Artifact GuideEU RED

RED software update impact for radio equipment

Software and firmware changes need a RED impact review when they can change radio behavior, intended use, cybersecurity functions, charging information, user-configurable features, or the assessed equipment and software configuration.

This page helps decide when an update needs a conformity review, technical-file update, declaration update, standards check, or notified-body follow-up before release.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Under the Radio Equipment Directive, software belongs in the compliance record when it affects an essential requirement or allows the radio equipment to operate as intended. Review every release against the configuration that was assessed, documented, declared, and, where applicable, certified. Article 3(3)(i) is not a blanket ban on loading software: it allows the Commission to activate a for specified equipment categories. The Commission states that it paused that initiative in 2021 because of potential overlap with the Cyber Resilience Act and resumed it in 2023 after it was agreed that cybersecurity requirements would transfer from RED to the Cyber Resilience Act.

Section 1

When a software update can affect RED conformity

Assess each update as a product change. First determine whether it can alter an Article 3 requirement: health and safety, EMC, efficient spectrum use, an activated Article 3(3) requirement, or the common-charger information and charging-capability rules for covered equipment.

Annex V requires the to identify software or firmware versions that affect compliance with essential requirements. Article 10(5) separately requires series-production procedures to account adequately for changes in product design or characteristics and changes in or other technical specifications. The release record therefore matters even when the supported conclusion is that no retest, declaration change, or notified-body action is needed.

  • Review updates that change transmitter power, frequency bands, modulation, duty cycle, antenna behavior, receiver parameters, geofencing, or region selection.
  • During the RED cybersecurity period through 10 December 2027, review updates that change cybersecurity controls for internet-connected, data-processing, wearable, childcare, toy, or payment-capable radio equipment covered by Delegated Regulation (EU) 2022/30.
  • Review updates that add or remove user-installable software, companion-app control, accessories, components, charging behavior, restriction information, or operating modes described in the instructions or declaration.
  • Record a no-impact decision only when the assessed model, hardware variant, firmware or software version, intended use, standards coverage, and market information remain aligned.
Recommended next step

Review RED software-change evidence before release

Check whether a firmware, app, OTA, or configuration update changes the Article 3 matrix, standards evidence, technical file, declaration, notified-body record, or release approval for radio equipment.

Section 2

Update the technical file before release

The update record should let a reviewer connect the software release to the radio equipment type placed on the EU market. Keep the release identifier, affected models, affected hardware variants, changed radio or security functions, standards impact, test impact, impact, notified-body impact, approval owner, and release decision.

Annex V is the anchor for the file: it calls for a general product description, conceptual design and manufacturing materials, software or firmware versions affecting compliance, user and installation information, or other technical specifications, the EU declaration, material where applicable, calculations, examinations, and test reports. Article 21 requires the to be continuously updated. If the release changes any of those records, update the file instead of relying on release notes alone.

  • Link each software or firmware version that affects RED compliance to the exact model, type designation, hardware revision, region configuration, and release channel.
  • Add regression evidence for the Article 3 requirements touched by the change rather than retesting unrelated requirements by default.
  • Update instructions, safety information, restriction information, frequency-band and power information, and software descriptions when the user-facing compliance description changes.
  • Keep the and EU declaration available for 10 years after the radio equipment has been placed on the market.
Section 3

Check standards and notified-body consequences

A software update can reopen the conformity-assessment route if the change affects a requirement that was covered by a harmonised standard, a partly applied standard, a technical specification, an certificate, or a full-quality-assurance approval. RED gives presumption of conformity only for the essential requirements covered by OJEU-published or parts of standards.

For Article 3(2) and Article 3(3), the notified-body question is especially important. If relevant OJEU-cited are not applied, are applied only in part, or no such standards exist for the requirement being assessed, Article 17 points the manufacturer to Annex III or Annex IV rather than Annex II for those requirements. For Annex III, modifications to the approved type that may affect conformity or certificate validity require additional approval.

