Solutions · By Industry · Iot

IoT & Connected Devices

CRA + RED Article 3(3) combined compliance — one deadline already passed, one still coming.

Pain

RED Article 3(3) became mandatory 1 August 2025. If you shipped after that date without compliance, you're in violation now.

What you want

A single compliance programme that covers RED today and becomes the CRA foundation for 2027.

What you get

ETSI EN 303 645 gap assessment mapped directly onto CRA Annex I — 6 overlapping provisions reused, not duplicated.

Two regulations. One product. One deadline already passed.

RED Article 3(3)(d)(e)(f) became mandatory on 1 August 2025. If your internet-connected radio equipment was placed on the EU market after that date without cybersecurity compliance, you are in violation now.

CRA follows in December 2027 — and it is significantly more demanding. But the overlap between RED Article 3(3) and CRA Annex I means that building your RED compliance programme now creates the foundation for CRA. You are not starting from zero in 2027.


RED Article 3(3) — what is required now

For internet-connected radio equipment (including consumer IoT, wearables, routers, smart home devices):

  • (d) Network security — device must not harm network functioning, cannot be weaponised into a botnet
  • (e) Personal data protection — encryption, data minimisation, secure credential management
  • (f) Fraud protection — authentication, signed firmware updates, session management

Compliance path: self-assess against ETSI EN 303 645 (13 provisions), draw up technical documentation, issue EU Declaration of Conformity, affix CE marking.

RED Article 3(3) compliance guide


CRA — what is coming December 2027

CRA applies to all "products with digital elements" placed on the EU market. For IoT manufacturers this means:

Annex I Part I (13 essential security requirements): no default passwords, secure updates, minimal attack surface, encryption, software integrity, audit logging, resilience.

Annex I Part II (operational obligations): SBOM (machine-readable, transitive depth), CVD policy (publicly accessible, operationally active), vulnerability log, ENISA notification workflow (from September 2026 for Article 14).

Conformity assessment: Default class = self-assessment. Important Class I = self-assessment with harmonised standard or third-party. Important Class II = notified body required.


RED × CRA overlap — what you can reuse

| Obligation | RED (ETSI EN 303 645) | CRA Annex I | |---|---|---| | No default passwords | §5.1 | Part I §2(2) | | CVD policy | §5.2 | Part II §1 + Art. 14 | | Secure software updates | §5.3 | Part I §2(7) | | Data encryption | §5.5 | Part I §2(4) | | Minimal attack surface | §5.6 | Part I §2(5) | | Software integrity | §5.7 | Part I §2(1) |

Strategy: Implement ETSI EN 303 645 now for RED CE marking. Use the same controls as the foundation for CRA Annex I. The gap from EN 303 645 to full CRA Annex I is real (SBOM, vulnerability reporting, 10-year retention, more detailed requirements) — but the overlap means the hard architectural work is already done.


What NexCyber provides for IoT manufacturers

  • Scope determination: CRA product class + RED applicability in one assessment
  • Gap assessment: ETSI EN 303 645 × 13 provisions AND CRA Annex I × 13 requirements mapped simultaneously
  • SBOM tracking: completeness check against CRA Annex I Part II requirements
  • CVD policy evidence: operational status tracked as a compliance artefact
  • MRCC: Machine-Readable Compliance Certificate per product × regulation × version — verifiable CE + CRA readiness signal for buyers

Key dates for IoT manufacturers

| Date | Event | |---|---| | 1 August 2025 | RED Article 3(3) — mandatory now for new products | | 11 September 2026 | CRA Article 14 ENISA vulnerability reporting | | 11 December 2027 | Full CRA obligations |


Tools


Related answers


NexCyber — EU Market Access Compliance Platform

Versus what you do today

Big4 consulting · In-house spreadsheet · NexCyber.

DimensionBig4 / ConsultingIn-house spreadsheetNexCyber
First assessment delay
4–8 weeks
2–6 weeks
5 minutes
Cost per regulation cycle
€90k–170k
€30k+ hidden
Included
Reproducibility
Slide deck of the day
Depends on editor
Deterministic, identical re-runs
Article-level traceability
Footnote
Often missing
Live link to EUR-Lex
Update when law changes
Re-billed mission
Restart from scratch
Automatic, MRCC re-signed
Deliverable format
Static PDF
XLSX/Word
PDF + MRCC machine-verifiable
Auditor verification
Email + chase
Not verifiable
sha256 verified in seconds
Multi-regulation simultaneous
1 mission per regulation
Duplicates & conflicts
5 regulations, 1 source of truth
New product line evolution
Re-billed mission
Full re-entry
Clone + delta
Run free assessment