The RED cybersecurity requirements: who is caught, and until when
If you place a wireless product on the EU market, three essential requirements have applied to it since 1 August 2025. They are short, they are vague, and the standards written to satisfy them arrive with restrictions attached. This is what they actually require and what a test has to produce.
What Delegated Regulation (EU) 2022/30 did
Directive 2014/53/EU, the Radio Equipment Directive, has always contained a set of dormant essential requirements in its Article 3(3). They only become applicable when the Commission activates them for named categories of equipment. In October 2021 the Commission did exactly that for three of them, in Commission Delegated Regulation (EU) 2022/30.
The three requirements are quoted here in full, because the whole regime rests on about forty words:
(d) radio equipment does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service; (e) radio equipment incorporates safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected; (f) radio equipment supports certain features ensuring protection from fraud.Directive 2014/53/EU, Article 3(3)
None of that reads like a security specification, and it is not meant to. The delegated regulation supplies the scope, the harmonised standards supply the detail, and the manufacturer supplies the evidence. Where the standards do not fully cover the product, the manufacturer also supplies a notified body.
Which products are caught
Article 1 of Delegated Regulation (EU) 2022/30 scopes each requirement separately, and the scoping is worth reading closely because it is broader than most product teams expect.
Point (d): anything that reaches the internet
Point (d) applies to any radio equipment that can communicate itself over the internet, whether it communicates directly or via any other equipment. The phrase “or via any other equipment” is what makes this so wide. A Zigbee sensor with no IP stack of its own is still caught if it reaches the internet through a hub. So is a Bluetooth accessory that only ever talks to a phone, if the phone relays its data onward.
Point (e): anything that handles personal, traffic or location data
Point (e) applies to radio equipment capable of processing personal data or traffic or location data. The regulation then names four categories explicitly: internet-connected radio equipment, equipment designed or intended exclusively for childcare, equipment covered by the toy safety Directive 2009/48/EC, and wearable equipment worn on, strapped to, or hung from the human body or clothing. A baby monitor, a connected toy and a fitness band are in scope by name rather than by argument.
Point (f): anything that moves value
Point (f) applies to internet-connected radio equipment that enables the user to transfer money, monetary value or virtual currency. This is the narrowest of the three and catches payment terminals, wallets in hardware and similar products.
The dates, and the repeal that is not an amnesty
Three instruments set the timeline, and the third one is the reason this regime is regularly described wrongly.
| Instrument | Date | Effect |
|---|---|---|
| Delegated Regulation (EU) 2022/30 | 29 Oct 2021 | Made Article 3(3)(d), (e) and (f) applicable to the named categories; originally to apply from 1 August 2024. |
| Delegated Regulation (EU) 2023/2444 | 20 Jul 2023 | Amended the date of application to 1 August 2025, after CEN and CENELEC asked for nine more months to finish the harmonised standards. |
| Implementing Decision (EU) 2025/138 | 28 Jan 2025 | Cited EN 18031-1, -2 and -3 in the Official Journal, with restrictions, as the harmonised standards supporting the three requirements. |
| Delegated Regulation (EU) 2026/339 | 16 Feb 2026 | Repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, the day Regulation (EU) 2024/2847 applies in full. |
The repeal exists to prevent double regulation. Recital 3 of Delegated Regulation (EU) 2026/339 says that the essential cybersecurity requirements in Annex I of the Cyber Resilience Act include all the elements of Article 3(3), points (d), (e) and (f), so keeping both alive would subject the same product to two overlapping cybersecurity regimes. Recital 4 says the repeal is needed so that does not happen.
What the repeal does not do is erase the obligation retrospectively. Recital 5 states that the repeal does not affect Union market surveillance and control, under Directive 2014/53/EU, of compliance with those essential requirements for radio equipment that was or is placed on the Union market between 1 August 2025 and 10 December 2027. A product shipped this year carries a RED cybersecurity file, and an authority can still ask for it in 2029.
Why the conformity route is the real cost
The interesting money in this regime is not in the requirements. It is in Article 17 of Directive 2014/53/EU, which decides who signs off on them.
For the Article 3(3) requirements, a manufacturer may use internal production control – module A, a self-declaration route with no third party involved – only where the relevant harmonised standards have been applied in full. Where the manufacturer has not applied them, has applied them only in part, or where no such standards exist, the product must go through EU-type examination followed by conformity to type based on internal production control, or through full quality assurance. Both of those involve a notified body.
This is why the restrictions attached to EN 18031 in Implementing Decision (EU) 2025/138 matter far more than their length suggests. A single design decision – letting a user finish setup without setting a password – takes the presumption of conformity away for that requirement, and with it the self-declaration route. The bench note on the EN 18031 restrictions works through exactly how that happens.
The corollary is that the cheapest possible RED cybersecurity project is one where somebody checks the restricted behaviours on a real unit early, while the firmware team can still change the onboarding flow. The most expensive is one where nobody checks until the notified body does.
