Regulations · RED

Radio Equipment Directive

Directive 2014/53/EU + Delegated Act 2022/30RED Cyber (Delegated Regulation 2022/30) applies to internet-connected radio equipment from 1 August 2025. Articles 3.3(d/e/f) cover security, fraud and privacy. Market access requires conformity.

In force since
2025-08-01
Atomic obligations
26
Max exposure
Market withdrawal
+ national financial penalties

Who is concerned?

RED applies to all radio equipment (any equipment using radio spectrum) placed on the EU market.

  • Wireless devices : Wi-Fi, Bluetooth, cellular, NFC, RFID, sub-1GHz IoT
  • Internet-connected radio equipment — since August 2025 cybersecurity obligations
  • Childcare, wearable, toy radio products — additional safety requirements

If your product has any wireless capability, RED is in scope.

What it requires (high-level)

  • Conformity assessment — Module A (self), B+C (Notified Body), H (full quality assurance).
  • Harmonised standards — EN 18031 series (cybersecurity), EN 303 645 (consumer IoT baseline).
  • Article 3(3)(d)(e)(f) cybersecurity — network resilience, data protection, fraud prevention. Live since 1 Aug 2025.
  • SAR testing — for body-worn equipment (specific absorption rate).
  • CE marking — required before placing on the market.

Penalty exposure

Primarily market withdrawal and financial penalties under national law (vary by member state, typically €30k–€300k per non-conforming product line).

Practical impact : non-compliance blocks EU market access entirely. Distributors will refuse non-CE-marked products.

How NexCyber helps with RED

  • CRA/RED overlap detection — many IoT products fall under both regulations. NexCyber auto-detects overlap and maps controls without double-work.
  • EN 18031 alignment — controls auto-mapped to RED Art. 3(3)(d)(e)(f).
  • EN 303 645 baseline — consumer IoT requirements pre-filled.
  • Conformity dossier — Module A/B+C/H workflow ready for Notified Body review.

RED — Frequently asked questions

When does RED Cyber become mandatory?+

Articles 3(3)(d), 3(3)(e) and 3(3)(f) of the RED Directive (cybersecurity, fraud protection and personal-data protection requirements) became mandatory on 1 August 2025 via Delegated Regulation (EU) 2022/30. Equipment placed on the EU market after this date must demonstrate conformity.

Which products fall under RED Cyber?+

Internet-connected radio equipment : smartphones, tablets, IoT devices, wearables, smart appliances, connected cameras, baby monitors, fitness trackers, smart toys with connectivity, and any device that can communicate over the internet whether directly or indirectly via a hub.

How does RED Cyber relate to the CRA?+

CRA supersedes RED Cyber for products with digital elements when it applies in full (December 2027). Until then, RED Cyber applies. NexCyber maps the overlap and produces a single evidence trail valid for both regimes, including the conformity declarations and Annex VI technical documentation.

What proves RED Cyber conformity?+

Either internal production control with harmonised standards (EN 18031-1/2/3 cover the three Articles), or EU-type examination by a Notified Body if standards are not used. Each device must carry the CE mark, technical documentation must be available for 10 years, and the EU Declaration of Conformity must accompany the product.

See your RED readiness in 5 minutes.

Free assessment. No credit card. EU-hosted. Auditable engine.

Run free assessment