RED is binding EU product law. ETSI EN 303 645 is a consumer IoT cybersecurity baseline, not the harmonised RED cybersecurity standards series.
Use EN 303 645 to strengthen engineering evidence, but use the cited EN 18031 parts and RED conformity rules when making a presumption-of-conformity claim.
can improve a consumer IoT security program, but it does not by itself establish RED conformity. RED Article 3(3)(d), (e), and (f) cybersecurity requirements apply to specified radio-equipment categories from 1 August 2025 through 10 December 2027. Delegated Regulation (EU) 2026/339 repeals the category act from 11 December 2027 and preserves RED surveillance for equipment placed on the market during that period. The standards cited for those requirements are EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024, subject to restrictions. ETSI published EN 303 645 V3.1.3 in September 2024; teams using the older V2.1.1 (2020-06) should identify the edition and assess the change before reusing results.
Side-by-side comparison
RED vs ETSI EN 303 645
RED is the legal market-access regime. EN 303 645 is a consumer IoT security baseline that can contribute evidence but does not replace RED or EN 18031.
Binding law for radio equipment, including applicable cybersecurity requirements, conformity assessment, technical documentation, declaration, CE marking, and market surveillance.
Second framework
ETSI EN 303 645
A voluntary baseline standard for consumer IoT cybersecurity and data protection; current edition V3.1.3 (2024-09).
RED applies to radio equipment placed on the EU market. Delegated Regulation (EU) 2022/30 activates network-protection, privacy and personal-data, and fraud-protection requirements for specified categories. The manufacturer must decide which points apply to the finished radio equipment, complete the proper conformity assessment, prepare technical documentation, issue the EU declaration, and affix CE marking.
applies a baseline set of cybersecurity provisions to consumer IoT devices. Examples named by the standard include connected children's toys and baby monitors, safety products such as smoke detectors and door locks, smart cameras and televisions, speakers, home assistants, connected appliances, alarms, hubs, wearables, and trackers. A specific product can still sit outside the standard's consumer IoT boundary or need additional sector-specific controls.
The current V3.1.3 standard is outcome-focused and is intended to be complemented by more specific, testable requirements. It does not focus on prolonged or sophisticated attacks or attacks requiring sustained physical access. Its product and service boundary therefore needs to be stated rather than assumed.
Start with the RED radio-equipment and Article 3(3) scope decision.
Then record whether the product is consumer IoT and which EN 303 645 edition, provisions, associated services, and evidence are being assessed.
Do not label an EN 303 645 assessment as RED certification or CE approval.
EN 303 645 V3.1.3 groups its baseline provisions around thirteen subjects: no universal default passwords; a way to manage vulnerability reports; software updates; secure storage of sensitive security parameters; secure communications; a reduced exposed attack surface; software integrity; protection of personal data; resilience to outages; examination of system telemetry; deletion of user data; easier installation and maintenance; and validation of input data.
The modal verb matters. A provision using 'shall' is mandatory for a claim against the standard when it applies; a provision using 'should' is a recommendation, and the assessment should record whether it is followed and why. Explanatory text, examples, and notes help interpret the provision but do not create a RED presumption-of-conformity claim.
For each provision, the assessment should state whether it applies, how it is met, what evidence supports the answer, and which device, software, mobile app, cloud service, or communication path was included. An unchecked checklist or supplier declaration is not enough to show that the tested boundary matches the finished radio product.
Identify the exact edition because clause numbering, terminology, and assessment results can differ between V2.1.1 and V3.1.3.
Keep architecture, credential, update, vulnerability-disclosure, cryptography, data-flow, telemetry, resilience, deletion, and input-validation evidence with the assessment.
Record exclusions and unsupported services instead of marking the whole product conformant without a stated boundary.
Bridge EN 303 645 to the actual RED standards route
Commission Implementing Decision (EU) 2025/138 cites the EN 18031 series for the RED cybersecurity requirements. EN 18031-1 addresses internet-connected radio equipment under Article 3(3)(d), EN 18031-2 addresses data-processing categories under Article 3(3)(e), and EN 18031-3 addresses internet-connected radio equipment processing virtual money or monetary value under Article 3(3)(f). The decision attaches restrictions, including limits involving passwords and parental or guardian access control.
EN 303 645 evidence can still be reused where the same control and system boundary support an EN 18031 requirement or another part of the RED technical case. The bridge must identify the RED point, EN 18031 clause, EN 303 645 provision, evidence item, product version, restriction, and remaining gap. If the applicable harmonised standard is not applied, is only partly applied, or does not cover the requirement because of a restriction, reassess the RED conformity route rather than claiming automatic presumption of conformity.
Use EN 18031 citation status, not the presence of an EN 303 645 report, to assess RED presumption of conformity.
Check each restriction in Implementing Decision (EU) 2025/138 against the product's password and access-control design.
Retest or update the bridge when firmware, associated services, credentials, update mechanisms, data flows, standards, or product boundaries change.
Repeals the RED cybersecurity category act from 11 December 2027 and preserves surveillance for covered equipment placed on the market through 10 December 2027.