  • Compare the update against the exact standard versions, clauses, restrictions, and test configurations used for the current declaration.
  • If a standard has lost presumption of conformity for products not yet placed on the market, decide whether the updated product needs a new standard route or notified-body route.
  • For Annex III certificates, ask whether the update changes the approved type, certificate conditions, software version, radio configuration, or evidence reviewed by the notified body.
  • For Annex IV quality-system approvals, check whether the update changes a design, production, inspection, testing, or quality-system control covered by the approval.
Section 4

Common mistakes in RED software-change records

Firmware can affect RED conformity even when no physical component changes. It can alter radio parameters, EMC behavior, safety functions, cybersecurity controls, restrictions, charging behavior, instructions, and the evidence used to place the equipment on the Union market.

Not every update requires a new conformity assessment. The impact decision must explain why the existing Article 3 matrix, standards evidence, , , and notified-body records still cover the released configuration, or identify the additional work required before release.

If a released update leaves radio equipment already placed on the market non-conforming, Article 10(11) requires the manufacturer to take the corrective measures needed to bring it into conformity, withdraw it, or recall it if appropriate. Where the equipment presents a risk, the manufacturer must immediately inform the competent national authorities in the Member States where it was made available, with details of the non-compliance, corrective measures, and results.

  • Do not ship an over-the-air update that changes radio or security behavior without checking the assessed equipment and software configuration.
  • Do not leave the , instructions, software identifiers, or technical file pointing to an older firmware version when the update affects compliance evidence.
  • Do not rely on a supplier or lab statement unless it identifies the affected model, software version, requirement, standard, and test or assessment basis.
  • Do not cite a harmonised standard for presumption of conformity unless the reference is published for RED in the Official Journal and covers the requirement and product configuration being claimed.
  • After release, keep the decision open until any required field correction, authority notification, withdrawal, or recall is completed and the records the outcome.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Supports horizontal EU product-law context for manufacturer responsibility, technical documentation, declarations of conformity, and CE-marked product controls.
"The manufacturer is responsible"
eur-lex.europa.eu
Referenced sections
  • Supports Article 10(11) corrective measures, withdrawal, recall, and risk-notification duties, Article 21 continuous updating, and Annex V software or firmware documentation.
"continuously updated"
single-market-economy.ec.europa.eu
Referenced sections
  • Supports the role of notified bodies where third-party conformity assessment is required.
"assess the conformity"
single-market-economy.ec.europa.eu
Referenced sections
  • Supports RED implementation context, guidance links, harmonised-standard resources, and Commission warnings about conformity-assessment evidence.
"CE marking can only be affixed"
single-market-economy.ec.europa.eu
Referenced sections
  • Official status source stating that the Commission paused the Article 3(3)(i) and Article 4 software initiative in 2021 because of potential Cyber Resilience Act overlap and resumed it in 2023 after it was agreed that cybersecurity requirements would transfer from RED to the Cyber Resilience Act.
"this initiative was resumed"
Related guides

