Artifact GuideEU RED

RED Cybersecurity Delegated Act Guide Article 3(3)(d/e/f)

Delegated Regulation (EU) 2022/30 activates three Radio Equipment Directive cybersecurity requirements for defined categories of radio equipment: network protection, personal-data and privacy safeguards, and protection from fraud.

This guide shows which connected, toy, childcare, wearable, or payment-capable radio products need Article 3(3)(d), (e), or (f) evidence during the RED cybersecurity transition.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

The requires a product-specific scope decision. Identify the radio equipment, decide which Article 3(3)(d), (e), and (f) requirements apply under Delegated Regulation (EU) 2022/30 as amended, and keep conformity evidence for the CE-marking route. The requirements have applied since 1 August 2025. Delegated Regulation (EU) 2026/339 repeals the act from 11 December 2027, when the Cyber Resilience Act applies in full, while preserving RED market surveillance for covered equipment placed on the market through 10 December 2027.

Section 1

What the delegated act adds to RED compliance

Directive 2014/53/EU already requires radio equipment to meet health and safety, electromagnetic compatibility, and efficient spectrum-use requirements. Article 3(3) also contains additional essential requirements for specified categories or classes of radio equipment, including points (d), (e), and (f).

Delegated Regulation (EU) 2022/30 specifies the categories or classes that must meet those three cybersecurity-related requirements. Delegated Regulation (EU) 2023/2444 moved the date of application to 1 August 2025 and corrected the Article 3(3)(e) data-processing trigger. Delegated Regulation (EU) 2026/339 repeals the category act from 11 December 2027 to avoid overlap with the Cyber Resilience Act.

  • Article 3(3)(d): radio equipment must not harm the network or its functioning, or misuse network resources in a way that causes unacceptable service degradation.
  • Article 3(3)(e): radio equipment must incorporate safeguards for the personal data and privacy of the user and subscriber when the delegated-act scope conditions are met.
  • Article 3(3)(f): radio equipment must support features ensuring protection from fraud when the delegated-act payment-transfer trigger is met.
  • Transition: retain the RED scope and conformity record for covered equipment placed on the Union market from 1 August 2025 through 10 December 2027; the repeal does not cancel surveillance of that equipment.
Section 2

Scope test for Article 3(3)(d), (e), and (f)

Start with the product, not the software feature list. Confirm that the item is radio equipment under RED and then test the delegated-act categories separately. One product can trigger more than one point.

For Article 3(3)(d), the trigger is internet-connected radio equipment: equipment that can communicate itself over the internet, directly or through other equipment. For Article 3(3)(e), the equipment must be capable of processing personal data, traffic data, or location data and fall into a specified category. For Article 3(3)(f), the trigger is internet-connected radio equipment that enables the holder or user to transfer money, monetary value, or virtual currency.

Apply the exclusions after the category test. Radio equipment also covered by the Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation is excluded from the delegated act's Article 3(3)(d), (e), and (f) requirements. Equipment also covered by the listed civil-aviation, motor-vehicle general-safety, or electronic-road-toll legislation is excluded from the activated Article 3(3)(e) and (f) requirements, but that second group is not excluded from Article 3(3)(d) on that basis.

  • Check Article 3(3)(d) for any internet-connected radio equipment, including products that reach the internet through an intermediate device.
  • Check Article 3(3)(e) for data-capable internet-connected radio equipment, radio equipment designed or intended exclusively for childcare, radio toys covered by Directive 2009/48/EC, and wearable radio equipment.
  • Check Article 3(3)(f) for internet-connected radio equipment that enables payment or transfer of money, monetary value, or virtual currency.
  • Document exclusions separately where another EU regime listed in Article 2 of Delegated Regulation (EU) 2022/30 removes equipment from some or all Article 3(3)(d/e/f) delegated-act categories.
Section 3

Evidence to keep in the RED technical file

The evidence pack should let a reviewer trace each Article 3(3)(d/e/f) conclusion from product facts to conformity evidence. Keep separate lines for network protection, data and privacy safeguards, and fraud protection so a missing payment feature, missing personal-data capability, or product-category exclusion is visible.

Where harmonised standards are used, keep the standard reference, edition, OJEU citation status, test plan, test report, and gap assessment. Implementing Decision (EU) 2025/138 cites EN 18031-1:2024 for Article 3(3)(d), EN 18031-2:2024 for Article 3(3)(e), and EN 18031-3:2024 for Article 3(3)(f), but with restrictions. The file must address the applicable notices on rationale and guidance sections, optional passwords, parental or guardian access control, and secure-update assessment. Where cited standards do not fully cover the requirement or are not used, record the alternative evidence and the required RED conformity route.

  • Product-scope memo: radio functions, internet path, intermediate equipment, sensors, data types, payment or value-transfer capability, intended users, and EU market role.
  • Article 3(3)(d/e/f) matrix: each point marked in scope, out of scope, or escalated, with the exact delegated-act trigger and evidence owner.
  • Cybersecurity evidence: network-abuse controls, authentication, access control, secure communications, update handling, vulnerability handling, privacy safeguards, and payment-fraud controls where relevant.
  • Conformity records: harmonised standards mapping, test reports, supplier inputs, risk assessment, notified-body certificate where applicable, EU declaration of conformity, and release approval.
Recommended next step

Map RED cybersecurity scope before release

Turn Article 3(3)(d), (e), and (f) into a product-specific evidence map for connected radio equipment, childcare devices, radio toys, wearables, and payment-capable products.

Section 4

Standards, notified bodies, and release gates

Make standards and notified-body decisions before release. The delegated act applies Article 3(3)(d/e/f) to defined product categories, while RED conformity-assessment rules determine how each manufacturer demonstrates compliance.

A cited EN 18031 standard does not automatically give unrestricted presumption of conformity. Compare the product implementation with every applicable notice in Implementing Decision (EU) 2025/138. If the cited standard does not cover the full requirement, Article 17 requires EU-type examination followed by conformity to type, or full quality assurance, for the affected Article 3(3) requirement.

  • Check whether cited harmonised standards cover the exact Article 3(3)(d/e/f) requirement and the product's intended use, radio functions, data flows, and payment features.
  • Use a notified-body route where Article 17 requires it because an applicable Article 3(3) harmonised standard is not used, is only partly used, or does not exist for the requirement.
  • Do not treat a generic cybersecurity certificate, supplier letter, penetration-test summary, or voluntary certificate as a substitute for RED conformity evidence unless it is mapped to the relevant essential requirement.
  • Reopen the file after firmware, cloud dependency, radio module, supplier, payment feature, user category, intended use, standard citation, or legal-scope changes.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Requires technical documentation, conformity assessment, EU declaration of conformity, instructions, identification, and authority-response documentation.
"technical documentation"
single-market-economy.ec.europa.eu
Referenced sections
  • Official Commission context for using harmonised standards and OJEU references to support presumption of conformity.
"Harmonised standards are European standards"
single-market-economy.ec.europa.eu
Referenced sections
  • Official Commission context for notified bodies and third-party conformity assessment under EU product rules.
"notified bodies"
single-market-economy.ec.europa.eu
Referenced sections
  • Commission RED page linking the RED guide, harmonised standards under RED, notified bodies, and warning against misleading voluntary certificates.
"Harmonised standards under the RED"
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016, 2024, 2025 and 2026 dates
Calendar the EU Radio Equipment Directive deadlines that affect launches: RED applicability, transition end, common charger dates, cybersecurity requirements, OJEU standards, CE marking, declarations and technical files.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT guidance, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.