- Source for the separate Article 3(3)(d), (e), and (f) triggers and exclusions.
"monetary value or virtual currency"
Delegated Regulation (EU) 2022/30 activates three RED essential requirements for defined classes of radio equipment: network protection, personal-data and privacy safeguards, and protection from fraud.
This page helps separate the Article 3(3)(d), (e), and (f) triggers, identify excluded equipment, and keep technical-file evidence aligned with RED conformity assessment.
Structured answer sets in this page tree.
Cited legal and guidance references.
For equipment placed on the market from 1 August 2025 through 10 December 2027, apply the RED cybersecurity rules point by point: network protection under Article 3(3)(d), personal-data and privacy safeguards under point (e), and fraud protection under point (f). Record the category trigger and exclusion, product risks and controls, standards used, any restricted , the Article 17 route, released software version, and evidence retained.
Start with radio-equipment scope under Directive 2014/53/EU, then apply Delegated Regulation (EU) 2022/30 requirement by requirement. Article 3(3)(d) requires equipment not to harm networks or their functioning or misuse network resources in a way that causes unacceptable service degradation. Article 3(3)(e) requires safeguards for personal data and privacy. Article 3(3)(f) requires features that protect against fraud for the activated category. These are binding outcomes; the EN 18031 standards provide voluntary technical specifications.
The triggers differ. Article 3(3)(d) applies to internet-connected radio equipment. Article 3(3)(e) applies to internet-connected radio equipment, childcare radio equipment, radio toys, and wearable radio equipment when the equipment can process personal data, traffic data, or location data. Article 3(3)(f) applies to internet-connected radio equipment when it enables the holder or user to transfer money, monetary value, or virtual currency.
Use a product-specific Article 3(3) matrix. Keep the product model, hardware variants, firmware or software versions affecting compliance, direct and indirect connectivity paths, trust boundaries, exposed interfaces, sensors and data categories, payment functions, intended users, reasonably foreseeable misuse, standards used, test reports, and the reason each point is included or excluded.
RED Annex V already expects technical documentation to include a general description of the equipment, software or firmware versions affecting essential-requirement compliance, user information, design materials, harmonised standards applied in full or in part, other technical specifications where standards are not used, the EU declaration of conformity, relevant EU-type examination material, design calculations, examinations, and test reports.
Map each product version to Article 3(3)(d), (e), and (f), standards coverage, notified-body needs, test evidence, and technical-file records.
Harmonised standards are voluntary, but RED gives only for the essential requirements covered by harmonised standards whose references have been published in the Official Journal of the European Union. Commission Implementing Decision (EU) 2025/138 cites EN 18031-1:2024 for Article 3(3)(d), EN 18031-2:2024 for Article 3(3)(e), and EN 18031-3:2024 for Article 3(3)(f). Each citation has notices that exclude specified content or implementation choices from the presumption of conformity.
The notices exclude each standard's rationale and guidance sections from and restrict reliance when clauses 6.2.5.1 and 6.2.5.2 allow the user not to set and use a password. EN 18031-2 also loses presumption for specified toy and childcare access-control clauses when parental or guardian control is not ensured. EN 18031-3 does not confer presumption for its clause 6.3.2.4 secure-update assessment criteria. Read every notice attached to the exact cited standard and implementation.
If a manufacturer assesses Article 3(2) or Article 3(3) without applying the applicable published harmonised standards, applies them only in part, or leaves a requirement outside the citation's , RED Article 17 requires EU-type examination followed by conformity to type or full quality assurance for the affected requirements.
The main failure pattern is mixing all RED cybersecurity obligations into one undifferentiated statement. Reviewers need to see whether Article 3(3)(d), (e), and (f) were each assessed against the product's actual connectivity, data processing, user group, wearable or childcare use, toy status, and payment functionality.
Another common mistake is citing a cybersecurity framework or supplier certificate without showing how it maps to the RED essential requirement, exact product and software version, concrete controls and tests, residual gaps, and conformity-assessment route used for market placement.
"monetary value or virtual currency"
"traffic data or location data"
"test reports"
"presumption of conformity"
"Improve network resilience"
"assess the conformity"