CRA and RED Cybersecurity comparison for connected products
Separate the Cyber Resilience Act from the RED cybersecurity delegated act before assigning CE, technical-file, and vulnerability-handling work.
Classify the product and its EU market-placement date first. RED cybersecurity conformity applies now to specified radio equipment; most CRA product duties apply from 11 December 2027, with CRA reporting starting earlier.
Use the RED cybersecurity route for covered radio equipment placed on the EU market from 1 August 2025. Prepare the CRA route for products with digital elements placed on the market from 11 December 2027, while also preparing for CRA Article 14 reporting from 11 September 2026. The regimes are not interchangeable: Delegated Regulation (EU) 2022/30 activates three Radio Equipment Directive (RED) essential requirements for specified radio equipment, while the Cyber Resilience Act (CRA) sets horizontal lifecycle requirements for products with digital elements. Commission Delegated Regulation (EU) 2026/339 repeals the RED delegated regulation with effect from 11 December 2027.
Side-by-side comparison
CRA vs RED cybersecurity delegated act
This matrix helps separate the CRA's horizontal product-cybersecurity duties from the RED delegated act's radio-equipment cybersecurity scope.
Horizontal EU cybersecurity regulation for products with digital elements, including software, hardware, covered components, and covered remote data processing.
Second framework
RED cybersecurity delegated act
Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive, applying cybersecurity-related essential requirements to certain radio equipment.
Covers products with digital elements placed on the EU market, including software or hardware products and covered remote data-processing solutions.
Covers categories of radio equipment specified in Delegated Regulation (EU) 2022/30, through RED Article 3(3)(d), (e), and (f).
Classify radio-equipment status and product-with-digital-elements status separately. A product can be both, but one conclusion does not prove the other.
Most CRA provisions apply from 11 December 2027. Article 14 reporting applies from 11 September 2026, and the notified-body provisions in Chapter IV apply from 11 June 2026.
For categories covered by Delegated Regulation (EU) 2022/30, the Commission FAQ describes a RED cybersecurity window for products placed on the market from 1 August 2025 through 10 December 2027.
For a radio product, keep the market-placement date in the release file. The applicable cybersecurity route can turn on whether the product is placed before or after 11 December 2027.
CRA duties include cybersecurity risk assessment, essential cybersecurity requirements, effective vulnerability handling during the support period, technical documentation, conformity assessment, EU declaration of conformity, CE marking, user instructions, and cooperation with market-surveillance authorities.
The RED delegated act makes specific RED cybersecurity essential requirements applicable by product category and function. The file must identify whether Article 3(3)(d), (e), or (f) applies and support the selected RED conformity route.
A RED technical file is not automatically a complete CRA file. Check whether it also covers support-period rationale, vulnerability-handling processes, CRA technical documentation, and Article 14 reporting readiness.
Products with digital elements placed on the market before 11 December 2027 are generally subject to CRA requirements only if substantially modified from that date, but Article 14 reporting applies to in-scope products.
If covered radio equipment was placed on the EU market during the RED cybersecurity window, later repeal of the delegated act would not undo RED market-surveillance treatment for that period.
Do not retrofit every pre-11 December 2027 product into full CRA documentation solely because the CRA starts applying. Do keep Article 14 reporting readiness and preserve RED evidence for radio equipment placed during the RED window.
CRA harmonised standards are being developed under a CRA standardisation request and must address the CRA's own essential cybersecurity requirements.
EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 support corresponding RED cybersecurity requirements, but their Official Journal citations contain limits on the .
Reuse mappings, tests, and controls only after identifying which CRA requirement and RED requirement each item supports and checking every applicable limitation in the harmonised-standard citation.
The CRA applies in full from 11 December 2027, with earlier Article 14 reporting from 11 September 2026 and Chapter IV from 11 June 2026.
The applies to covered radio equipment placed on the market from 1 August 2025 and is repealed with effect from 11 December 2027.
Use the individual product's first EU market-placement date. Covered radio equipment placed on the market through 10 December 2027 follows the RED cybersecurity route; covered products placed on the market from 11 December 2027 follow the CRA route.
Under the CRA, the technical file must support conformity assessment, CE marking, the EU declaration of conformity, and market-surveillance responses for products with digital elements.
Under the RED delegated act, the evidence file must support compliance with the RED cybersecurity requirements for the covered radio-equipment category and the standards used for that route.
Keep one file structure, but split the legal basis. A shared test report can sit in both files only if each file says exactly what it proves.
CRA Article 14 reporting starts on 11 September 2026 for in-scope products, including products placed on the market before most CRA duties apply. Most CRA conformity duties apply from 11 December 2027.
The RED delegated act governs applicable RED cybersecurity essential requirements for covered radio equipment placed on the market from 1 August 2025 through 10 December 2027.
During the transition, separate RED product conformity from CRA reporting and readiness. Do not describe both regimes as imposing the same full conformity duties at the same time.
If the product is a product with digital elements, apply the CRA analysis for the unit or software version being placed on the market.
If the product is covered radio equipment under Delegated Regulation (EU) 2022/30, identify each applicable RED Article 3(3)(d), (e), or (f) requirement for the same market-placement event.
