Cyber workflowRED Article 3(3)(d/e/f)

RED cybersecurity compliance workflow

Build a release-ready evidence trail for radio equipment affected by Article 3(3)(d), (e), and (f) of Directive 2014/53/EU as activated by Commission Delegated Regulation (EU) 2022/30.

This workflow helps classify the product, decide which cyber requirements apply, capture safeguards and test evidence, and document the conformity-assessment route before CE release.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

RED cyber compliance starts by deciding whether the product is or falls within another category assigned to Article 3(3)(e). For each radio product, record whether Article 3(3)(d), (e), or (f) applies, why any derogation applies, which standards or notified-body route supports the claim, and where the evidence lives in the technical documentation.

Section 1

Classify the radio equipment against Article 3(3)(d), (e), and (f)

Start with the actual product architecture and user journey. Article 3(3)(d) applies to radio equipment that can communicate itself over the internet, directly or through other equipment. Article 3(3)(e) applies when a listed category can process personal data, traffic data, or location data; the listed categories are , equipment designed or intended exclusively for childcare, radio equipment covered by the Toy Safety Directive, and equipment designed or intended to be worn on, strapped to, or hung from the body or clothing. The last three categories do not need an internet connection to enter the Article 3(3)(e) test. Article 3(3)(f) applies to internet-connected radio equipment that enables the holder or user to transfer money, monetary value, or virtual currency.

The classification memo should be short enough to review at release, but detailed enough to show how firmware, companion apps, cloud services, sensors, payment functions, and user roles were considered.

  • Record whether the product can communicate over the internet directly or through another device.
  • For Article 3(3)(e), check internet-connected equipment, childcare equipment, toys with radio functions, and wearable radio equipment against the relevant data-processing facts.
  • For Article 3(3)(f), identify any function through which the equipment enables its holder or user to transfer money, monetary value, or virtual currency. A subscription or in-app purchase is relevant only if the radio equipment enables that transfer; the label alone does not decide applicability.
  • Document out-of-scope conclusions with the product facts and the exact legal source, not with labels such as low risk or not connected.
Section 2

Check derogations and the application date before opening release gates

Before assigning controls, confirm whether another EU regime removes the product from one or more RED cyber requirements. Delegated Regulation (EU) 2022/30 excludes radio equipment covered by medical-device and in vitro diagnostic medical-device rules from Article 3(3)(d), (e), and (f). It also excludes equipment covered by the cited aviation, motor-vehicle, and electronic-road-toll legislation from Article 3(3)(e) and (f).

The application date was changed by Commission Delegated Regulation (EU) 2023/2444. The requirements apply to covered equipment placed on the Union market from 1 August 2025 through 10 December 2027. Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30 from 11 December 2027, but expressly preserves RED market surveillance and compliance control for equipment placed on the market during that interval.

  • Keep a derogation decision row for each candidate regime rather than burying the answer in meeting notes.
  • If only Article 3(3)(e) or (f) is excluded, continue the Article 3(3)(d) network-harm analysis where the product is .
  • Tie release gates, supplier attestations, and test-plan due dates to the unit's market-placement date, using 1 August 2025 as the start of the delegated RED cyber period and 10 December 2027 as its last day.
  • For equipment first placed on the market from 11 December 2027, perform a fresh legal analysis under the Cyber Resilience Act and any remaining RED requirements instead of carrying forward the repealed category act as the sole basis.
  • Flag legal review when the product combines regulated medical, vehicle, aviation, tolling, payment, childcare, toy, wearable, or telecom-network functions.
Section 3

Build the Article 3(3)(d/e/f) evidence matrix

The evidence matrix should connect each applicable RED cyber requirement to concrete product evidence. A reviewer should be able to trace from the legal trigger to the product feature, safeguard, verification result, residual issue, release owner, and technical-documentation location.

Do not use a single cybersecurity policy as the only evidence. RED evidence should include product-specific architecture, firmware and software behavior, data flows, authentication and access controls, update behavior, abuse cases, test results, supplier inputs, and conformity-assessment decisions.

  • For Article 3(3)(d), capture network-resilience evidence showing how the equipment avoids harming networks, misusing network resources, or causing unacceptable degradation of service.
  • For Article 3(3)(e), capture product-specific safeguards for the personal data, traffic data, or location data the equipment can process. Authentication, access control, encryption, and protection against unauthorized transmission are evidence examples where the product design and risk analysis make them relevant; the delegated regulation does not prescribe that fixed control list.
  • For Article 3(3)(f), capture product-specific evidence that the equipment supports protection from fraud for the transfer function. User authentication, transaction authorization, and abuse testing are evidence examples, not mandatory wording or a complete control set.
  • Link each evidence row to a test report, design record, supplier declaration, software bill or version record, issue tracker item, risk decision, or technical-file section.
Recommended next step

Turn the RED cyber workflow into release evidence

Use Sorena to convert product facts, supplier inputs, standards decisions, and Article 3(3)(d/e/f) evidence into a reviewable RED cybersecurity pack.

Section 4

Choose the standards, notified-body, and CE documentation route

After classification and evidence mapping, decide how the manufacturer will demonstrate conformity. OJEU-cited harmonised standards give presumption of conformity only for the essential requirements and parts they cover. Standards are not mandatory, but Article 17 requires Annex III or Annex IV for an Article 3(3) requirement when the manufacturer does not apply the relevant cited standards, applies them only in part, or no such standards exist. Commission Implementing Decision (EU) 2025/138 cites EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 with notices that restrict presumption of conformity, so the standards record must identify the relevant part and every notice that affects the product's implementation.

Keep cyber evidence aligned with the broader RED technical documentation, EU declaration of conformity, CE marking decision, instructions, and post-release change controls. A firmware or cloud-service change can undermine the original evidence if the release process does not re-run the affected Article 3(3)(d/e/f) checks.

  • Record the exact harmonised standard, edition, OJEU citation status, requirement coverage, and test-lab output used for each claim.
  • Where no suitable harmonised standard is used, record the conformity-assessment module, notified-body involvement, certificate or opinion reference, and unresolved limitations.
  • Add a release hold if a cyber evidence row is missing, the product facts changed, a supplier component changed, or the standard cited no longer supports the claim.
  • After launch, re-run the workflow for security incidents, vulnerability fixes, material software updates, supplier substitutions, and authority or customer requests.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • General EU product-law guidance for manufacturer responsibility, conformity assessment, CE marking, and technical documentation.
"The manufacturer is responsible for the conformity assessment."
eur-lex.europa.eu
Referenced sections
  • Primary RED text defining the Article 3(3)(d), (e), and (f) essential requirements.
"radio equipment does not harm the network or its functioning"
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016 to 2027
Calendar EU Radio Equipment Directive launch dates through 2027: RED applicability, common charger, cybersecurity, standards, CE marking, declarations and retention.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT standard, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.