FAQEU

RED FAQ Cybersecurity Applicability

RED cybersecurity applicability turns on the product category and function, not on a generic connected-device label.

This FAQ helps decide whether Article 3(3)(d), (e), or (f) applies to covered equipment placed on the market from 1 August 2025 through 10 December 2027, before the cybersecurity category act is repealed.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 26, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 26, 2026
Overview

For equipment placed on the market from 1 August 2025 through 10 December 2027, RED cybersecurity requirements apply when radio equipment falls into the categories specified by Commission Delegated Regulation (EU) 2022/30, as amended by Commission Delegated Regulation (EU) 2023/2444. In practice, check three triggers: whether the equipment can communicate itself over the internet, whether it is internet-connected, childcare, toy, or capable of processing personal, traffic, or , and whether enables transfer of money, monetary value, or virtual currency. repeals the category act from 11 December 2027 while preserving RED surveillance of covered equipment placed during the earlier interval.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

When do RED cybersecurity requirements apply to connected radio equipment?

Start with Article 3(3)(d): it applies to any radio equipment that can communicate itself over the internet, whether directly or through another device. That trigger is about the equipment's own capability to exchange data with the internet, not merely whether the product is used near a network.

Then check Article 3(3)(e): it applies to covered equipment if it can process under GDPR, , or under the ePrivacy Directive. The covered categories are , radio equipment designed or intended exclusively for childcare, radio equipment covered by the Toy Safety Directive, and .

Finally check Article 3(3)(f): it applies to if the holder or user can use it to transfer money, monetary value, or virtual currency. These 2022/30 requirements apply to covered equipment placed on the market from 1 August 2025 through 10 December 2027.

Representative examples, subject to the product facts, include a Wi-Fi router or connected camera under point (d); a connected baby monitor, radio toy, fitness tracker, or smart watch that processes covered data under point (e); and a payment-capable smart watch or handheld terminal under point (f). The delegated categories and functions control, not the product label.

Apply the derogations point by point. Radio equipment also governed by the Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation is outside Article 3(3)(d), (e), and (f) under this delegated act. Equipment also governed by the listed aviation, vehicle type-approval, or electronic road-toll legislation is outside points (e) and (f), but not point (d).

From 11 December 2027, Delegated Regulation (EU) 2022/30 no longer specifies the RED cybersecurity categories. Its repeal does not stop RED surveillance of equipment placed from 1 August 2025 through 10 December 2027. For equipment first placed from 11 December 2027, perform a fresh Cyber Resilience Act and RED scope analysis rather than carrying the earlier category decision forward.

  • Apply Article 3(3)(d) to for network protection and prevention of network-resource misuse.
  • Apply Article 3(3)(e) when the covered category and data-processing trigger are both present.
  • Apply Article 3(3)(f) when enables transfers of money, monetary value, or virtual currency.
  • Check the derogations in Delegated Regulation (EU) 2022/30 before deciding which RED cybersecurity points apply; the medical-device derogation and the aviation, vehicle, and road-toll derogation do not cover the same points.
  • Record the placing-on-the-market date and retain the RED cybersecurity evidence for covered equipment placed through 10 December 2027; reassess the governing law for equipment first placed from 11 December 2027.

When do RED cybersecurity requirements apply to connected radio equipment?

For covered equipment placed on the market from 1 August 2025 through 10 December 2027, Article 3(3)(d) applies to radio equipment that can communicate itself over the internet. Article 3(3)(e) applies when internet-connected, childcare, toy, or can process personal, traffic, or . Article 3(3)(f) applies when enables transfers of money, monetary value, or virtual currency. Delegated Regulation (EU) 2022/30 is repealed from 11 December 2027, so later placement needs a fresh Cyber Resilience Act and RED analysis.

What evidence should support this EU Radio Equipment Directive decision?

Keep a product-specific applicability memo that identifies the radio function, internet-communication capability, data types processed, childcare/toy/wearable status, payment-transfer functionality, any 2022/30 derogation considered, the Article 3(3) point applied, and the evidence used for the conclusion.

Do the medical, aviation, vehicle, and road-toll derogations remove the same RED cybersecurity duties?