Use one release record for the facts, then record the CRA and RED legal conclusions separately.
Covers products with digital elements placed on the EU market, including software or hardware products and covered remote data-processing solutions.
RED cybersecurity delegated act
Covers categories of radio equipment specified in Delegated Regulation (EU) 2022/30, through RED Article 3(3)(d), (e), and (f).
Operational implication
Classify radio-equipment status and product-with-digital-elements status separately. A product can be both, but one conclusion does not prove the other.
Most CRA provisions apply from 11 December 2027. Article 14 reporting applies from 11 September 2026, and the notified-body provisions in Chapter IV apply from 11 June 2026.
RED cybersecurity delegated act
For categories covered by Delegated Regulation (EU) 2022/30, the Commission FAQ describes a RED cybersecurity window for products placed on the market from 1 August 2025 through 10 December 2027.
Operational implication
For a radio product, keep the market-placement date in the release file. The applicable cybersecurity route can turn on whether the product is placed before or after 11 December 2027.
CRA duties include cybersecurity risk assessment, essential cybersecurity requirements, effective vulnerability handling during the support period, technical documentation, conformity assessment, EU declaration of conformity, CE marking, user instructions, and cooperation with market-surveillance authorities.
RED cybersecurity delegated act
The RED delegated act makes specific RED cybersecurity essential requirements applicable by product category and function. The file must identify whether Article 3(3)(d), (e), or (f) applies and support the selected RED conformity route.
Operational implication
A RED technical file is not automatically a complete CRA file. Check whether it also covers support-period rationale, vulnerability-handling processes, CRA technical documentation, and Article 14 reporting readiness.
Products with digital elements placed on the market before 11 December 2027 are generally subject to CRA requirements only if substantially modified from that date, but Article 14 reporting applies to in-scope products.
RED cybersecurity delegated act
If covered radio equipment was placed on the EU market during the RED cybersecurity window, later repeal of the delegated act would not undo RED market-surveillance treatment for that period.
Operational implication
Do not retrofit every pre-11 December 2027 product into full CRA documentation solely because the CRA starts applying. Do keep Article 14 reporting readiness and preserve RED evidence for radio equipment placed during the RED window.
CRA harmonised standards are being developed under a CRA standardisation request and must address the CRA's own essential cybersecurity requirements.
RED cybersecurity delegated act
EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 support corresponding RED cybersecurity requirements, but their Official Journal citations contain limits on the .
Operational implication
Reuse mappings, tests, and controls only after identifying which CRA requirement and RED requirement each item supports and checking every applicable limitation in the harmonised-standard citation.
The CRA applies in full from 11 December 2027, with earlier Article 14 reporting from 11 September 2026 and Chapter IV from 11 June 2026.
RED cybersecurity delegated act
The applies to covered radio equipment placed on the market from 1 August 2025 and is repealed with effect from 11 December 2027.
Operational implication
Use the individual product's first EU market-placement date. Covered radio equipment placed on the market through 10 December 2027 follows the RED cybersecurity route; covered products placed on the market from 11 December 2027 follow the CRA route.
Under the CRA, the technical file must support conformity assessment, CE marking, the EU declaration of conformity, and market-surveillance responses for products with digital elements.
RED cybersecurity delegated act
Under the RED delegated act, the evidence file must support compliance with the RED cybersecurity requirements for the covered radio-equipment category and the standards used for that route.
Operational implication
Keep one file structure, but split the legal basis. A shared test report can sit in both files only if each file says exactly what it proves.
CRA Article 14 reporting starts on 11 September 2026 for in-scope products, including products placed on the market before most CRA duties apply. Most CRA conformity duties apply from 11 December 2027.
RED cybersecurity delegated act
The RED delegated act governs applicable RED cybersecurity essential requirements for covered radio equipment placed on the market from 1 August 2025 through 10 December 2027.
Operational implication
During the transition, separate RED product conformity from CRA reporting and readiness. Do not describe both regimes as imposing the same full conformity duties at the same time.
If the product is a product with digital elements, apply the CRA analysis for the unit or software version being placed on the market.
RED cybersecurity delegated act
If the product is covered radio equipment under Delegated Regulation (EU) 2022/30, identify each applicable RED Article 3(3)(d), (e), or (f) requirement for the same market-placement event.
Operational implication
Use one release record for the facts, then record the CRA and RED legal conclusions separately.
Record whether the product is radio equipment, a product with digital elements, or both.
Record the first EU market-placement date for the unit or software version being assessed.
For 1 August 2025 through 10 December 2027, check RED delegated-act coverage for radio equipment and keep RED cybersecurity evidence where applicable.
From 11 September 2026, apply CRA Article 14 reporting to in-scope products. For products placed on the market from 11 December 2027, check all applicable CRA duties, including support period, vulnerability handling, technical documentation, conformity assessment, and CE marking.
Apply the repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
Where one evidence artifact is reused, state exactly which CRA requirement and which RED requirement it supports.
