RED Cybersecurity and EN 18031: What Radio Makers Must Do
RED cybersecurity since August 2025: Delegated Regulation 2022/30, Article 3(3)(d)(e)(f), EN 18031 restrictions and when a notified body becomes necessary.

The Cyber Resilience Act, Regulation (EU) 2024/2847, applies in two main steps. Its reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026. Its main cybersecurity obligations apply to products with digital elements placed on the EU market from 11 December 2027, when the CE marking will also cover them.
The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity rules for products with digital elements. These are hardware and software products that connect, directly or indirectly, to a device or a network. A connected industrial machine, a controller with remote access or a device that talks to a cloud dashboard can all fall into this group.
The CRA is a regulation, so it applies directly in every Member State with the same text. You do not need to look for national versions of it. The text published in the Official Journal of the European Union is the text that applies.
Its focus is cybersecurity as such. It asks for secure design, vulnerability handling and security updates. It also covers the whole life of the product, and not only the moment of sale. This is a change for many manufacturers, who are used to thinking of compliance as a check done once before shipment.
The CRA applies in steps. Two dates matter most for manufacturers outside the EU:
| Date | What applies |
|---|---|
| 11 September 2026 | Reporting obligations: actively exploited vulnerabilities and severe incidents affecting the security of your products must be reported through the ENISA single reporting platform |
| 11 December 2027 | Main obligations: products with digital elements placed on the market from this date must meet the CRA cybersecurity requirements, and the CE marking also declares compliance with them |
Both dates are set in the regulation as currently published. Guidance on how the rules work in practice is still developing, so check the latest position in the Official Journal and the Commission's guidance before you finalise your plans.
The reporting obligations have applied since 11 September 2026. Manufacturers must report two kinds of events:
Reports go through a single reporting platform managed by ENISA, the EU cybersecurity agency. The deadlines are short. They start with an early warning within 24 hours.
Because the duty concerns your products on the EU market, it can apply to models you already sell, and not only to new designs. A short deadline leaves no time to work out the process when the event happens. You need an internal procedure in place beforehand:
This sits next to your other after-sale duties. Under the EU product laws you already have to investigate complaints, take corrective action and inform authorities when a product presents a risk. The CRA adds a specific reporting channel for security events. Consumer accidents under the General Product Safety Regulation go through a different portal, the Safety Business Gateway, so do not mix the two.
The main obligations apply from 11 December 2027. Like other EU product laws, the CRA applies per unit placed on the market. A unit placed on the market on 10 December 2027 does not have to meet the main CRA requirements. An identical unit placed one day later does.
From that date, the CE marking on a product with digital elements also declares compliance with the CRA cybersecurity requirements. The commitment covers the life of the product, including security updates. In practice, you will need:
The CRA also asks for an electronic contact on the product information, such as a website or email address, next to your postal address. Plan the space on the label or data plate early.
The CRA allows the Commission to adopt common specifications when harmonised standards are missing or not good enough. Common specifications, like harmonised standards, can give presumption of conformity. Check which harmonised standards and common specifications exist for your product as the date approaches, because the situation is changing.
The CRA does not replace the other product laws that apply to your product. It is added to them.
Machinery. The CRA and the machinery law apply together. The Machinery Regulation, Regulation (EU) 2023/1230, applies to machinery placed on the market from 20 January 2027. It asks for protection against corruption of the control system, as a safety matter. The CRA asks for cybersecurity as such. A connected machine will have to meet both. Our guide to the Machinery Regulation 2023/1230 changes covers the machinery side.
Radio equipment. Since 1 August 2025, Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive has required many internet-connected radio products to protect the network, personal data and against fraud. The RED cybersecurity requirements are expected to give way to the CRA once it fully applies, and Delegated Regulation (EU) 2022/30 is currently set to be repealed from 11 December 2027. Check the latest position. Until then, the RED rules apply. See our guide on RED cybersecurity and EN 18031.
Take a hypothetical machine with built-in Wi-Fi, sold to professional users. The same model would move through three regimes. Units placed on the market now follow the Machinery Directive, Directive 2006/42/EC, plus the RED with its cybersecurity delegated act. Units placed from 20 January 2027 follow the Machinery Regulation instead. Units placed from 11 December 2027 must also meet the CRA. The date of each unit counts.
December 2027 may look far away, but design cycles for industrial products are long. A product you design today may still be in production then. A practical plan:
The Cyber Resilience Act course goes through the requirements in depth.
To see how the CRA fits into the wider CE system, start with the free first module of CE Marking Fundamentals.
CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.
In two main steps. The reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026. The main obligations apply to products with digital elements placed on the market from 11 December 2027. Check the latest position in the Official Journal, as guidance is still developing.
The reporting duty concerns your products on the EU market, so it can apply to models you already sell. Reports go through the ENISA single reporting platform, starting with an early warning within 24 hours. Prepare an internal procedure so you can meet these deadlines.
No. The two apply together. The Machinery Regulation asks for protection against corruption of the control system as a safety matter, while the CRA asks for cybersecurity as such: secure design, vulnerability handling and updates.
RED cybersecurity comes from Delegated Regulation (EU) 2022/30 and has applied to many internet-connected radio products since 1 August 2025. The CRA covers products with digital elements more broadly and adds duties across the product life. The RED cybersecurity requirements are currently set to give way to the CRA from 11 December 2027.
This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.
RED cybersecurity since August 2025: Delegated Regulation 2022/30, Article 3(3)(d)(e)(f), EN 18031 restrictions and when a notified body becomes necessary.
Machinery Regulation 2023/1230 changes from 20 January 2027: per-unit transition, Annex I Part A and B, partly completed machinery and digital instructions.
CE marking requirements for non-EU manufacturers, step by step: applicable EU laws, harmonised standards, conformity assessment, technical file, DoC and labels.
Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.
Thanks, you are on the list. We will be in touch before launch.