- Primary source for the product-category matrix and Article 3(3)(d), (e), and (f) scoping questions.
"categories or classes of radio equipment"
Commission Delegated Regulation (EU) 2022/30 activates RED Article 3(3)(d), (e), and (f) for defined categories of radio equipment, including internet-connected products, childcare equipment, toy radio equipment, wearables, and payment-capable internet-connected radio equipment.
This page maps a product to the correct cybersecurity, privacy, and fraud-protection category, checks the exclusions, and explains the current 1 August 2025 to 10 December 2027 RED transition.
Structured answer sets in this page tree.
Cited legal and guidance references.
The RED cybersecurity category decision has three separate outputs. First confirm Directive 2014/53/EU scope. Then test whether the product is for Article 3(3)(d), whether a listed product can process personal, traffic, or location data for point (e), and whether it enables value transfers for point (f), before applying the sector exclusions. These requirements cover market placement from 1 August 2025 through 10 December 2027; repeal takes effect on 11 December 2027 without ending surveillance of equipment placed during that interval.
Delegated Regulation (EU) 2022/30 applies three different RED Article 3(3) points to different triggers. Article 3(3)(d), the network-protection requirement, applies when the equipment itself can exchange data with the internet, whether directly or through another product. A Bluetooth or Wi-Fi path through a phone or gateway can therefore qualify; local radio capability with no internet communication does not qualify on that fact alone.
Article 3(3)(e), the personal-data and privacy requirement, applies only when the covered radio equipment can process personal data, traffic data, or location data. The covered categories are , equipment designed or intended exclusively for childcare, equipment covered by the Toy Safety Directive, and equipment designed or intended, exclusively or not, to be worn on, strapped to, or hung from the body or clothing. Examples in the delegated act include child monitors and radio equipment in the form of a wristwatch, ring, wristband, headset, earphone, or glasses.
Article 3(3)(f), the fraud-protection requirement, applies to that enables the holder or user to transfer money, monetary value, or virtual currency. Ordinary online purchasing on a separate device, general internet access, or storage of account data does not establish this trigger without a product function that enables the transfer.
The delegated act includes targeted exclusions, so a product-category decision should not stop at the first apparent match. Radio equipment to which the Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation applies is excluded from all three requirements activated by Delegated Regulation (EU) 2022/30. The product must actually fall under the cited sector regulation; health-related marketing or use near a patient is not enough.
For Article 3(3)(e) and (f), the delegated act also excludes radio equipment to which the civil aviation safety regulation, motor-vehicle general safety type-approval regulation, or electronic road toll systems directive applies. Those sector exclusions do not remove Article 3(3)(d), and none erases RED generally; they narrow only the delegated act points named in Article 2.
Delegated Regulation (EU) 2023/2444 moved the application date to 1 August 2025. Delegated Regulation (EU) 2026/339 now repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, the date on which the Cyber Resilience Act applies in full.
For equipment placed on the Union market from 1 August 2025 through 10 December 2027, keep the RED Article 3(3)(d), (e), and (f) category decision and conformity evidence. The 2026 repeal expressly preserves market surveillance and control of compliance for equipment placed on the market during that period. Products placed on the market from 11 December 2027 need a fresh regime analysis rather than an assumption that the old RED category record alone covers the Cyber Resilience Act.
The evidence should let a reviewer repeat the category decision without reconstructing the product history. For each product family and market variant, keep the radio-equipment basis, network diagram, protocol and internet-communication analysis, data and sensor inventory, intended-use claims, childcare or toy classification, wearable design assessment, payment-transfer flow, exclusions checked, market-placement date, applicable Article 3(3) points, standards position, and conformity assessment route.
This page is a scope artifact, not a full security-control catalogue. The product file still needs the security design, test reports, standards mapping, supplier inputs, software-version evidence, EU declaration of conformity, and notified-body documentation where the chosen RED conformity assessment route requires it. EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 are OJEU-cited for the three cybersecurity requirements, but Commission Implementing Decision (EU) 2025/138 attaches restrictions. A standards matrix must capture those notices instead of treating an EN 18031 report as unrestricted presumption of conformity.
This RED category guide helps align product, regulatory, security, quality, legal, and supplier teams around Article 3(3)(d), (e), and (f) scope, exclusions, application timing, standards strategy, and retained evidence.
Answer RED cybersecurity scope, category, timing, and evidence questions with cited outputs.
Review your RED product-category matrix, exclusions, standards strategy, conformity route, and release evidence.
"categories or classes of radio equipment"
"It shall apply from 1 August 2025."
"repealed with effect from 11 December 2027"
"with restrictions"
"EU declaration of conformity"
"Commission Delegated Regulation (EU) 2022/30"
"activating Articles 3(3)(d), (e) and (f)"