Who actually carries the obligation
The conformity assessment belongs to the manufacturer. Article 17(1) says the manufacturer shall perform a conformity assessment of the radio equipment with a view to meeting the essential requirements in Article 3, taking into account all intended operating conditions. It adds a sentence that quietly widens most test plans: where the radio equipment is capable of taking different configurations, the conformity assessment shall confirm whether it meets the essential requirements in all possible configurations. A device that behaves differently in access-point mode, in station mode and in a factory-reset provisioning state has three configurations to answer for, not one.
Importers do not escape. Article 12(2) requires an importer, before placing radio equipment on the market, to ensure that the appropriate conformity assessment procedure under Article 17 has been carried out by the manufacturer, that the technical documentation exists, and that the CE marking and accompanying documents are in place. Article 12(6) goes further: when deemed appropriate with regard to the risks presented, importers shall carry out sample testing of radio equipment made available on the market, investigate, and where necessary keep a register of complaints, non-conforming equipment and recalls. Article 12(8) requires the importer to keep a copy of the EU declaration of conformity available to market surveillance authorities for ten years.
Distributors carry a lighter but real duty. Article 13(2) requires them to verify, before making equipment available, that it bears the CE marking, that it comes with the required documents and instructions in a language end-users in that Member State can understand, and that the manufacturer and importer have met their own labelling and documentation obligations.
For a European company importing wireless product from a factory outside the EU, that combination is the important one. You are not merely reselling someone else’s compliance. You are expected to have checked that the assessment happened, and where the risk justifies it, to test samples yourself.
What a test has to produce for the RED file
A test report is not a conformity assessment. It is evidence that goes into one, which means it has to be written for two readers at once: an engineer who has to reproduce the finding, and an assessor who has to decide whether the file supports the declaration.
- An identified unit. Hardware revision, firmware build, radio module and its firmware. A finding against an unspecified unit is not evidence.
- The interface, not the abstraction. “Weak authentication” means nothing in a file. “The BLE GATT characteristic at handle 0x0021 accepts a configuration write without bonding, on firmware 1.4.2” means something.
- The requirement it fails. Each finding tied to point (d), (e) or (f), and to the EN 18031 clause if the standard was applied.
- The restriction check. An explicit statement of whether the product allows a user to complete setup without setting a password, and whether parental or guardian access control is ensured where the child-facing classes apply.
- A retest against the shipped build. Fixes verified on the firmware that actually goes out, not on a branch.
The device attack surface mapper on the home page lists what a tester does to each exposure and the instrument behind it, which is a reasonable starting point for a scope document.
What to do in the next quarter
For a manufacturer or importer that has not yet built a RED cybersecurity file, the order of work is fairly stable across products.
- Confirm scope: does the product communicate over the internet directly or via other equipment, does it process personal, traffic or location data, is it a childcare product, a toy or a wearable, and does it move monetary value.
- Check the excluded categories in Article 2 before doing anything else. A medical device or a vehicle component is somewhere else entirely.
- Test the two restricted behaviours on a production unit: whether setup can be completed with no password, and whether parental or guardian access control is ensured for the relevant classes.
- Decide the conformity route on the basis of that answer, not on the basis of a plan to apply the standard in full.
- Run the device assessment across board, firmware, radio, app and cloud, and map every finding to a requirement.
- Keep the file. The repeal does not remove market surveillance over product placed on the market before 11 December 2027.
If the product is also heading for the CRA regime after December 2027 – and most of them are – it is worth reading the note on what the Cyber Resilience Act asks you to test before commissioning work, so one engagement produces evidence for both files.
Sources
- Commission Delegated Regulation (EU) 2022/30 of 29 October 2021 supplementing Directive 2014/53/EU with regard to the application of the essential requirements referred to in Article 3(3), points (d), (e) and (f)
- Directive 2014/53/EU on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment Article 3(3) sets the essential requirements; Article 17 sets the conformity assessment procedures.
- Commission Delegated Regulation (EU) 2023/2444 amending Delegated Regulation (EU) 2022/30 as regards the date of application
- Commission Delegated Regulation (EU) 2026/339 of 16 February 2026 repealing Delegated Regulation (EU) 2022/30 Recital 5 preserves market surveillance for product placed on the market between 1 August 2025 and 10 December 2027.
- Commission Implementing Decision (EU) 2025/138 on harmonised standards for radio equipment relating to cybersecurity
- Radio Equipment Directive (RED): update on Articles 3(3)(d), (e) and (f) on cybersecurity
Follow-up
Questions this raises
Does a Bluetooth-only device fall under point (d)?
Our product ships in 2027. Should we build a RED file or a CRA file?
Can we self-declare conformity with the cybersecurity requirements?
Keep reading
More bench notes
-
EN 18031: the restrictions that decide your conformity route
Three harmonised standards were cited for the RED cybersecurity requirements, and all three arrived with restrictions. One of them turns a single onboarding decision into the difference between self-declaration and a notified body.
Read the note -
What the Cyber Resilience Act actually asks you to test
Annex I is a list of thirteen product properties and eight process duties, and one of those duties is regular security testing. Here is what each of them means for a device, and which route your product takes through conformity assessment.
Read the note -
The hardware attack surface: what happens on the bench
Debug headers, unpopulated pads, flash chips and radios. What a tester actually does to a board, what “disabled in software” has to mean in practice, and how to design the surface down before the unit ships.
Read the note