The CRA covers software and hardware products with direct or indirect logical or physical data connections to a device or network, including separately placed components and remote data-processing solutions on which a product function depends. Subject to exclusions and special rules, it requires manufacturers to assess cybersecurity risks, meet Annex I product-security and vulnerability-handling requirements, set and communicate a support period, prepare technical documentation, complete conformity assessment, issue an EU declaration of conformity, affix CE marking, give users required information, and cooperate with market-surveillance authorities.
The is narrower and requirement-specific. RED Article 3(3)(d), on avoiding harm to networks and misuse of network resources, applies to internet-connected radio equipment. Article 3(3)(e), on personal data and privacy, applies when specified internet-connected, childcare, toy, or wearable radio equipment can process personal, traffic, or location data. Article 3(3)(f), on protection from fraud, applies to internet-connected radio equipment that enables transfers of money, monetary value, or virtual currency.
Use CRA analysis when the item is software, hardware, or a covered component or remote processing solution placed on the EU market as a product with digital elements.
Use RED delegated-act analysis only when the item is radio equipment in a category covered by Delegated Regulation (EU) 2022/30.
A connected radio product may need RED conformity work and CRA transition work at the same time, especially CRA Article 14 reporting from 11 September 2026. A non-radio software product does not enter RED scope merely because it is connected.
Recommended next step
Check which evidence file your connected product needs
Use Sorena to compare a specific product, market-placement date, and radio-equipment status against the CRA and RED cybersecurity sources, then keep the cited scope and evidence conclusion with the release record.
The Commission CRA FAQ states that the RED cybersecurity requirements made applicable by Delegated Regulation (EU) 2022/30 apply to covered radio-equipment categories placed on the market on or after 1 August 2025.
Commission Delegated Regulation (EU) 2026/339 now repeals the RED delegated regulation with effect from 11 December 2027. Covered radio equipment placed on the market from 1 August 2025 through 10 December 2027 remains subject to the RED cybersecurity essential requirements, while covered products placed on the market on or after 11 December 2027 follow the CRA cybersecurity requirements. The Commission FAQ also explains that the repeal does not undo RED market-surveillance treatment for equipment placed on the market during the RED period.
For covered radio equipment placed on the EU market from 1 August 2025 to 10 December 2027, keep RED cybersecurity evidence.
For products with digital elements first placed on the EU market on or after 11 December 2027, prepare CRA conformity evidence unless an exclusion or specific rule applies.
For individual products placed on the market before 11 December 2027, CRA Article 69 generally limits the other CRA product duties unless the product is substantially modified from that date. Article 14 reporting nevertheless applies from 11 September 2026 to in-scope products, including units placed on the market earlier.
3
Section 3
Evidence differences
A CRA file needs to show the cybersecurity risk assessment and how the product and vulnerability-handling processes meet the CRA's essential cybersecurity requirements. Annex VII names technical-documentation elements such as product description, design and production information, vulnerability-handling process details, software bill of materials where applicable, coordinated vulnerability disclosure policy, secure-update approach, support-period rationale, standards or technical specifications used, test reports, and the EU declaration of conformity.
For RED delegated-act work, keep the evidence tied to the applicable RED essential requirement and conformity-assessment route. The EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 references were published with limitations: the cited Commission decision states that rationale and guidance sections do not confer a and gives additional limitations for password, parental-control, and payment-product cases. Using an EN 18031 standard therefore requires checking the Official Journal notices, not only the standard title.
The CRA standardisation request says CRA standards should build on RED delegated-regulation work where possible, while fully addressing CRA-specific requirements. A RED test report can support a CRA control only where the team maps the tested property to the relevant CRA requirement and identifies any gap.
Do not treat a RED EN 18031 mapping as a complete CRA file unless it also covers CRA risk assessment, support-period, vulnerability-handling, documentation, and reporting duties.
Do not duplicate engineering evidence unnecessarily; reuse test results or control mappings only after the CRA and RED legal bases are separately identified.
Keep the market-placement date and product category conclusion with the evidence, because the transition turns on when the individual product is placed on the market.
4
Section 4
Practical classification questions
Start with product facts. Identify whether the item intentionally emits or receives radio waves for radio communication or radiodetermination, whether it can communicate over the internet itself, whether it processes the data or payments that trigger Article 3(3)(e) or (f), whether it is a product with digital elements, and whether remote data processing is necessary for a product function.
Apply the dates to each individual unit or software product first placed on the EU market; an older model does not exempt newly placed units. Record separate conclusions for RED scope, CRA scope, the applicable date, the conformity route, and CRA reporting. A classification label such as "connected device" is not enough.
Is the product software, hardware, or a component placed on the market as a product with digital elements?
Is it radio equipment in a category covered by Delegated Regulation (EU) 2022/30?
Was the relevant unit or version placed on the market before 1 August 2025, between 1 August 2025 and 10 December 2027, or on or after 11 December 2027?
Does the planned release substantially modify a pre-11 December 2027 product, or is it only a non-substantial update?
If EN 18031 is used, which part applies and do any Official Journal limitations remove or narrow its ?
Which evidence proves the applicable RED essential requirements, CRA risk assessment, technical documentation, vulnerability handling, support period, CE marking, reporting, and market-surveillance response?