RED vs Cyber Resilience Act for connected radio equipment
A connected radio product can fall under both regimes. RED controls EU radio-equipment conformity; the Cyber Resilience Act adds lifecycle cybersecurity duties for products with digital elements.
Run two applicability checks, then reuse engineering evidence only where it supports a requirement under each legal instrument.
Many connected wireless products fall under both RED and the Cyber Resilience Act. RED applies because the product intentionally transmits or receives radio waves. The CRA can apply because it is a with a direct or indirect data connection. RED cybersecurity has applied to covered radio-equipment categories since 1 August 2025. CRA vulnerability and incident reporting starts on 11 September 2026, and its main obligations apply from 11 December 2027. Scope exclusions and transition rules still require a product-specific review.
Side-by-side comparison
RED vs Cyber Resilience Act for connected radio equipment
Use RED for radio-equipment market access and the CRA for lifecycle cybersecurity. Many connected wireless products need both.
Directive 2014/53/EU controls radio-equipment safety, EMC, spectrum use, activated cybersecurity requirements, conformity assessment, technical documentation, declaration, and CE marking.
Second framework
Cyber Resilience Act
Regulation (EU) 2024/2847 controls cybersecurity for in-scope products with digital elements across design, production, market placement, vulnerability handling, support, and reporting.
RED vs Cyber Resilience Act for connected radio equipment
The CRA applies its essential cybersecurity requirements to in-scope products with digital elements, subject to its classifications, exclusions, and transition provisions.
Manage cybersecurity through the product lifecycle, set and document the support period, handle vulnerabilities, provide user information, complete conformity assessment, and report as required.
The EN 18031 series is cited for RED cybersecurity with restrictions. Check the exact part, clause, and restriction before relying on presumption of conformity.
CRA harmonised standards can support presumption of conformity only within their cited scope. Product classification can change the available conformity route.
Risk analysis, threat models, security tests, standards mappings, and technical documentation must support the selected RED requirements and product boundary.
The CRA can use many of the same engineering records, plus vulnerability handling, support-period, software-component, reporting, and lifecycle evidence.
The CRA applies its essential cybersecurity requirements to in-scope products with digital elements, subject to its classifications, exclusions, and transition provisions.
Manage cybersecurity through the product lifecycle, set and document the support period, handle vulnerabilities, provide user information, complete conformity assessment, and report as required.
Assign regulatory, engineering, product-security, support, and incident-reporting owners explicitly.
Comparison row 4
Standards and conformity
EU RED
The EN 18031 series is cited for RED cybersecurity with restrictions. Check the exact part, clause, and restriction before relying on presumption of conformity.
CRA harmonised standards can support presumption of conformity only within their cited scope. Product classification can change the available conformity route.
Use separate readiness gates and do not defer RED work to the CRA main application date.
Comparison row 6
Reusable evidence
EU RED
Risk analysis, threat models, security tests, standards mappings, and technical documentation must support the selected RED requirements and product boundary.
The CRA can use many of the same engineering records, plus vulnerability handling, support-period, software-component, reporting, and lifecycle evidence.
RED starts with the radio function. Directive 2014/53/EU covers electrical or electronic products that intentionally emit or receive radio waves for radio communication or radiodetermination. Delegated Regulation (EU) 2022/30 then activates Article 3(3)(d), (e), and (f) for specified categories. Article 3(3)(d) covers internet-connected radio equipment; Article 3(3)(e) covers listed radio equipment that processes personal, traffic, or location data; and Article 3(3)(f) covers internet-connected radio equipment that enables transfers of money, monetary value, or virtual currency.
The CRA starts with a made available on the EU market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. The boundary can include integrated remote data processing developed by or for the manufacturer when the product cannot perform one of its functions without that processing. For example, a connected camera and the manufacturer-controlled cloud function needed to deliver its advertised monitoring feature may need to be assessed together.
Regulation (EU) 2024/2847 contains exclusions and sector-specific rules, including for certain medical devices, vehicles, marine equipment, and aviation products. Natural or legal persons who only contribute source code to qualifying free and open-source software outside a commercial activity are also outside the Regulation, while open-source software stewards and commercial supply have specific treatment. A RED conclusion does not decide CRA scope, and a CRA exclusion does not remove RED duties.
Record the finished product, radio technologies, software and remote-processing functions, intended use, data connections, markets, and economic operators.
Map RED Article 3(3)(d), (e), and (f) separately; one product can trigger more than one point.
Check CRA exclusions, open-source treatment, product classification, and transition rules against Regulation (EU) 2024/2847 before assigning CRA deliverables.
Under RED, the manufacturer identifies the applicable Article 3 requirements, completes the Article 17 conformity assessment, prepares technical documentation, issues an EU declaration of conformity, and affixes CE marking. For the delegated cybersecurity requirements, EN 18031-1, EN 18031-2, and EN 18031-3 are cited with restrictions in Implementing Decision (EU) 2025/138. A restricted or partial standards claim may affect the available presumption of conformity and the RED conformity route.
The CRA requires manufacturers to address cybersecurity across planning, design, development, production, delivery, and maintenance; document conformity; handle vulnerabilities during the support period; provide required user information; and meet the applicable reporting duties. The support period must reflect expected use and is generally at least five years from market placement; it may match a shorter expected use for a product expected to be used for less than five years and should be longer where the product is reasonably expected to remain in use longer.
CRA classification changes the conformity route. General products can use internal control. Important Class I products can use internal control only when the manufacturer fully applies applicable harmonised standards, common specifications, or qualifying European cybersecurity certification; other routes require third-party assessment. Important Class II and critical products have stricter routes under Articles 32 and 33. One CE marking can indicate conformity with all applicable EU harmonisation acts, but the technical reasoning must still show how each act is satisfied.
Maintain a RED requirements matrix and a CRA requirements matrix, even if they link to the same threat model, test report, software bill of materials, or vulnerability record.
Record the exact EN 18031 part and every applicable restriction before claiming RED presumption of conformity.
Do not describe a product as CRA-compliant solely because it has passed RED cybersecurity testing.
The RED cybersecurity delegated act has applied since 1 August 2025. The CRA entered into force on 10 December 2024. CRA Chapter IV provisions apply from 11 June 2026, Article 14 reporting duties apply from 11 September 2026, and the rest of the Regulation applies from 11 December 2027. Products placed on the market before 11 December 2027 are generally subject to the main CRA requirements only if substantially modified after that date, but Article 14 reporting applies to in-scope products placed on the market earlier as well.
From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability or a severe incident affecting product security must use the CRA reporting process. Article 14 requires an early warning within 24 hours and a fuller notification within 72 hours. The final report is due no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the incident notification for a severe incident.
Build an evidence bridge rather than a single compliance label. For each reused artifact, identify the product version, requirement, legal basis, test boundary, owner, date, standards status, and remaining gap. Reopen the bridge when connectivity, data processing, payment functions, firmware, support period, suppliers, or standards change.
Use 1 August 2025 as the RED cybersecurity application date for covered radio equipment.
Prepare CRA reporting processes before 11 September 2026 and the broader CRA conformity file before 11 December 2027.
Keep the RED technical documentation and EU declaration for 10 years after the radio equipment is placed on the market; track CRA record and support-period duties on their own basis.