Explore more topics

Are radio kits and evaluation boards covered by the RED? | RED FAQ
RED FAQ for radio kits, construction kits, amateur-radio kits, and custom-built professional R&D evaluation boards under Directive 2014/53/EU.
EU Radio Equipment Directive Timeline: RED, Cyber and USB-C Dates
Understand which RED dates changed market-access rules, including 2016 application, the 2017 transition cutoff, common-charger dates, and cybersecurity requirements from 1 August 2025.
EU RED Applicability Test for Radio Equipment
Decide whether Directive 2014/53/EU applies to a connected product, which RED requirements are triggered, and what evidence belongs in the technical file.
EU RED Common Charger FAQ: Which devices need USB-C?
FAQ on EU RED common charger scope, 28 December 2024 and 28 April 2026 dates, USB-C, USB Power Delivery, charger unbundling, labels, pictograms, and evidence.
EU RED Common Charger Obligations: USB-C scope, dates, labels
Check RED common-charger device categories, application dates, USB-C and USB Power Delivery specifications, charger unbundling, consumer pictograms, labels, and release evidence.
EU RED compliance evidence guide
Build a Radio Equipment Directive compliance file with Article 3 requirement mapping, harmonised-standard checks, conformity assessment evidence, EU declarations, CE marking, and RED source links.
EU RED Cybersecurity Product Categories: 2022/30 scope
Classify products under RED Delegated Regulation (EU) 2022/30, including exclusions, EN 18031 evidence, and the 1 August 2025 to 10 December 2027 transition.
EU RED FAQ: Scope, CE and USB-C
Answers to common EU RED questions on radio equipment scope, Article 3 requirements, cybersecurity, USB-C common charger rules, CE marking, and technical-file evidence.
EU RED Radio Equipment Scope: products and exclusions
Decide whether a product is radio equipment under Directive 2014/53/EU, with RED scope tests, exclusions, examples, and evidence records.
EU RED Requirements Map: CE and Article 3
Map Radio Equipment Directive requirements for radio products: Article 3 safety, EMC, spectrum, selected Article 3(3) duties, common charger rules, conformity assessment, CE marking, EU declaration, and technical documentation.
EU RED Scope and Classification
Classify products under the EU Radio Equipment Directive with cited tests for radio equipment scope, exclusions, Article 3 requirement buckets, cybersecurity, common charging, and evidence records.
EU RED Scope Classification Workflow
Classify products under the EU Radio Equipment Directive with a cited workflow for RED scope, exclusions, Article 3 requirements, standards, CE evidence, cybersecurity, and common-charger triggers.
RED Article 10 labelling, instructions, and restrictions
Apply RED Article 10 to product identifiers, manufacturer contacts, instructions, declaration statements, radio-frequency information, charging labels, and use restrictions.
RED Article 3 requirement selection workflow
Select the right RED Article 3 branches for radio equipment: safety, EMC, spectrum, delegated Article 3(3) duties, cybersecurity, common charging, evidence, and conformity assessment.
RED Article 3 Requirements: Safety, EMC, Spectrum and Cyber
Map Radio Equipment Directive Article 3(1), 3(2), and 3(3) requirements to safety, EMC, spectrum, interoperability, emergency, software, and cyber evidence.
RED Compliance Checklist for Radio Equipment
Use this RED release checklist for product scope, Article 3 requirements, technical documentation, EU declarations, CE marking, cybersecurity, common charging, and notified-body decisions.
RED compliance deadlines calendar: 2016 to 2027
Calendar EU Radio Equipment Directive launch dates through 2027: RED applicability, common charger, cybersecurity, standards, CE marking, declarations and retention.
RED conformity assessment and CE marking
EU Radio Equipment Directive guide to Article 17 conformity modules, notified-body triggers, technical documentation, EU declarations, and CE marking.
RED Conformity Assessment Template
Template fields for documenting RED Article 3 requirements, Article 17 route selection, harmonised standards, notified-body evidence, technical documentation, EU declaration, CE marking, cybersecurity, and common-charger checks.
RED Cyber Compliance Workflow for Article 3(3)(d/e/f)
A cited RED cybersecurity workflow for internet-connected radio equipment, privacy and data safeguards, payment-fraud features, evidence packs, and CE release gates.
RED Cybersecurity Delegated Act Guide | Article 3(3)(d/e/f)
Guide to RED Article 3(3)(d), (e), and (f) scope, EN 18031 evidence, the 1 August 2025 application date, and repeal of Delegated Regulation (EU) 2022/30 from 11 December 2027.
