Artifact GuideEU RED

RED cybersecurity requirements Article 3(3)(d), (e), and (f)

Delegated Regulation (EU) 2022/30 activates three RED essential requirements for defined classes of radio equipment: network protection, personal-data and privacy safeguards, and protection from fraud.

This page helps separate the Article 3(3)(d), (e), and (f) triggers, identify excluded equipment, and keep technical-file evidence aligned with RED conformity assessment.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

For equipment placed on the market from 1 August 2025 through 10 December 2027, apply the RED cybersecurity rules point by point: network protection under Article 3(3)(d), personal-data and privacy safeguards under point (e), and fraud protection under point (f). Record the category trigger and exclusion, product risks and controls, standards used, any restricted , the Article 17 route, released software version, and evidence retained.

Section 1

Which RED cybersecurity requirement applies?

Start with radio-equipment scope under Directive 2014/53/EU, then apply Delegated Regulation (EU) 2022/30 requirement by requirement. Article 3(3)(d) requires equipment not to harm networks or their functioning or misuse network resources in a way that causes unacceptable service degradation. Article 3(3)(e) requires safeguards for personal data and privacy. Article 3(3)(f) requires features that protect against fraud for the activated category. These are binding outcomes; the EN 18031 standards provide voluntary technical specifications.

The triggers differ. Article 3(3)(d) applies to internet-connected radio equipment. Article 3(3)(e) applies to internet-connected radio equipment, childcare radio equipment, radio toys, and wearable radio equipment when the equipment can process personal data, traffic data, or location data. Article 3(3)(f) applies to internet-connected radio equipment when it enables the holder or user to transfer money, monetary value, or virtual currency.

  • Record whether the device can communicate over the internet directly or through other equipment.
  • For Article 3(3)(e), document whether the equipment processes personal data, traffic data, or location data and whether it is internet-connected, childcare, toy, or wearable radio equipment.
  • For Article 3(3)(f), document the payment or value-transfer function; do not treat ordinary connectivity as enough for the fraud-protection trigger.
  • Check exclusions separately: equipment to which the Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation applies is excluded from points (d), (e), and (f); equipment covered by the cited civil aviation, vehicle type-approval, or electronic road toll legislation is excluded only from points (e) and (f).
  • Use the unit's market-placement date, not the product-family launch date. Delegated Regulation (EU) 2026/339 repeals the category act from 11 December 2027 and preserves RED surveillance for covered equipment placed on the market from 1 August 2025 through 10 December 2027. Equipment first placed from 11 December 2027 needs a fresh Cyber Resilience Act and RED analysis.
Section 2

What evidence should the technical file contain?

Use a product-specific Article 3(3) matrix. Keep the product model, hardware variants, firmware or software versions affecting compliance, direct and indirect connectivity paths, trust boundaries, exposed interfaces, sensors and data categories, payment functions, intended users, reasonably foreseeable misuse, standards used, test reports, and the reason each point is included or excluded.

RED Annex V already expects technical documentation to include a general description of the equipment, software or firmware versions affecting essential-requirement compliance, user information, design materials, harmonised standards applied in full or in part, other technical specifications where standards are not used, the EU declaration of conformity, relevant EU-type examination material, design calculations, examinations, and test reports.

  • Create a traceability table for Article 3(3)(d), (e), and (f) with the product facts, requirement conclusion, evidence file name, owner, and approval date.
  • For network protection, keep abuse-case analysis and test evidence for network harm, resource misuse, malicious traffic, denial of service, and service degradation risks relevant to the product's intended use and internet path.
  • For privacy and personal data, keep data inventory, sensor inventory, authentication, access-control, encryption, default-credential, and child/user data safeguards where those facts support the Article 3(3)(e) conclusion.
  • For fraud protection, keep evidence tied to the payment or value-transfer flow, including authentication, authorisation, transaction integrity, secure update, and transaction-abuse controls where the product enables transfers of money, monetary value, or virtual currency.
  • Keep vulnerability findings, control verification, residual-risk approvals, release sign-off, update authenticity evidence, supplier component records, and regression results with the exact firmware or software version assessed.
Recommended next step

Build a RED cybersecurity evidence file

Map each product version to Article 3(3)(d), (e), and (f), standards coverage, notified-body needs, test evidence, and technical-file records.

