RED Cybersecurity and EN 18031: What Radio Makers Must Do
RED cybersecurity since August 2025: Delegated Regulation 2022/30, Article 3(3)(d)(e)(f), EN 18031 restrictions and when a notified body becomes necessary.

Delegated Regulation (EU) 2022/30, which added cybersecurity requirements to the Radio Equipment Directive, is repealed by Delegated Regulation (EU) 2026/339 with effect from 11 December 2027. From that date, the cybersecurity of radio products with digital elements is covered by the Cyber Resilience Act, while the RED keeps covering safety, EMC and the radio spectrum. Until then, the RED cybersecurity rules and the EN 18031 standards still apply to every unit you place on the market.
Since 1 August 2025, Delegated Regulation (EU) 2022/30 has activated three essential requirements of the Radio Equipment Directive (RED), Directive 2014/53/EU, for many internet-connected radio products. They sit in Article 3(3), points (d), (e) and (f): protection of the network, protection of personal data and privacy, and protection from fraud.
The harmonised standards for these requirements are EN 18031-1, EN 18031-2 and EN 18031-3. Their references were published in the Official Journal of the European Union by Commission Implementing Decision (EU) 2025/138 of 28 January 2025, with restrictions. A restriction means that part of a standard does not give presumption of conformity. Read the citation and its notes, and check the latest position, because citations can be amended.
The restrictions decide your conformity assessment route for these requirements:
Our guide to RED cybersecurity and EN 18031 explains the scope, the three requirements and the restrictions in detail. This guide looks at what happens next.
The Commission adopted Delegated Regulation (EU) 2026/339 on 16 February 2026. It was published in the Official Journal on 29 April 2026. Its operative article is short: Delegated Regulation (EU) 2022/30 is repealed with effect from 11 December 2027.
That is the date when the main obligations of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, apply. The recitals of the repealing act explain the reason. The CRA sets horizontal cybersecurity requirements for products with digital elements, and they include the elements of the RED cybersecurity requirements. Without the repeal, the same radio product would face two sets of cybersecurity rules.
The recitals also state that the repeal does not affect the checks by market surveillance authorities on radio equipment placed on the market between 1 August 2025 and 10 December 2027. Units you place in that period must meet Delegated Regulation (EU) 2022/30, and authorities can still check them against it after the repeal.
From 11 December 2027, the cybersecurity of a radio product with digital elements is assessed against the CRA. The essential requirements are in Annex I of Regulation (EU) 2024/2847. Part I covers the security properties of the product. Part II covers vulnerability handling by the manufacturer.
The RED does not disappear. It continues to cover safety and electromagnetic compatibility (EMC) under Article 3(1), and the efficient use of the radio spectrum under Article 3(2). A Wi-Fi product placed on the market in 2028 therefore needs both: the RED for safety, EMC and radio, and the CRA for cybersecurity.
| Topic | Today (until 10 December 2027) | From 11 December 2027 |
|---|---|---|
| Legal basis for cybersecurity | RED Article 3(3)(d), (e), (f) via Delegated Regulation (EU) 2022/30 | CRA, Annex I of Regulation (EU) 2024/2847 |
| Safety, EMC, radio spectrum | RED Article 3(1) and 3(2) | RED Article 3(1) and 3(2), unchanged |
| Harmonised standards for cybersecurity | EN 18031-1, -2, -3, cited with restrictions | Standards cited under the CRA (check the Official Journal) |
| Notified body for cybersecurity | Depends on the EN 18031 restrictions and how you apply the standards | Depends on the CRA product category and the route you choose |
| Obligations after sale | General RED and market surveillance duties; CRA reporting since 11 September 2026 | Full CRA duties, including vulnerability handling and security updates |
| Declaration of conformity | Directive 2014/53/EU with Delegated Regulation (EU) 2022/30 | Directive 2014/53/EU and Regulation (EU) 2024/2847 |
Under the CRA, the need for a notified body depends on whether your product falls into the categories of important or critical products listed in its annexes, and on the standards you apply. Many products remain open to self-assessment, but check the lists carefully. Our Cyber Resilience Act timeline covers the dates and the main obligations.
Placing on the market happens unit by unit. The date that counts is the date each individual unit is first made available on the EU market. The launch date of the model does not decide it.
Article 69 of the CRA sets the transitional rules. Three points matter for radio products:
Units already placed on the market before 11 December 2027 can still be sold by distributors afterwards. Stock planning therefore matters. Agree with your importer when each batch is placed on the market, and keep records that show the date for each serial number.
Partly, and with care. Recital 3 of Delegated Regulation (EU) 2026/339 states that the CRA requirements include all the elements of the RED cybersecurity requirements. The CRA itself, in recital 30, acknowledges the link with the RED delegated act and asks for coordination in standardisation and guidance during the transition.
The CRA harmonised standards are being developed by CEN, CENELEC and ETSI under a standardisation request from the Commission, which they accepted in 2025. Until those standards are cited in the Official Journal, you cannot know exactly which EN 18031 evidence will map to them. Check the latest position before you plan your test campaign.
What you can reasonably carry forward:
What the CRA adds goes beyond EN 18031. Annex I Part II requires vulnerability handling over the support period, including security updates and coordinated vulnerability disclosure. You also need a defined support period, user information on security, and technical documentation organised around the CRA requirements. Expect to rewrite part of your file, even if the technical measures stay the same. The Cyber Resilience Act course covers these requirements one by one.
Now to mid-2027: stay compliant with the RED.
During 2027: prepare the switch.
From 11 December 2027: switch per unit.
Watch the Official Journal throughout. CRA standards, Commission guidance and implementing acts are still being published. The RED cybersecurity course covers the current RED regime in depth.
For the framework behind all of this, start with the free first module of CE Marking Fundamentals: economic operators, placing on the market and the CE marking.
CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.
Yes. It has applied since 1 August 2025 and remains applicable until 10 December 2027. Delegated Regulation (EU) 2026/339 repeals it with effect from 11 December 2027. Every unit placed on the market before that date must meet it.
It depends on how your EN 18031 evidence maps to the CRA requirements and to the CRA harmonised standards once they are cited. Some evidence can be reused, but the CRA adds requirements such as vulnerability handling and security updates. Plan a gap analysis in 2027 and check the latest position on standards.
Article 69 of the CRA states that EU-type examination certificates and approval decisions for cybersecurity requirements issued under other EU harmonisation legislation remain valid until 11 June 2028, unless they expire earlier. Agree with your notified body how it fits into your CRA assessment and plan the next step before that date.
RED cybersecurity adds three requirements to the RED: network protection, personal data and privacy, and protection from fraud. The CRA covers cybersecurity across the product life, including vulnerability handling, a support period and security updates. From 11 December 2027 the CRA takes over the cybersecurity part, and the RED keeps safety, EMC and the radio spectrum.
This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.
RED cybersecurity since August 2025: Delegated Regulation 2022/30, Article 3(3)(d)(e)(f), EN 18031 restrictions and when a notified body becomes necessary.
Cyber Resilience Act dates: vulnerability reporting since 11 September 2026, main obligations from 11 December 2027, and how the CRA fits with CE marking.
How harmonised standards give presumption of conformity: Official Journal citation, Annex Z scope, editions and cessation dates, restrictions, EN vs ISO/IEC.
Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.
Thanks, you are on the list. We will be in touch before launch.