RED Cybersecurity Requirements for Radio Equipment
EU RED cybersecurity requirements under Article 3(3)(d), (e), and (f): scope, affected radio equipment, application date, standards, notified bodies, and evidence.
RED DoC and CE marking file: what to include
FAQ answer for Radio Equipment Directive declarations of conformity, CE marking evidence, technical documentation, notified-body records, and related labels.
RED EMC and LVD Safety Interplay for Radio Equipment
Explain how EU RED Article 3 applies LVD safety objectives and EMC requirements to radio equipment, with evidence, test-plan, and technical-file guidance.
RED Harmonised Standards and Test Plans: OJEU evidence guide
Build a Radio Equipment Directive standards matrix and test plan around OJEU-cited harmonised standards, Article 3 requirements, Article 17 route triggers, and Annex V technical-file evidence.
RED importer obligations FAQ | Directive 2014/53/EU
What importers must check before placing radio equipment on the EU market: conformity assessment, spectrum use, technical documentation, EU declaration, CE marking, traceability, instructions, restrictions, storage, corrective action, and authority cooperation.
RED notified body route selection under Article 17
Decide when RED radio equipment can use internal production control and when Article 17 requires Annex III EU-type examination or Annex IV full quality assurance.
RED Notified Body Trigger Workflow: Article 17 evidence guide
Decide when the EU Radio Equipment Directive needs a notified body by mapping Article 3 requirements, OJEU-cited harmonised standards, Annex III EU-type examination, and Annex IV full quality assurance evidence.
RED penalties, fines, and enforcement actions
EU Radio Equipment Directive penalties guide covering Article 46, Member State penalty rules, recalls, withdrawals, formal non-compliance, and enforcement evidence.
RED radio modules FAQ: host product assessment
FAQ on how Directive 2014/53/EU treats RF modules and host products, including module evidence, final-product responsibility, Article 3 assessment, technical documentation, instructions, antennas, software, and DoC records.
RED SAR and RF Exposure Evidence FAQ
What SAR and RF exposure evidence to keep under the EU Radio Equipment Directive, including Article 3(1)(a), foreseeable use, frequency, power, antenna, and standards evidence.
RED standards not cited in the OJEU: can you use them?
FAQ answer for Radio Equipment Directive products when a standard is useful but not OJEU-cited, including presumption of conformity, Article 17 route selection, and technical-file evidence.
RED vs Cyber Resilience Act for radio equipment
Compare EU RED cybersecurity and Cyber Resilience Act duties for connected radio equipment, including scope, dates, evidence, reporting, and conformity routes.
RED vs EMC Directive: which law applies to radio equipment?
Decide when EU radio equipment uses RED instead of the EMC Directive and how to place EMC tests, declarations, fixed installations, and technical evidence.
RED vs ETSI EN 303 645: what the IoT standard proves
Compare binding EU RED cybersecurity duties with ETSI EN 303 645 consumer IoT standard, current editions, EN 18031, evidence reuse, and CE conformity.
RED vs LVD: electrical safety for radio equipment
Decide when EU radio equipment uses RED safety requirements instead of the Low Voltage Directive, including voltage limits, chargers, evidence, and declarations.
RED vs Market Surveillance Regulation for radio equipment
Compare RED product-conformity duties with Regulation (EU) 2019/1020 for responsible operators, online offers, customs controls, authority requests, and corrective action.
RED vs UK PSTI for connected radio products
Compare EU RED with the UK PSTI consumer connectable product regime, including scope, exclusions, passwords, updates, vulnerability reporting, evidence, and dates.
When do RED cybersecurity requirements apply to connected radio equipment? | RED FAQ
RED FAQ explaining when Article 3(3)(d), (e), and (f) cybersecurity requirements apply to internet-connected, childcare, toy, wearable, and payment-capable radio equipment.
Which receivers and transmitters are covered by RED? | Directive 2014/53/EU FAQ
RED scope FAQ for products that intentionally emit or receive radio waves for radio communication or radiodetermination, including receiver-only products, transmitters, accessory-dependent products, and common exclusions.
Wi-Fi and Bluetooth Products Under the EU RED
FAQ for assessing Wi-Fi, Bluetooth, BLE and other short-range wireless products under the EU Radio Equipment Directive, including Article 3, CE, technical file, cybersecurity and notified-body triggers.