Discuss this signal with compliance peers, get the weekly digest, and never miss an enforcement deadline that affects your products.
The EU Radio Equipment Directive cybersecurity requirements became mandatory on August 1, 2025, establishing new security standards for IoT devices and connected products. These requirements will transition to the Cyber Resilience Act framework by 2027, fundamentally changing compliance obligations for manufacturers of radio equipment, smart devices, and connected products across the European market.
The Radio Equipment Directive (RED) 2014/53/EU originally focused on essential requirements for radio spectrum efficiency and electromagnetic compatibility. The rapid proliferation of IoT devices and increased connectivity exposed significant security vulnerabilities in connected products, prompting regulatory intervention. The European Commission recognised that traditional radio equipment approval processes were insufficient to address cybersecurity risks posed by billions of connected devices entering the market annually.
The expansion of RED with cybersecurity requirements represents the EU's first comprehensive attempt to regulate security standards for connected products at the point of market entry. This regulatory shift affects manufacturers who previously faced minimal cybersecurity obligations under product safety legislation.
The Commission Delegated Regulation (EU) 2022/30 introduced mandatory cybersecurity requirements under Article 3(3) of the Radio Equipment Directive. These requirements became enforceable on August 1, 2025, establishing three core security obligations: network security protection, personal data and privacy protection, and fraud prevention mechanisms.
The Cyber Resilience Act, adopted in 2024, will supersede these RED cybersecurity requirements when it becomes applicable in 2027. According to the European Commission's Q&A document, "the CRA will replace the cybersecurity requirements currently applicable under the Radio Equipment Directive for products with digital elements that fall within its scope."
Commission Delegated Regulation (EU) 2022/30 establishes cybersecurity requirements under Article 3(3)(d), (e), and (f) of Directive 2014/53/EU. These requirements apply to radio equipment that can connect to the internet or network infrastructure.
Article 3(3)(d) mandates that radio equipment "does not harm the network or its functioning, nor misuse network resources, thus avoiding damage to the network and deterioration of the service." Article 3(3)(e) requires "adequate safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected." Article 3(3)(f) demands "features that ensure protection from fraud."
The Cyber Resilience Act will establish a parallel framework with essential cybersecurity requirements for products with digital elements. The CRA introduces a risk-based approach with different conformity assessment procedures depending on the cybersecurity risk level of the product.
The cybersecurity requirements affect manufacturers of IoT devices, smart home applications, wearables, radio modules, routers, and connected products that previously faced minimal cybersecurity obligations. Products that can connect to networks or the internet fall within scope, regardless of their primary function.
Manufacturers must now demonstrate compliance through technical documentation, risk assessments, and conformity assessment procedures before placing products on the EU market. Non-compliance results in products being unable to bear CE marking, effectively blocking market access.
The transition to the Cyber Resilience Act will expand the scope beyond radio equipment to include all products with digital elements, potentially affecting software products, industrial control systems, and embedded systems that do not contain radio functionality.
Manufacturers must conduct cybersecurity risk assessments identifying potential vulnerabilities and implementing appropriate safeguards. Technical documentation must demonstrate how the product meets each of the three cybersecurity requirements under Article 3(3)(d), (e), and (f).
Conformity assessment procedures require manufacturers to apply harmonised standards where available or demonstrate compliance through alternative technical solutions. The EU Declaration of Conformity must explicitly reference compliance with the cybersecurity requirements.
Products must implement security by design principles, including secure default configurations, authentication mechanisms, and data protection measures. Manufacturers must establish processes for security updates and vulnerability management throughout the product lifecycle.
The RED cybersecurity requirements became mandatory on August 1, 2025. Products placed on the market after this date must comply with the new requirements. Products already on the market before August 1, 2025, benefit from a grace period but new stock must comply.
The Cyber Resilience Act will become applicable 36 months after its entry into force, expected in 2027. During the transition period, manufacturers must prepare for the new framework while maintaining compliance with existing RED requirements.
Market surveillance authorities have begun enforcement activities, with non-compliant products subject to corrective measures including market withdrawal. The European Commission has not published specific enforcement statistics for the initial implementation period.
The RED cybersecurity requirements apply uniformly across all EU member states and EEA countries. National market surveillance authorities implement enforcement according to their existing procedures for radio equipment compliance.
The Cyber Resilience Act will similarly apply across the EU with uniform requirements, though member states may maintain additional national cybersecurity regulations for specific sectors or critical infrastructure.
Manufacturers should immediately verify compliance status for all radio equipment products. Conduct comprehensive cybersecurity risk assessments for each product line, identifying network connectivity features and data processing capabilities.
Implement security by design principles in product development processes. Establish secure default configurations, authentication mechanisms, and encryption for data transmission. Document all cybersecurity measures in technical files supporting CE marking.
Prepare for the Cyber Resilience Act transition by monitoring the development of harmonised standards and conformity assessment procedures. Products currently compliant with RED cybersecurity requirements may require additional measures under the CRA framework.
Engage with notified bodies early to understand conformity assessment requirements. Current testing laboratory capacity for cybersecurity assessments remains limited, potentially creating bottlenecks for compliance verification.
Establish vulnerability management processes including security update mechanisms and incident response procedures. The CRA will mandate ongoing cybersecurity obligations throughout the product lifecycle, extending beyond initial market placement.