RED cyber comparisonEU radio equipment

RED vs Cyber Resilience Act for connected radio equipment

A connected radio product can fall under both regimes. RED controls EU radio-equipment conformity; the Cyber Resilience Act adds lifecycle cybersecurity duties for products with digital elements.

Run two applicability checks, then reuse engineering evidence only where it supports a requirement under each legal instrument.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
12

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Many connected wireless products fall under both RED and the Cyber Resilience Act. RED applies because the product intentionally transmits or receives radio waves. The CRA can apply because it is a with a direct or indirect data connection. RED cybersecurity has applied to covered radio-equipment categories since 1 August 2025. CRA vulnerability and incident reporting starts on 11 September 2026, and its main obligations apply from 11 December 2027. Scope exclusions and transition rules still require a product-specific review.

Side-by-side comparison

RED vs Cyber Resilience Act for connected radio equipment

Use RED for radio-equipment market access and the CRA for lifecycle cybersecurity. Many connected wireless products need both.

Review all sources
First framework
EU RED

Directive 2014/53/EU controls radio-equipment safety, EMC, spectrum use, activated cybersecurity requirements, conformity assessment, technical documentation, declaration, and CE marking.

Second framework
Cyber Resilience Act

Regulation (EU) 2024/2847 controls cybersecurity for in-scope products with digital elements across design, production, market placement, vulnerability handling, support, and reporting.

Comparison row 1

Scope test

EU RED

Is the finished item radio equipment that intentionally emits or receives radio waves for radio communication or radiodetermination?

Cyber Resilience Act

Is it a whose intended or reasonably foreseeable use includes a direct or indirect data connection, and is no exclusion controlling?

Operational implication

Document both tests. Neither result determines the other.

Comparison row 2

Cybersecurity trigger

EU RED

Article 3(3)(d), (e), and (f) apply only to the categories specified by Delegated Regulation (EU) 2022/30.

Cyber Resilience Act

The CRA applies its essential cybersecurity requirements to in-scope products with digital elements, subject to its classifications, exclusions, and transition provisions.

Operational implication

A connected radio product may trigger both, but the requirement sets are not interchangeable.

Comparison row 3

Main manufacturer work

EU RED

Assess Article 3 conformity, prepare the technical file and EU declaration, affix CE marking, provide required instructions, and retain the records.

Cyber Resilience Act

Manage cybersecurity through the product lifecycle, set and document the support period, handle vulnerabilities, provide user information, complete conformity assessment, and report as required.

Operational implication

Assign regulatory, engineering, product-security, support, and incident-reporting owners explicitly.

Comparison row 4

Standards and conformity

EU RED

The EN 18031 series is cited for RED cybersecurity with restrictions. Check the exact part, clause, and restriction before relying on presumption of conformity.

Cyber Resilience Act

CRA harmonised standards can support presumption of conformity only within their cited scope. Product classification can change the available conformity route.

Operational implication

A standard test report is evidence, not a blanket legal conclusion.

Comparison row 5

Key dates

EU RED

The delegated RED cybersecurity requirements apply from 1 August 2025.

Cyber Resilience Act

CRA Chapter IV applies from 11 June 2026, Article 14 reporting from 11 September 2026, and the remaining provisions from 11 December 2027.

Operational implication

Use separate readiness gates and do not defer RED work to the CRA main application date.

Comparison row 6

Reusable evidence

EU RED

Risk analysis, threat models, security tests, standards mappings, and technical documentation must support the selected RED requirements and product boundary.

Cyber Resilience Act

The CRA can use many of the same engineering records, plus vulnerability handling, support-period, software-component, reporting, and lifecycle evidence.

Operational implication

Reuse the artifact only after recording which requirement it supports under each regime and what remains unproved.

Practical decision rule

What should a product team do?

