When do RED cybersecurity requirements apply to connected radio equipment?
Start with Article 3(3)(d): it applies to any radio equipment that can communicate itself over the internet, whether directly or through another device. That trigger is about the equipment's own capability to exchange data with the internet, not merely whether the product is used near a network.
Then check Article 3(3)(e): it applies to covered equipment if it can process under GDPR, , or under the ePrivacy Directive. The covered categories are , radio equipment designed or intended exclusively for childcare, radio equipment covered by the Toy Safety Directive, and .
Finally check Article 3(3)(f): it applies to if the holder or user can use it to transfer money, monetary value, or virtual currency. These 2022/30 requirements apply to covered equipment placed on the market from 1 August 2025 through 10 December 2027.
Representative examples, subject to the product facts, include a Wi-Fi router or connected camera under point (d); a connected baby monitor, radio toy, fitness tracker, or smart watch that processes covered data under point (e); and a payment-capable smart watch or handheld terminal under point (f). The delegated categories and functions control, not the product label.
Apply the derogations point by point. Radio equipment also governed by the Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation is outside Article 3(3)(d), (e), and (f) under this delegated act. Equipment also governed by the listed aviation, vehicle type-approval, or electronic road-toll legislation is outside points (e) and (f), but not point (d).
From 11 December 2027, Delegated Regulation (EU) 2022/30 no longer specifies the RED cybersecurity categories. Its repeal does not stop RED surveillance of equipment placed from 1 August 2025 through 10 December 2027. For equipment first placed from 11 December 2027, perform a fresh Cyber Resilience Act and RED scope analysis rather than carrying the earlier category decision forward.
- Apply Article 3(3)(d) to for network protection and prevention of network-resource misuse.
- Apply Article 3(3)(e) when the covered category and data-processing trigger are both present.
- Apply Article 3(3)(f) when enables transfers of money, monetary value, or virtual currency.
- Check the derogations in Delegated Regulation (EU) 2022/30 before deciding which RED cybersecurity points apply; the medical-device derogation and the aviation, vehicle, and road-toll derogation do not cover the same points.
- Record the placing-on-the-market date and retain the RED cybersecurity evidence for covered equipment placed through 10 December 2027; reassess the governing law for equipment first placed from 11 December 2027.
When do RED cybersecurity requirements apply to connected radio equipment?
For covered equipment placed on the market from 1 August 2025 through 10 December 2027, Article 3(3)(d) applies to radio equipment that can communicate itself over the internet. Article 3(3)(e) applies when internet-connected, childcare, toy, or can process personal, traffic, or . Article 3(3)(f) applies when enables transfers of money, monetary value, or virtual currency. Delegated Regulation (EU) 2022/30 is repealed from 11 December 2027, so later placement needs a fresh Cyber Resilience Act and RED analysis.
What evidence should support this EU Radio Equipment Directive decision?
Keep a product-specific applicability memo that identifies the radio function, internet-communication capability, data types processed, childcare/toy/wearable status, payment-transfer functionality, any 2022/30 derogation considered, the Article 3(3) point applied, and the evidence used for the conclusion.
Do the medical, aviation, vehicle, and road-toll derogations remove the same RED cybersecurity duties?
No. Under Delegated Regulation (EU) 2022/30, radio equipment also governed by the EU Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation is outside points (d), (e), and (f). Equipment also governed by the listed aviation, vehicle type-approval, or electronic road-toll legislation is outside points (e) and (f), but point (d) still needs a separate decision.
Can the manufacturer use RED internal production control for cybersecurity?
Only when the Article 17 conditions are met. For Article 3(3) requirements, internal production control is available when the manufacturer applies the relevant harmonised standards in full. If a relevant standard is not applied, is only partly applied, or does not fully cover the requirement because of an Official Journal restriction, use an available route involving EU-type examination plus conformity to type or full quality assurance.
Binding RED source for Article 3 essential requirements and the legal basis for delegated acts activating Article 3(3)(d), (e), and (f).
Delegated source specifying the radio-equipment categories and classes for Article 3(3)(d), (e), and (f).
Amending source that changes the 2022/30 application date and corrects the Article 3(3)(e) data wording.
Repeals Delegated Regulation (EU) 2022/30 from 11 December 2027 and preserves RED surveillance for covered equipment placed during the 1 August 2025 to 10 December 2027 application interval.