Product Assurance Learning

Home / Guides

Guide

RED Cybersecurity After the CRA: The 2027 Transition

Delegated Regulation (EU) 2022/30, which added cybersecurity requirements to the Radio Equipment Directive, is repealed by Delegated Regulation (EU) 2026/339 with effect from 11 December 2027. From that date, the cybersecurity of radio products with digital elements is covered by the Cyber Resilience Act, while the RED keeps covering safety, EMC and the radio spectrum. Until then, the RED cybersecurity rules and the EN 18031 standards still apply to every unit you place on the market.

8 min readUpdated 7 October 2026By the VeridEx editorial team

What applies to radio equipment cybersecurity today

Since 1 August 2025, Delegated Regulation (EU) 2022/30 has activated three essential requirements of the Radio Equipment Directive (RED), Directive 2014/53/EU, for many internet-connected radio products. They sit in Article 3(3), points (d), (e) and (f): protection of the network, protection of personal data and privacy, and protection from fraud.

The harmonised standards for these requirements are EN 18031-1, EN 18031-2 and EN 18031-3. Their references were published in the Official Journal of the European Union by Commission Implementing Decision (EU) 2025/138 of 28 January 2025, with restrictions. A restriction means that part of a standard does not give presumption of conformity. Read the citation and its notes, and check the latest position, because citations can be amended.

The restrictions decide your conformity assessment route for these requirements:

  • Module A (internal production control) is possible only if you fully apply the cited EN 18031 standards and no restriction affects your product.
  • A notified body is needed if a restriction matters for your product, if you apply the standards only in part, or if no harmonised standard covers the requirement. The routes are module B plus C (EU-type examination) or module H (full quality assurance).

Our guide to RED cybersecurity and EN 18031 explains the scope, the three requirements and the restrictions in detail. This guide looks at what happens next.

What Delegated Regulation (EU) 2026/339 does

The Commission adopted Delegated Regulation (EU) 2026/339 on 16 February 2026. It was published in the Official Journal on 29 April 2026. Its operative article is short: Delegated Regulation (EU) 2022/30 is repealed with effect from 11 December 2027.

That is the date when the main obligations of the Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, apply. The recitals of the repealing act explain the reason. The CRA sets horizontal cybersecurity requirements for products with digital elements, and they include the elements of the RED cybersecurity requirements. Without the repeal, the same radio product would face two sets of cybersecurity rules.

The recitals also state that the repeal does not affect the checks by market surveillance authorities on radio equipment placed on the market between 1 August 2025 and 10 December 2027. Units you place in that period must meet Delegated Regulation (EU) 2022/30, and authorities can still check them against it after the repeal.

What changes for radio products on 11 December 2027

From 11 December 2027, the cybersecurity of a radio product with digital elements is assessed against the CRA. The essential requirements are in Annex I of Regulation (EU) 2024/2847. Part I covers the security properties of the product. Part II covers vulnerability handling by the manufacturer.

The RED does not disappear. It continues to cover safety and electromagnetic compatibility (EMC) under Article 3(1), and the efficient use of the radio spectrum under Article 3(2). A Wi-Fi product placed on the market in 2028 therefore needs both: the RED for safety, EMC and radio, and the CRA for cybersecurity.

TopicToday (until 10 December 2027)From 11 December 2027
Legal basis for cybersecurityRED Article 3(3)(d), (e), (f) via Delegated Regulation (EU) 2022/30CRA, Annex I of Regulation (EU) 2024/2847
Safety, EMC, radio spectrumRED Article 3(1) and 3(2)RED Article 3(1) and 3(2), unchanged
Harmonised standards for cybersecurityEN 18031-1, -2, -3, cited with restrictionsStandards cited under the CRA (check the Official Journal)
Notified body for cybersecurityDepends on the EN 18031 restrictions and how you apply the standardsDepends on the CRA product category and the route you choose
Obligations after saleGeneral RED and market surveillance duties; CRA reporting since 11 September 2026Full CRA duties, including vulnerability handling and security updates
Declaration of conformityDirective 2014/53/EU with Delegated Regulation (EU) 2022/30Directive 2014/53/EU and Regulation (EU) 2024/2847

Under the CRA, the need for a notified body depends on whether your product falls into the categories of important or critical products listed in its annexes, and on the standards you apply. Many products remain open to self-assessment, but check the lists carefully. Our Cyber Resilience Act timeline covers the dates and the main obligations.

Units placed before and after 11 December 2027

Placing on the market happens unit by unit. The date that counts is the date each individual unit is first made available on the EU market. The launch date of the model does not decide it.

  • A unit placed on the market up to 10 December 2027 must meet Delegated Regulation (EU) 2022/30, along with the rest of the RED.
  • A unit placed on the market from 11 December 2027 must meet the CRA for cybersecurity, and the RED for safety, EMC and radio.

