Home RED

RED

Radio Equipment Directive - cybersecurity obligations for connected products.
By Eliseo Thrope
2 articles

RED Cyber explained — cybersecurity for radio equipment

RED Cyber explained — cybersecurity for radio equipment TL;DR — The RED cybersecurity delegated act adds mandatory security requirements to the EU's Radio Equipment Directive. It targets internet-connected radio devices — think IoT, wearables, connected toys, and wireless consumer products — requiring them to protect the network, safeguard personal data, and prevent fraud. It is a key stepping stone toward the broader CRA regime. What is RED Cyber? The Radio Equipment Directive (RED, 2014/53/EU) governs radio equipment placed on the EU market. A delegated act (2022/30) activates specific cybersecurity requirements under Article 3(3)(d), (e), and (f) of the RED — commonly called "RED Cyber." It applies to radio equipment that can communicate over the internet, either directly or via other equipment. Who is affected? Manufacturers of internet-connected radio devices, including: - Consumer IoT (smart home devices, sensors, cameras) - Wearables and connected health devices - Connected toys and childcare equipment - Wireless consumer electronics If your product has radio/wireless connectivity and touches the internet, RED Cyber likely applies. What does RED Cyber require? The delegated act activates three protection goals: Article 3(3)(d) — Network protection. The device must not harm the network or its functioning, nor misuse network resources. Article 3(3)(e) — Protection of personal data and privacy. The device must incorporate safeguards to protect personal data and users' privacy. Article 3(3)(f) — Protection from fraud. The device must include features to minimise the risk of monetary fraud, such as unauthorised transactions. Manufacturers demonstrate conformity, typically by applying harmonised standards where available, or otherwise involving a notified body. RED Cyber and the CRA RED Cyber is, in effect, an early and narrower cousin of the CRA. Both address product cybersecurity; RED Cyber focuses on connected radio equipment, while the CRA is horizontal across all products with digital elements. As the CRA phases in, it becomes the broader regime, but RED Cyber obligations remain relevant for radio equipment in the interim and where they apply. The practical upshot: a connected radio device may need to satisfy RED Cyber and prepare for the CRA — with heavily overlapping evidence (secure design, vulnerability handling, risk assessment). → Related: The CRA explained The three protection goals at a glance | Article | Protection goal | What it means in practice | |---|---|---| | ▸ 3(3)(d) | Network | The device must not harm the network or misuse its resources | | ▸ 3(3)(e) | Privacy | The device must safeguard personal data and users' privacy | | ▸ 3(3)(f) | Fraud | The device must minimise the risk of monetary fraud | These three goals translate into concrete engineering practices: secure defaults, authentication, encryption of sensitive data, and protection of transactional flows. RED Cyber and the CRA — a timeline view RED Cyber CRA (horizontal) ─────────────────▶ ─────────────────────────▶ Radio equipment, All products with connected devices digital elements │ │ └── narrower, earlier └── broader, phasing in cybersecurity for 2026-2027 radio equipment The two overlap heavily in intent. Evidence you build for RED Cyber — secure design, vulnerability handling, risk assessment — carries directly into CRA readiness. Treating them together avoids duplicated effort. Frequently asked questions My device uses Wi-Fi/Bluetooth but isn't "internet-connected" directly — am I in scope? Likely yes. The scope covers equipment that can communicate over the internet directly or via other equipment. Indirect connectivity counts. Do I need a notified body? Where harmonised standards exist and you apply them fully, you may self-declare. Where they do not, or you deviate, notified-body involvement becomes more likely. Confirm against the current standards landscape. If I'm preparing for the CRA, do I still need to worry about RED Cyber? While RED Cyber applies to your product, yes. The good news: the evidence is largely shared, so readiness for one advances the other. What happens if my device fails to meet the requirements? Non-compliant radio equipment can be refused market access or withdrawn by market-surveillance authorities, and CE marking cannot be lawfully affixed. As with the CRA, a device blocked from the EU market is a commercial problem, not only a compliance one — which is why building the security evidence early matters. Do the three protection goals apply to every connected device equally? The applicable goals depend on the device's function — for example, the fraud-protection goal is especially relevant to devices handling payments or transactions. Scoping determines which goals bite hardest for your specific product. What conformity looks like in practice Demonstrating RED Cyber conformity generally means one of two routes. Where harmonised standards exist and you apply them in full, you can self-declare conformity and affix the CE marking on that basis. Where such standards do not yet cover your case, or you deviate from them, a notified body typically becomes involved to assess conformity. Either way, you assemble a technical file evidencing how the device meets the three protection goals — the same discipline of documented, evidenced security that the CRA will expect more broadly. Because the harmonised-standards landscape evolves, confirm the current position for your product category rather than assuming last year's answer still holds. Key takeaways - ▸ RED Cyber adds cybersecurity requirements to radio equipment via a delegated act. - ▸ It targets internet-connected radio devices — IoT, wearables, connected consumer products. - ▸ Three protection goals: network, privacy, fraud. - ▸ Evidence built for RED Cyber carries forward to CRA readiness. What to do now 1. Confirm applicability — does your device have internet-connected radio capability? 2. Map to the three protection goals — network, privacy, fraud. 3. Apply harmonised standards where available; plan notified-body involvement where needed. 4. Prepare for the CRA — the evidence you build for RED Cyber carries forward. A free scope review shows how RED Cyber and the CRA jointly apply to your connected products. → Related: How EU compliance works NexCyber provides a readiness analysis, not legal advice. Conformity assessment for radio equipment may involve harmonised standards and accredited notified bodies. Last reviewed 2026-07-10.

