Artifact GuideEU

EU RED cybersecurity product categories

Commission Delegated Regulation (EU) 2022/30 activates RED Article 3(3)(d), (e), and (f) for defined categories of radio equipment, including internet-connected products, childcare equipment, toy radio equipment, wearables, and payment-capable internet-connected radio equipment.

This page maps a product to the correct cybersecurity, privacy, and fraud-protection category, checks the exclusions, and explains the current 1 August 2025 to 10 December 2027 RED transition.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The RED cybersecurity category decision has three separate outputs. First confirm Directive 2014/53/EU scope. Then test whether the product is for Article 3(3)(d), whether a listed product can process personal, traffic, or location data for point (e), and whether it enables value transfers for point (f), before applying the sector exclusions. These requirements cover market placement from 1 August 2025 through 10 December 2027; repeal takes effect on 11 December 2027 without ending surveillance of equipment placed during that interval.

Section 1

Which product categories trigger Article 3(3)(d), (e), and (f)?

Delegated Regulation (EU) 2022/30 applies three different RED Article 3(3) points to different triggers. Article 3(3)(d), the network-protection requirement, applies when the equipment itself can exchange data with the internet, whether directly or through another product. A Bluetooth or Wi-Fi path through a phone or gateway can therefore qualify; local radio capability with no internet communication does not qualify on that fact alone.

Article 3(3)(e), the personal-data and privacy requirement, applies only when the covered radio equipment can process personal data, traffic data, or location data. The covered categories are , equipment designed or intended exclusively for childcare, equipment covered by the Toy Safety Directive, and equipment designed or intended, exclusively or not, to be worn on, strapped to, or hung from the body or clothing. Examples in the delegated act include child monitors and radio equipment in the form of a wristwatch, ring, wristband, headset, earphone, or glasses.

Article 3(3)(f), the fraud-protection requirement, applies to that enables the holder or user to transfer money, monetary value, or virtual currency. Ordinary online purchasing on a separate device, general internet access, or storage of account data does not establish this trigger without a product function that enables the transfer.

  • Use Article 3(3)(d) for , including products that reach the internet through other equipment.
  • Use Article 3(3)(e) only after confirming both a covered category and the ability to process personal data, traffic data, or location data.
  • Treat baby monitors and other exclusively childcare radio equipment as a separate Article 3(3)(e) category when they meet the data-processing condition, even if they are not internet-connected.
  • Treat toy radio equipment covered by Directive 2009/48/EC and wearable radio equipment as Article 3(3)(e) categories when the data-processing condition is met.
  • Use Article 3(3)(f) for that enables transfers of money, monetary value, or virtual currency.
Section 2

What exclusions should be checked before scoping a product in?

The delegated act includes targeted exclusions, so a product-category decision should not stop at the first apparent match. Radio equipment to which the Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation applies is excluded from all three requirements activated by Delegated Regulation (EU) 2022/30. The product must actually fall under the cited sector regulation; health-related marketing or use near a patient is not enough.

For Article 3(3)(e) and (f), the delegated act also excludes radio equipment to which the civil aviation safety regulation, motor-vehicle general safety type-approval regulation, or electronic road toll systems directive applies. Those sector exclusions do not remove Article 3(3)(d), and none erases RED generally; they narrow only the delegated act points named in Article 2.

  • Check Regulation (EU) 2017/745 and Regulation (EU) 2017/746 before applying Article 3(3)(d), (e), or (f) under this delegated act.
  • For Article 3(3)(e) and (f), also check Regulation (EU) 2018/1139, Regulation (EU) 2019/2144, and Directive (EU) 2019/520.
  • Record the exclusion analysis at product-family and variant level, because software, connectivity, payment, sensor, or market-positioning changes can alter the conclusion.
  • Do not use common-charger scope, CE-marking status, or generic IoT labels as substitutes for the delegated act category test.
Section 3

When do the cybersecurity category requirements apply?

Delegated Regulation (EU) 2023/2444 moved the application date to 1 August 2025. Delegated Regulation (EU) 2026/339 now repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, the date on which the Cyber Resilience Act applies in full.

For equipment placed on the Union market from 1 August 2025 through 10 December 2027, keep the RED Article 3(3)(d), (e), and (f) category decision and conformity evidence. The 2026 repeal expressly preserves market surveillance and control of compliance for equipment placed on the market during that period. Products placed on the market from 11 December 2027 need a fresh regime analysis rather than an assumption that the old RED category record alone covers the Cyber Resilience Act.

  • Use 1 August 2025 for the Delegated Regulation (EU) 2022/30 cybersecurity category application date.
  • Use 10 December 2027 as the last day before the delegated act's repeal takes effect; preserve evidence for equipment placed on the market during the RED cybersecurity period.
  • Keep the category decision, standards strategy, conformity assessment route, security test evidence, and EU declaration update aligned to that date.
  • Distinguish individual units placed on the market before 1 August 2025 from units first placed on the market on or after that date; continued availability of a product family does not answer when a particular unit was placed on the market.
  • Recheck the category decision when harmonised standards, product functions, payment flows, data processing, intended use, or exclusion status changes.
Section 4

What evidence should a product-category review retain?

The evidence should let a reviewer repeat the category decision without reconstructing the product history. For each product family and market variant, keep the radio-equipment basis, network diagram, protocol and internet-communication analysis, data and sensor inventory, intended-use claims, childcare or toy classification, wearable design assessment, payment-transfer flow, exclusions checked, market-placement date, applicable Article 3(3) points, standards position, and conformity assessment route.

This page is a scope artifact, not a full security-control catalogue. The product file still needs the security design, test reports, standards mapping, supplier inputs, software-version evidence, EU declaration of conformity, and notified-body documentation where the chosen RED conformity assessment route requires it. EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 are OJEU-cited for the three cybersecurity requirements, but Commission Implementing Decision (EU) 2025/138 attaches restrictions. A standards matrix must capture those notices instead of treating an EN 18031 report as unrestricted presumption of conformity.

  • Keep a dated category matrix that separately answers Article 3(3)(d), (e), and (f), rather than one combined yes/no cybersecurity label.
  • Attach product specifications showing radio function, direct and indirect internet paths, sensors, microphones, cameras, location features, cloud paths, payment flows, and intended user group.
  • Keep the exclusion check with citations to the sector legislation considered and the reason it did or did not apply.
  • Tie the result to release gates for design, firmware, app, cloud service, packaging claims, instructions, supplier declarations, standards updates, and conformity assessment.
  • Reopen the record after material firmware, hardware, data-processing, payment, accessory, intended-use, supplier, market, or legal-source changes.
Recommended next step

Turn RED cybersecurity scope into release evidence

This RED category guide helps align product, regulatory, security, quality, legal, and supplier teams around Article 3(3)(d), (e), and (f) scope, exclusions, application timing, standards strategy, and retained evidence.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Primary RED source for conformity assessment, EU declaration of conformity, CE marking, and technical documentation context.
"EU declaration of conformity"
single-market-economy.ec.europa.eu
Referenced sections
  • Commission RED overview noting the delegated act activation of Article 3(3)(d), (e), and (f) for certain categories of radio equipment.
"activating Articles 3(3)(d), (e) and (f)"
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016 to 2027
Calendar EU Radio Equipment Directive launch dates through 2027: RED applicability, common charger, cybersecurity, standards, CE marking, declarations and retention.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT standard, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.