Section 3

How do standards and notified bodies affect the route?

Harmonised standards are voluntary, but RED gives only for the essential requirements covered by harmonised standards whose references have been published in the Official Journal of the European Union. Commission Implementing Decision (EU) 2025/138 cites EN 18031-1:2024 for Article 3(3)(d), EN 18031-2:2024 for Article 3(3)(e), and EN 18031-3:2024 for Article 3(3)(f). Each citation has notices that exclude specified content or implementation choices from the presumption of conformity.

The notices exclude each standard's rationale and guidance sections from and restrict reliance when clauses 6.2.5.1 and 6.2.5.2 allow the user not to set and use a password. EN 18031-2 also loses presumption for specified toy and childcare access-control clauses when parental or guardian control is not ensured. EN 18031-3 does not confer presumption for its clause 6.3.2.4 secure-update assessment criteria. Read every notice attached to the exact cited standard and implementation.

If a manufacturer assesses Article 3(2) or Article 3(3) without applying the applicable published harmonised standards, applies them only in part, or leaves a requirement outside the citation's , RED Article 17 requires EU-type examination followed by conformity to type or full quality assurance for the affected requirements.

  • List every harmonised standard used, the version, the OJEU citation status, the Article 3(3) point it covers, and any partial-use limits.
  • Where no published harmonised standard fully covers a triggered Article 3(3) requirement, plan either Annex III EU-type examination plus conformity to type or Annex IV full quality assurance.
  • Keep the notified-body certificate, annexes, evaluation limits, and change-approval records with the technical documentation when a notified-body route is used.
  • Reassess the file when firmware, hardware, interfaces, cloud dependencies, suppliers, data processing, intended users, payment features, threat assumptions, harmonised standards, law, or the approved type changes; also reopen it after a material vulnerability, incident, complaint, or authority request.
Section 4

Common documentation mistakes

The main failure pattern is mixing all RED cybersecurity obligations into one undifferentiated statement. Reviewers need to see whether Article 3(3)(d), (e), and (f) were each assessed against the product's actual connectivity, data processing, user group, wearable or childcare use, toy status, and payment functionality.

Another common mistake is citing a cybersecurity framework or supplier certificate without showing how it maps to the RED essential requirement, exact product and software version, concrete controls and tests, residual gaps, and conformity-assessment route used for market placement.

  • Do not cite the original 1 August 2024 application date without also applying the 2023 amendment that moved the date to 1 August 2025.
  • Do not assume every internet-connected product triggers Article 3(3)(f); the fraud requirement depends on transfer of money, monetary value, or virtual currency.
  • Do not rely on a generic cybersecurity test report if it omits the radio equipment model, firmware version, data categories, payment features, or Article 3(3) coverage.
  • Do not cite EN 18031 alone. Record the part used, its 2024 edition, the Article 3(3) point covered, and every Official Journal notice relevant to the product and implementation.
  • Do not use a non-OJEU or draft standard as if it automatically gives ; document the technical-specification route and notified-body implications.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Source for technical documentation, EU declaration of conformity, CE marking, and notified-body evidence records.
"test reports"
single-market-economy.ec.europa.eu
Referenced sections
  • Commission source explaining that notified bodies assess conformity where third-party assessment is required.
"assess the conformity"
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016, 2024, 2025 and 2026 dates
Calendar the EU Radio Equipment Directive deadlines that affect launches: RED applicability, transition end, common charger dates, cybersecurity requirements, OJEU standards, CE marking, declarations and technical files.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT guidance, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.