Last updated on Jul 13, 2026

RED Cyber — EN 18031 standards and conformity routes, deep dive

In one paragraph The Radio Equipment Directive (RED) cybersecurity delegated act activates Article 3(3)(d), (e), (f). The EN 18031 series of harmonised standards translates these requirements into testable specifications. This article walks the series, the conformity routes, and the evidence NexCyber tracks per route. The three articles activated - Article 3(3)(d) — network protection. The equipment does not harm the network and is robust against network attacks. - Article 3(3)(e) — personal data and privacy. The equipment safeguards stored or transmitted personal data. - Article 3(3)(f) — fraud protection. The equipment protects against monetary fraud where it enables monetary transactions. Different product categories trigger different combinations. The EN 18031 series EN 18031 is a three-part harmonised standard: - EN 18031-1 — common security requirements for internet-connected radio equipment (covers Article 3(3)(d)). - EN 18031-2 — security requirements for processing personal data, location data, or traffic data (covers Article 3(3)(e)). - EN 18031-3 — security requirements for radio equipment allowing the user to transfer money, monetary value, or virtual currency (covers Article 3(3)(f)). Conformity to the relevant parts grants presumption of conformity with the RED essential requirements activated by the delegated act. Conformity routes A manufacturer can choose between several routes for assessing conformity: - Module A — Internal production control. Manufacturer's self-declaration based on internal control. Allowed when the manufacturer applies harmonised standards in full. - Module B + C — EU-type examination plus conformity to type based on internal production control. Notified body involvement at type level. - Module H — Full quality assurance. Notified body involvement on the manufacturer's quality system. The choice depends on whether harmonised standards are applied in full, whether the product is in scope of further mandatory routes, and on the manufacturer's quality-system maturity. How NexCyber tracks conformity evidence per route Module A Evidence we expect: - Technical documentation that demonstrates application of EN 18031 in full. - Test reports (typically from in-house or accredited labs). - Manufacturer's signed declaration of conformity. - Annexes: SBOM, vulnerability handling policy, change management records. Module B + C Evidence we expect: - Notified body type-examination certificate. - Type-test reports. - Production control records demonstrating conformity to the approved type. - Surveillance reports if applicable. Module H Evidence we expect: - Quality system certificate from a notified body. - Quality system documentation (procedures, audit reports, management review records). - Sample production records showing the QMS in action. NexCyber stores the artefacts in the evidence workspace, links them to the obligation, and shows the confidence per item. Where RED Cyber meets CRA For most connected radio products, CRA also applies. The overlap is significant: technical documentation, SBOM, vulnerability handling, security update policy. NexCyber detects the overlap and maps a single evidence item across both regulations. A practical sequence: 1. Confirm RED Cyber applicability in the scope review. 2. Pick a conformity route. 3. Reuse the technical file and SBOM across RED Cyber and CRA. 4. Track notified body involvement where the route requires it. Manufacturer responsibilities Even with the most favourable route, the manufacturer retains responsibilities: - Initial conformity assessment before placing on the market. - Continued conformity through the lifecycle. - Vulnerability handling, security updates, end-of-support communication. - Cooperation with market surveillance authorities. NexCyber surfaces each responsibility in the assessment. Importers and distributors Importers and distributors also carry obligations: verifying the manufacturer's documentation, ensuring marking, refraining from placing non-conforming products on the market. NexCyber supports importer / distributor workspaces with the same evidence model. Post-market obligations - Monitoring for issues with the product. - Vulnerability disclosure channel. - Remediation through security updates. - Reporting actively exploited vulnerabilities and severe incidents where required. NexCyber tracks the post-market plan and the field metrics. What RED Cyber via NexCyber does NOT do - It does not perform the harmonised-standard tests. Test labs do. - It does not issue CE marking decisions. Manufacturers and notified bodies do. - It does not interpret borderline category questions; it flags them for human regulatory triage. Common pitfalls - Applying EN 18031 partially and claiming Module A. - Stale SBOM that no longer matches the firmware shipped. - Notified body involvement booked too late for the release schedule. - No documented vulnerability handling channel at end of support. Related articles - RED Cyber basics — wider picture. - CRA — Vulnerability handling, coordinated disclosure, and post-market obligations — overlap. - Preparing an SBOM (CycloneDX or SPDX). Next step Open the RED Cyber assessment, confirm the article(s) activated, choose your conformity route, and start attaching the route-specific evidence.

Last updated on Jun 03, 2026