Article 69 of the CRA sets the transitional rules. Three points matter for radio products:

  1. Existing certificates. EU-type examination certificates and approval decisions issued for cybersecurity requirements of products with digital elements under other EU harmonisation legislation remain valid until 11 June 2028, unless they expire earlier. A certificate issued under the RED for Article 3(3)(d), (e) or (f) falls into this category. Agree with your notified body how it will be used in your CRA assessment, and plan a new assessment before that date.
  2. Products already on the market. Products placed on the market before 11 December 2027 are subject to the CRA requirements only if they undergo a substantial modification from that date.
  3. Reporting. The reporting obligations of Article 14 apply to all products with digital elements within scope that were placed on the market before 11 December 2027, as well. They have applied since 11 September 2026.

Units already placed on the market before 11 December 2027 can still be sold by distributors afterwards. Stock planning therefore matters. Agree with your importer when each batch is placed on the market, and keep records that show the date for each serial number.

Can you reuse EN 18031 work for the CRA?

Partly, and with care. Recital 3 of Delegated Regulation (EU) 2026/339 states that the CRA requirements include all the elements of the RED cybersecurity requirements. The CRA itself, in recital 30, acknowledges the link with the RED delegated act and asks for coordination in standardisation and guidance during the transition.

The CRA harmonised standards are being developed by CEN, CENELEC and ETSI under a standardisation request from the Commission, which they accepted in 2025. Until those standards are cited in the Official Journal, you cannot know exactly which EN 18031 evidence will map to them. Check the latest position before you plan your test campaign.

What you can reasonably carry forward:

  • your inventory of interfaces, network services and stored data;
  • your risk assessment, updated for the wider CRA scope;
  • secure design measures already in place, such as authentication, secure updates and protection of stored data;
  • test reports, as supporting evidence, where they remain relevant to the product version you ship.

What the CRA adds goes beyond EN 18031. Annex I Part II requires vulnerability handling over the support period, including security updates and coordinated vulnerability disclosure. You also need a defined support period, user information on security, and technical documentation organised around the CRA requirements. Expect to rewrite part of your file, even if the technical measures stay the same. The Cyber Resilience Act course covers these requirements one by one.

A practical plan for radio product manufacturers, 2026 to 2028

Now to mid-2027: stay compliant with the RED.

  • Keep every unit compliant with Delegated Regulation (EU) 2022/30 and the EN 18031 standards as cited.
  • Run your CRA reporting procedure. Reporting through the ENISA single reporting platform has applied since 11 September 2026.
  • Do not delay a needed RED notified body assessment in the hope of skipping it. The RED rules apply to every unit until 10 December 2027.

During 2027: prepare the switch.

  • List your radio products and decide which will still be placed on the market after 11 December 2027.
  • Classify each one under the CRA and decide whether a notified body will be needed.
  • Carry out a gap analysis between your EN 18031 file and CRA Annex I, Parts I and II.
  • Set the support period and the update process for each product.
  • Prepare the new technical documentation and a draft EU Declaration of Conformity.

From 11 December 2027: switch per unit.

  • Ship units with the updated declaration, which lists the RED and the CRA.
  • Track which serial numbers were placed before and after the date.
  • If you hold a RED cybersecurity EU-type examination certificate, plan its replacement before 11 June 2028.

Watch the Official Journal throughout. CRA standards, Commission guidance and implementing acts are still being published. The RED cybersecurity course covers the current RED regime in depth.

Key points

  • Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027.
  • Until 10 December 2027, every unit must meet the RED cybersecurity requirements and you work with EN 18031 as cited, restrictions included.
  • From 11 December 2027, cybersecurity follows CRA Annex I, while the RED still covers safety, EMC and the radio spectrum.
  • Under CRA Article 69, cybersecurity certificates issued under other EU legislation remain valid until 11 June 2028 at the latest.
  • EN 18031 work is a good starting point, but the CRA adds vulnerability handling, support periods and updates.

For the framework behind all of this, start with the free first module of CE Marking Fundamentals: economic operators, placing on the market and the CE marking.

Learn the whole route, step by step

CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.

Frequently asked questions

Is Delegated Regulation (EU) 2022/30 still in force?

Yes. It has applied since 1 August 2025 and remains applicable until 10 December 2027. Delegated Regulation (EU) 2026/339 repeals it with effect from 11 December 2027. Every unit placed on the market before that date must meet it.

Do I need to test my radio product again for the CRA?

It depends on how your EN 18031 evidence maps to the CRA requirements and to the CRA harmonised standards once they are cited. Some evidence can be reused, but the CRA adds requirements such as vulnerability handling and security updates. Plan a gap analysis in 2027 and check the latest position on standards.

What happens to my RED cybersecurity EU-type examination certificate?

Article 69 of the CRA states that EU-type examination certificates and approval decisions for cybersecurity requirements issued under other EU harmonisation legislation remain valid until 11 June 2028, unless they expire earlier. Agree with your notified body how it fits into your CRA assessment and plan the next step before that date.

What is the difference between RED cybersecurity and the CRA for a Wi-Fi product?

RED cybersecurity adds three requirements to the RED: network protection, personal data and privacy, and protection from fraud. The CRA covers cybersecurity across the product life, including vulnerability handling, a support period and security updates. From 11 December 2027 the CRA takes over the cybersecurity part, and the RED keeps safety, EMC and the radio spectrum.

This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.

Related guides

Be first in line

Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.