ComparisonEU RED

RED vs ETSI EN 303 645 law versus IoT baseline

RED is binding EU product law. ETSI EN 303 645 is a consumer IoT cybersecurity baseline, not the harmonised RED cybersecurity standards series.

Use EN 303 645 to strengthen engineering evidence, but use the cited EN 18031 parts and RED conformity rules when making a presumption-of-conformity claim.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
12

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

can improve a consumer IoT security program, but it does not by itself establish RED conformity. RED Article 3(3)(d), (e), and (f) cybersecurity requirements apply to specified radio-equipment categories from 1 August 2025 through 10 December 2027. Delegated Regulation (EU) 2026/339 repeals the category act from 11 December 2027 and preserves RED surveillance for equipment placed on the market during that period. The standards cited for those requirements are EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024, subject to restrictions. ETSI published EN 303 645 V3.1.3 in September 2024; teams using the older V2.1.1 (2020-06) should identify the edition and assess the change before reusing results.

Side-by-side comparison

RED vs ETSI EN 303 645

RED is the legal market-access regime. EN 303 645 is a consumer IoT security baseline that can contribute evidence but does not replace RED or EN 18031.

Review all sources
First framework
EU RED

Binding law for radio equipment, including applicable cybersecurity requirements, conformity assessment, technical documentation, declaration, CE marking, and market surveillance.

Second framework
ETSI EN 303 645

A voluntary baseline standard for consumer IoT cybersecurity and data protection; current edition V3.1.3 (2024-09).

Comparison row 1

Scope

EU RED

Radio equipment placed on the EU market, with cyber points activated for specified categories.

ETSI EN 303 645

Consumer IoT devices and their relevant device, software, service, and data boundary.

Operational implication

A product can be in both scopes, one scope, or neither; document each test.

Comparison row 3

Requirement set

EU RED

Network protection, privacy and personal-data safeguards, and fraud protection for the specified Article 3(3) categories.

ETSI EN 303 645

Thirteen baseline subjects covering credentials, vulnerability disclosure, updates, secure design, data protection, resilience, deletion, maintenance, and input validation.

Operational implication

Map control by control; the two structures are not one-to-one.

Comparison row 4

RED standards route

EU RED

EN 18031-1, -2, and -3 are the cited RED cybersecurity standards, with restrictions.

ETSI EN 303 645

EN 303 645 can supply supporting control evidence but is not the cited RED cybersecurity series.

Operational implication

Check EN 18031 and Decision (EU) 2025/138 before claiming presumption of conformity.

Comparison row 5

Evidence and next step

EU RED

Keep the RED scope memo, Article 3 matrix, standards position, tests, risk analysis, technical file, declaration, and conformity-route evidence.

ETSI EN 303 645

Keep provision-by-provision applicability, implementation, test, architecture, service-boundary, and residual-risk evidence for the named edition.

Operational implication

Create a bridge table and close every RED gap not covered by the EN 303 645 assessment.

Practical decision rule

How should teams use EN 303 645 in a RED program?

  • Classify the finished product and map RED Article 3(3)(d), (e), and (f) first.
  • Name the EN 303 645 edition and assessed device-service boundary.
  • Use EN 18031 and its Official Journal restrictions for the RED standards claim.
  • Reuse EN 303 645 evidence only through a requirement-level bridge with documented residual gaps.
Section 2

Know what EN 303 645 evidence covers

EN 303 645 V3.1.3 groups its baseline provisions around thirteen subjects: no universal default passwords; a way to manage vulnerability reports; software updates; secure storage of sensitive security parameters; secure communications; a reduced exposed attack surface; software integrity; protection of personal data; resilience to outages; examination of system telemetry; deletion of user data; easier installation and maintenance; and validation of input data.

The modal verb matters. A provision using 'shall' is mandatory for a claim against the standard when it applies; a provision using 'should' is a recommendation, and the assessment should record whether it is followed and why. Explanatory text, examples, and notes help interpret the provision but do not create a RED presumption-of-conformity claim.

For each provision, the assessment should state whether it applies, how it is met, what evidence supports the answer, and which device, software, mobile app, cloud service, or communication path was included. An unchecked checklist or supplier declaration is not enough to show that the tested boundary matches the finished radio product.

  • Identify the exact edition because clause numbering, terminology, and assessment results can differ between V2.1.1 and V3.1.3.
  • Keep architecture, credential, update, vulnerability-disclosure, cryptography, data-flow, telemetry, resilience, deletion, and input-validation evidence with the assessment.
  • Record exclusions and unsupported services instead of marking the whole product conformant without a stated boundary.
Section 3

Bridge EN 303 645 to the actual RED standards route

Commission Implementing Decision (EU) 2025/138 cites the EN 18031 series for the RED cybersecurity requirements. EN 18031-1 addresses internet-connected radio equipment under Article 3(3)(d), EN 18031-2 addresses data-processing categories under Article 3(3)(e), and EN 18031-3 addresses internet-connected radio equipment processing virtual money or monetary value under Article 3(3)(f). The decision attaches restrictions, including limits involving passwords and parental or guardian access control.

EN 303 645 evidence can still be reused where the same control and system boundary support an EN 18031 requirement or another part of the RED technical case. The bridge must identify the RED point, EN 18031 clause, EN 303 645 provision, evidence item, product version, restriction, and remaining gap. If the applicable harmonised standard is not applied, is only partly applied, or does not cover the requirement because of a restriction, reassess the RED conformity route rather than claiming automatic presumption of conformity.

  • Use EN 18031 citation status, not the presence of an EN 303 645 report, to assess RED presumption of conformity.
  • Check each restriction in Implementing Decision (EU) 2025/138 against the product's password and access-control design.
  • Retest or update the bridge when firmware, associated services, credentials, update mechanisms, data flows, standards, or product boundaries change.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Repeals the RED cybersecurity category act from 11 December 2027 and preserves surveillance for covered equipment placed on the market through 10 December 2027.
eur-lex.europa.eu
Referenced sections
  • Annex V states the RED technical-documentation content.
etsi.org
Referenced sections
  • ETSI explains that harmonised standards take effect through Official Journal citation and that ETSI does not certify products.
etsi.org
Referenced sections
  • Clauses 5 and 6 contain the consumer IoT cybersecurity and data-protection provisions and their explanatory text.
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016 to 2027
Calendar EU Radio Equipment Directive launch dates through 2027: RED applicability, common charger, cybersecurity, standards, CE marking, declarations and retention.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED software update impact for radio equipment
Assess when firmware, app, and software updates can affect EU Radio Equipment Directive conformity, technical documentation, DoC, standards, and notified-body evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.