RED Cyber explained — cybersecurity for radio equipment
TL;DR — The RED cybersecurity delegated act adds mandatory security requirements to the EU's Radio Equipment Directive. It targets internet-connected radio devices — think IoT, wearables, connected toys, and wireless consumer products — requiring them to protect the network, safeguard personal data, and prevent fraud. It is a key stepping stone toward the broader CRA regime.
What is RED Cyber?
The Radio Equipment Directive (RED, 2014/53/EU) governs radio equipment placed on the EU market. A delegated act (2022/30) activates specific cybersecurity requirements under Article 3(3)(d), (e), and (f) of the RED — commonly called "RED Cyber."
It applies to radio equipment that can communicate over the internet, either directly or via other equipment.
Who is affected?
Manufacturers of internet-connected radio devices, including:
- Consumer IoT (smart home devices, sensors, cameras)
- Wearables and connected health devices
- Connected toys and childcare equipment
- Wireless consumer electronics
If your product has radio/wireless connectivity and touches the internet, RED Cyber likely applies.
What does RED Cyber require?
The delegated act activates three protection goals:
Article 3(3)(d) — Network protection. The device must not harm the network or its functioning, nor misuse network resources.
Article 3(3)(e) — Protection of personal data and privacy. The device must incorporate safeguards to protect personal data and users' privacy.
Article 3(3)(f) — Protection from fraud. The device must include features to minimise the risk of monetary fraud, such as unauthorised transactions.
Manufacturers demonstrate conformity, typically by applying harmonised standards where available, or otherwise involving a notified body.
RED Cyber and the CRA
RED Cyber is, in effect, an early and narrower cousin of the CRA. Both address product cybersecurity; RED Cyber focuses on connected radio equipment, while the CRA is horizontal across all products with digital elements. As the CRA phases in, it becomes the broader regime, but RED Cyber obligations remain relevant for radio equipment in the interim and where they apply.
The practical upshot: a connected radio device may need to satisfy RED Cyber and prepare for the CRA — with heavily overlapping evidence (secure design, vulnerability handling, risk assessment).
→ Related: The CRA explained
The three protection goals at a glance
| Article | Protection goal | What it means in practice |
|---|---|---|
| ▸ 3(3)(d) | Network | The device must not harm the network or misuse its resources |
| ▸ 3(3)(e) | Privacy | The device must safeguard personal data and users' privacy |
| ▸ 3(3)(f) | Fraud | The device must minimise the risk of monetary fraud |
These three goals translate into concrete engineering practices: secure defaults, authentication, encryption of sensitive data, and protection of transactional flows.
RED Cyber and the CRA — a timeline view
RED Cyber CRA (horizontal)
─────────────────▶ ─────────────────────────▶
Radio equipment, All products with
connected devices digital elements
│ │
└── narrower, earlier └── broader, phasing in
cybersecurity for 2026-2027
radio equipment
The two overlap heavily in intent. Evidence you build for RED Cyber — secure design, vulnerability handling, risk assessment — carries directly into CRA readiness. Treating them together avoids duplicated effort.
Frequently asked questions
My device uses Wi-Fi/Bluetooth but isn't "internet-connected" directly — am I in scope? Likely yes. The scope covers equipment that can communicate over the internet directly or via other equipment. Indirect connectivity counts.
Do I need a notified body? Where harmonised standards exist and you apply them fully, you may self-declare. Where they do not, or you deviate, notified-body involvement becomes more likely. Confirm against the current standards landscape.
If I'm preparing for the CRA, do I still need to worry about RED Cyber? While RED Cyber applies to your product, yes. The good news: the evidence is largely shared, so readiness for one advances the other.
What happens if my device fails to meet the requirements? Non-compliant radio equipment can be refused market access or withdrawn by market-surveillance authorities, and CE marking cannot be lawfully affixed. As with the CRA, a device blocked from the EU market is a commercial problem, not only a compliance one — which is why building the security evidence early matters.
Do the three protection goals apply to every connected device equally? The applicable goals depend on the device's function — for example, the fraud-protection goal is especially relevant to devices handling payments or transactions. Scoping determines which goals bite hardest for your specific product.
What conformity looks like in practice
Demonstrating RED Cyber conformity generally means one of two routes. Where harmonised standards exist and you apply them in full, you can self-declare conformity and affix the CE marking on that basis. Where such standards do not yet cover your case, or you deviate from them, a notified body typically becomes involved to assess conformity. Either way, you assemble a technical file evidencing how the device meets the three protection goals — the same discipline of documented, evidenced security that the CRA will expect more broadly.
Because the harmonised-standards landscape evolves, confirm the current position for your product category rather than assuming last year's answer still holds.
Key takeaways
- ▸ RED Cyber adds cybersecurity requirements to radio equipment via a delegated act.
- ▸ It targets internet-connected radio devices — IoT, wearables, connected consumer products.
- ▸ Three protection goals: network, privacy, fraud.
- ▸ Evidence built for RED Cyber carries forward to CRA readiness.
What to do now
- Confirm applicability — does your device have internet-connected radio capability?
- Map to the three protection goals — network, privacy, fraud.
- Apply harmonised standards where available; plan notified-body involvement where needed.
- Prepare for the CRA — the evidence you build for RED Cyber carries forward.
A free scope review shows how RED Cyber and the CRA jointly apply to your connected products.
→ Related: How EU compliance works
NexCyber provides a readiness analysis, not legal advice. Conformity assessment for radio equipment may involve harmonised standards and accredited notified bodies.
Last reviewed 2026-07-10.