  • Complete separate RED and CRA scope records for the finished product and each market version.
  • Meet the RED cybersecurity requirements already in force for covered radio equipment.
  • Prepare CRA reporting before 11 September 2026 and the broader CRA conformity work before 11 December 2027.
  • Link shared security evidence through a controlled mapping instead of treating either compliance conclusion as transferable.
Section 1

Decide scope under each instrument

RED starts with the radio function. Directive 2014/53/EU covers electrical or electronic products that intentionally emit or receive radio waves for radio communication or radiodetermination. Delegated Regulation (EU) 2022/30 then activates Article 3(3)(d), (e), and (f) for specified categories. Article 3(3)(d) covers internet-connected radio equipment; Article 3(3)(e) covers listed radio equipment that processes personal, traffic, or location data; and Article 3(3)(f) covers internet-connected radio equipment that enables transfers of money, monetary value, or virtual currency.

The CRA starts with a made available on the EU market whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. The boundary can include integrated remote data processing developed by or for the manufacturer when the product cannot perform one of its functions without that processing. For example, a connected camera and the manufacturer-controlled cloud function needed to deliver its advertised monitoring feature may need to be assessed together.

Regulation (EU) 2024/2847 contains exclusions and sector-specific rules, including for certain medical devices, vehicles, marine equipment, and aviation products. Natural or legal persons who only contribute source code to qualifying free and open-source software outside a commercial activity are also outside the Regulation, while open-source software stewards and commercial supply have specific treatment. A RED conclusion does not decide CRA scope, and a CRA exclusion does not remove RED duties.

  • Record the finished product, radio technologies, software and remote-processing functions, intended use, data connections, markets, and economic operators.
  • Map RED Article 3(3)(d), (e), and (f) separately; one product can trigger more than one point.
  • Check CRA exclusions, open-source treatment, product classification, and transition rules against Regulation (EU) 2024/2847 before assigning CRA deliverables.
Section 3

Plan the dates and evidence bridge

The RED cybersecurity delegated act has applied since 1 August 2025. The CRA entered into force on 10 December 2024. CRA Chapter IV provisions apply from 11 June 2026, Article 14 reporting duties apply from 11 September 2026, and the rest of the Regulation applies from 11 December 2027. Products placed on the market before 11 December 2027 are generally subject to the main CRA requirements only if substantially modified after that date, but Article 14 reporting applies to in-scope products placed on the market earlier as well.

From 11 September 2026, a manufacturer that becomes aware of an actively exploited vulnerability or a severe incident affecting product security must use the CRA reporting process. Article 14 requires an early warning within 24 hours and a fuller notification within 72 hours. The final report is due no later than 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability, or within one month after the incident notification for a severe incident.

Build an evidence bridge rather than a single compliance label. For each reused artifact, identify the product version, requirement, legal basis, test boundary, owner, date, standards status, and remaining gap. Reopen the bridge when connectivity, data processing, payment functions, firmware, support period, suppliers, or standards change.

  • Use 1 August 2025 as the RED cybersecurity application date for covered radio equipment.
  • Prepare CRA reporting processes before 11 September 2026 and the broader CRA conformity file before 11 December 2027.
  • Keep the RED technical documentation and EU declaration for 10 years after the radio equipment is placed on the market; track CRA record and support-period duties on their own basis.
Recommended next step

Turn both regimes into one evidence map

Keep separate RED and CRA requirements while linking each shared security artifact to the product version, legal basis, owner, and remaining gap.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding source for RED scope and conformity.
eur-lex.europa.eu
Referenced sections
  • Articles 10, 17, 18, and 19 and Annex V cover manufacturer duties, conformity assessment, the EU declaration, CE marking, and technical documentation.
digital-strategy.ec.europa.eu
Referenced sections
  • Official Commission explanation of the 24-hour early warning, 72-hour notification, and final-report deadlines that apply from 11 September 2026.
digital-strategy.ec.europa.eu
Referenced sections
  • The Commission overview confirms the 10 December 2024 entry into force, 11 September 2026 reporting date, and 11 December 2027 main application date.
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016, 2024, 2025 and 2026 dates
Calendar the EU Radio Equipment Directive deadlines that affect launches: RED applicability, transition end, common charger dates, cybersecurity requirements, OJEU standards, CE marking, declarations and technical files.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT guidance, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.