufacturer has not applied them, has applied them only in part, or where no such standards exist, the product must go through EU-type examination followed by conformity to type based on internal production control, or through full quality assurance. Both of those involve a notified body.

This is why the restrictions attached to EN 18031 in Implementing Decision (EU) 2025/138 matter far more than their length suggests. A single design decision – letting a user finish setup without setting a password – takes the presumption of conformity away for that requirement, and with it the self-declaration route. The bench note on the EN 18031 restrictions works through exactly how that happens.

The corollary is that the cheapest possible RED cybersecurity project is one where somebody checks the restricted behaviours on a real unit early, while the firmware team can still change the onboarding flow. The most expensive is one where nobody checks until the notified body does.

Who actually carries the obligation

The conformity assessment belongs to the manufacturer. Article 17(1) says the manufacturer shall perform a conformity assessment of the radio equipment with a view to meeting the essential requirements in Article 3, taking into account all intended operating conditions. It adds a sentence that quietly widens most test plans: where the radio equipment is capable of taking different configurations, the conformity assessment shall confirm whether it meets the essential requirements in all possible configurations. A device that behaves differently in access-point mode, in station mode and in a factory-reset provisioning state has three configurations to answer for, not one.

Importers do not escape. Article 12(2) requires an importer, before placing radio equipment on the market, to ensure that the appropriate conformity assessment procedure under Article 17 has been carried out by the manufacturer, that the technical documentation exists, and that the CE marking and accompanying documents are in place. Article 12(6) goes further: when deemed appropriate with regard to the risks presented, importers shall carry out sample testing of radio equipment made available on the market, investigate, and where necessary keep a register of complaints, non-conforming equipment and recalls. Article 12(8) requires the importer to keep a copy of the EU declaration of conformity available to market surveillance authorities for ten years.

Distributors carry a lighter but real duty. Article 13(2) requires them to verify, before making equipment available, that it bears the CE marking, that it comes with the required documents and instructions in a language end-users in that Member State can understand, and that the manufacturer and importer have met their own labelling and documentation obligations.

For a European company importing wireless product from a factory outside the EU, that combination is the important one. You are not merely reselling someone else’s compliance. You are expected to have checked that the assessment happened, and where the risk justifies it, to test samples yourself.

What a test has to produce for the RED file

A test report is not a conformity assessment. It is evidence that goes into one, which means it has to be written for two readers at once: an engineer who has to reproduce the finding, and an assessor who has to decide whether the file supports the declaration.

  • An identified unit. Hardware revision, firmware build, radio module and its firmware. A finding against an unspecified unit is not evidence.
  • The interface, not the abstraction. “Weak authentication” means nothing in a file. “The BLE GATT characteristic at handle 0x0021 accepts a configuration write without bonding, on firmware 1.4.2” means something.
  • The requirement it fails. Each finding tied to point (d), (e) or (f), and to the EN 18031 clause if the standard was applied.
  • The restriction check. An explicit statement of whether the product allows a user to complete setup without setting a password, and whether parental or guardian access control is ensured where the child-facing classes apply.
  • A retest against the shipped build. Fixes verified on the firmware that actually goes out, not on a branch.

The device attack surface mapper on the home page lists what a tester does to each exposure and the instrument behind it, which is a reasonable starting point for a scope document.

What to do in the next quarter

For a manufacturer or importer that has not yet built a RED cybersecurity file, the order of work is fairly stable across products.

  1. Confirm scope: does the product communicate over the internet directly or via other equipment, does it process personal, traffic or location data, is it a childcare product, a toy or a wearable, and does it move monetary value.
  2. Check the excluded categories in Article 2 before doing anything else. A medical device or a vehicle component is somewhere else entirely.
  3. Test the two restricted behaviours on a production unit: whether setup can be completed with no password, and whether parental or guardian access control is ensured for the relevant classes.
  4. Decide the conformity route on the basis of that answer, not on the basis of a plan to apply the standard in full.
  5. Run the device assessment across board, firmware, radio, app and cloud, and map every finding to a requirement.
  6. Keep the file. The repeal does not remove market surveillance over product placed on the market before 11 December 2027.

If the product is also heading for the CRA regime after December 2027 – and most of them are – it is worth reading the note on what the Cyber Resilience Act asks you to test before commissioning work, so one engagement produces evidence for both files.

Sources

  1. Commission Delegated Regulation (EU) 2022/30 of 29 October 2021 supplementing Directive 2014/53/EU with regard to the application of the essential requirements referred to in Article 3(3), points (d), (e) and (f) EUR-Lex (OJ L 7, 12.1.2022) · 2022
  2. Directive 2014/53/EU on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment EUR-Lex (OJ L 153, 22.5.2014) · 2014 Article 3(3) sets the essential requirements; Article 17 sets the conformity assessment procedures.
  3. Commission Delegated Regulation (EU) 2023/2444 amending Delegated Regulation (EU) 2022/30 as regards the date of application EUR-Lex · 2023
  4. Commission Delegated Regulation (EU) 2026/339 of 16 February 2026 repealing Delegated Regulation (EU) 2022/30 EUR-Lex (OJ L, 29.4.2026) · 2026 Recital 5 preserves market surveillance for product placed on the market between 1 August 2025 and 10 December 2027.
  5. Commission Implementing Decision (EU) 2025/138 on harmonised standards for radio equipment relating to cybersecurity EUR-Lex · 2025
  6. Radio Equipment Directive (RED): update on Articles 3(3)(d), (e) and (f) on cybersecurity European Commission, DG GROW · 2026

Follow-up

Questions this raises

Does a Bluetooth-only device fall under point (d)?
It can. Article 1(1) applies point (d) to any radio equipment that can communicate itself over the internet, whether it communicates directly or via any other equipment. A device that reaches the internet through a phone or a hub meets that description even though it has no IP stack of its own.
Our product ships in 2027. Should we build a RED file or a CRA file?
Both, in practice. Product placed on the Union market before 11 December 2027 is assessed under the RED cybersecurity requirements, and Delegated Regulation (EU) 2026/339 preserves market surveillance over that product after the repeal. Product placed on the market from 11 December 2027 falls under Regulation (EU) 2024/2847. Since the CRA Annex I requirements include the elements of Article 3(3)(d), (e) and (f), one well-scoped assessment can feed both files.
Can we self-declare conformity with the cybersecurity requirements?
Only if you apply the relevant harmonised standards in full. Article 17 of Directive 2014/53/EU allows internal production control for the Article 3(3) requirements on that condition. Where the standards are applied only in part, or a restriction in the Official Journal citation removes the presumption for your design, the file must go through EU-type examination plus conformity to type, or full quality assurance, both involving a notified body.