No. Under Delegated Regulation (EU) 2022/30, radio equipment also governed by the EU Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation is outside points (d), (e), and (f). Equipment also governed by the listed aviation, vehicle type-approval, or electronic road-toll legislation is outside points (e) and (f), but point (d) still needs a separate decision.

Can the manufacturer use RED internal production control for cybersecurity?

Only when the Article 17 conditions are met. For Article 3(3) requirements, internal production control is available when the manufacturer applies the relevant harmonised standards in full. If a relevant standard is not applied, is only partly applied, or does not fully cover the requirement because of an Official Journal restriction, use an available route involving EU-type examination plus conformity to type or full quality assurance.

Citations
Question 2

What facts decide RED cybersecurity applicability?

The first fact is whether the item is radio equipment under RED and can communicate itself over the internet. Delegated Regulation (EU) 2022/30 treats direct and indirect internet communication as relevant, so a device that reaches the internet through a phone, hub, gateway, or other intermediate equipment can still be internet-connected for this assessment.

The second fact is whether the equipment falls into a data-sensitive category. Article 3(3)(e) is not limited to ordinary internet-connected equipment; it also covers radio equipment designed or intended exclusively for childcare, radio equipment covered by the Toy Safety Directive, and when the data-processing trigger is met.

The third fact is payment capability. If enables the holder or user to transfer money, monetary value, or virtual currency, map Article 3(3)(f) separately from the network-protection and privacy/data-protection checks.

  • Record the communications path: direct internet access, phone bridge, hub, cloud gateway, or another intermediate path.
  • List the data types the equipment can process, including , , and where relevant.
  • State whether the product is intended for childcare, is a radio toy, is wearable, or supports payment or value-transfer flows.
  • Keep any exclusion or derogation analysis explicit; do not bury it in a generic RED checklist.
Citations
Question 3

Implementation checklist for RED cybersecurity applicability

Use a short applicability record before choosing standards, tests, or notified-body routes. The record should answer which Article 3(3) point applies and why, rather than saying only that the product is connected or cyber-relevant.

  • Confirm the product is radio equipment and identify the radio function, software version, and market-placement scenario.
  • Test the Article 3(3)(d) trigger: can the equipment communicate itself over the internet, directly or indirectly?
  • Test the Article 3(3)(e) trigger: is the equipment internet-connected, childcare, toy, or , and can it process personal, traffic, or ?
  • Test the Article 3(3)(f) trigger: can the holder or user transfer money, monetary value, or virtual currency through the internet-connected equipment?
  • Record the 1 August 2025 application date and the evidence source used for each yes, no, or escalation answer.
  • If relying on EN 18031-1, EN 18031-2, or EN 18031-3 for presumption of conformity, record the applicable 2024 part and the limitations published with its OJEU reference; applying a restricted option does not confer presumption for the affected requirement.
  • Reassess after changes to radio functions, internet paths, apps, cloud services, data fields, intended users, childcare or toy claims, wearability, payment functions, firmware, standards, or applicable sector legislation.
Citations
Recommended next step

Document the RED cybersecurity scope decision

Turn this RED cybersecurity FAQ into a repeatable applicability record for product, legal, quality, security, and regulatory teams. Keep the Article 3(3) trigger, product facts, citation, owner, and evidence together.

Question 4

Common mistakes in RED cybersecurity scope decisions

A single yes/no cybersecurity label hides the legal decision. The delegated act applies different Article 3(3) points to different equipment categories, so the record needs to show which point applies and which product fact triggered it.

  • Do not assume that every radio product with wireless connectivity is covered by every cybersecurity point.
  • Do not miss indirect internet communication through another device when applying Article 3(3)(d).
  • Do not apply Article 3(3)(e) without checking both the covered category and the personal, traffic, or location-data trigger.
  • Do not treat payment capability as only a software or service issue when the enables the transfer flow.
  • Do not use the original 1 August 2024 date after the 2023 amendment; use 1 August 2025.
Citations
Primary sources

References and citations

Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016 to 2027
Calendar EU Radio Equipment Directive launch dates through 2027: RED applicability, common charger, cybersecurity, standards, CE marking, declarations and retention.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT standard, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.