Cyber Resilience Act Dates: What Applies in 2026 and 2027
Cyber Resilience Act dates: vulnerability reporting since 11 September 2026, main obligations from 11 December 2027, and how the CRA fits with CE marking.

Since 1 August 2025, Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive (RED) requires many internet-connected radio products to protect the network, personal data and users against fraud. The harmonised standards for these requirements are the EN 18031 series, but their citations in the Official Journal carry restrictions. Whether you can self-declare under module A or need a notified body depends on how those restrictions affect your product.
The Radio Equipment Directive, Directive 2014/53/EU, has always covered three areas: safety, electromagnetic compatibility (EMC) and efficient use of the radio spectrum. Delegated Regulation (EU) 2022/30 adds a fourth area for many connected radio products: cybersecurity. It does this through three essential requirements in Article 3(3) of the directive.
These requirements have applied since 1 August 2025. They apply to each unit placed on the market from that date, because placing on the market happens unit by unit. A model you have sold for years must meet them for every new unit you ship today.
For the products concerned, cybersecurity is now part of what the CE marking declares. In practice this can mean cybersecurity testing, extra technical documentation and, in some cases, a notified body.
Start with the RED itself. It covers any product that intentionally emits or receives radio waves for communication or radiodetermination. That includes Wi-Fi, Bluetooth, mobile networks, RFID and radar. A product that integrates a radio module becomes radio equipment as a whole. A packaging machine or an industrial controller with a built-in Wi-Fi module is therefore radio equipment, and the RED applies to the complete product.
The delegated regulation then targets many internet-connected radio products. A practical first check is simple: if your product has Wi-Fi, Bluetooth or a mobile connection and it talks to the internet, assess the delegated regulation first. Then read its scope provisions word by word, as you would for any EU product law, and record your conclusion in your applicability analysis.
Write down the reason in both directions. If you decide the requirements apply, note which ones. If you decide they do not, note the provision that supports your decision. An authority or a notified body may ask you why.
The three essential requirements activated by the delegated regulation sit in Article 3(3) of the RED, points (d), (e) and (f). In plain words:
Do your applicability analysis point by point. For each of the three points, record whether it applies to your product and why, with the provision of the delegated regulation that supports your answer. The same structure then carries through to your standards list, your test reports and your declaration.
These requirements sit next to the core RED requirements. Safety and EMC, in Article 3(1), still apply in full. So do the radio requirements of Article 3(2). For radio equipment, you cover safety and EMC through the RED itself, so you do not apply the Low Voltage Directive or the EMC Directive separately.
The harmonised standards for the cybersecurity requirements are the EN 18031 series. As with any harmonised standard, a standard gives presumption of conformity only once its reference is published in the Official Journal of the European Union, and only for the requirements it covers.
The EN 18031 standards were cited with restrictions when first published. A restriction means that part of the standard does not give presumption of conformity. The note attached to the citation explains which clauses are affected. Their citations currently carry restrictions, and the framework is still changing, so you must check the latest position in the Official Journal before you decide anything.
In practice:
Our guide to harmonised standards and presumption of conformity explains how to read the lists, editions and cessation dates.
This is where the restrictions have a direct cost. Under the RED, the choice of conformity assessment procedure depends on harmonised standards:
| Requirements | Module A (internal production control) | Otherwise |
|---|---|---|
| Article 3(1): safety and EMC | Always possible | Not needed |
| Article 3(2) and 3(3): radio and cybersecurity | Only if harmonised standards covering them are fully applied, and no restriction in their citation matters for your product | Module B plus C, or module H, with a notified body |
So module A is no longer possible for the cybersecurity requirements in three situations: a restriction in the EN 18031 citation affects your product, you apply the standards only in part, or no harmonised standard covers the requirement. In each case, a notified body must take part for those requirements.
Under module B plus C, the notified body examines the design and issues an EU-type examination certificate, and you control production. Because the body acts only in the design phase, its four-digit number does not follow the CE marking. Under module H, the body approves and monitors your quality system, and its number appears next to the CE marking, shown as CE xxxx.
Before you sign a contract, check in NANDO, the Commission's database of notified bodies, that the body is notified under the RED for your module and product. More detail on procedures across laws is in our guide do I need a notified body.
The technical documentation should show how each applicable cybersecurity requirement is met. Typical content includes:
Be careful with integrated radio modules. A module with its own reports is a good start, but it does not make the whole product compliant. Assess the product as a whole, and keep each report traceable to the hardware and software revision tested.
The EU Declaration of Conformity lists Directive 2014/53/EU together with Delegated Regulation (EU) 2022/30, plus RoHS and any other law that applies, such as machinery. Under the RED, each unit comes with a copy of the full declaration or a simplified declaration with an internet address.
Finally, plan for change. The Cyber Resilience Act, Regulation (EU) 2024/2847, applies its main obligations from 11 December 2027. For radio products, the cybersecurity requirements of the RED delegated act are expected to give way to the Cyber Resilience Act once it fully applies, and Delegated Regulation (EU) 2022/30 is currently set to be repealed from that date. Check the latest position in the Official Journal. Our guide to Cyber Resilience Act dates sets out what applies when, and the RED cybersecurity course covers the requirements in depth.
The free first module of our CE Marking Fundamentals course explains the framework behind these rules: economic operators, placing on the market and the CE marking.
CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.
Not always. You can use module A for Article 3(3)(d), (e) and (f) if you fully apply EN 18031 standards cited in the Official Journal and no restriction in the citation matters for your product. If a restriction affects your product, or you apply the standards only in part, you need a notified body under module B plus C or module H.
No. A product that integrates a radio module becomes radio equipment as a whole, and you must assess the complete product. The module's reports are useful evidence, but integration can change the result, so the assessment and any testing must cover your product.
Delegated Regulation (EU) 2022/30 adds three cybersecurity requirements to the RED for many internet-connected radio products, and it has applied since 1 August 2025. The Cyber Resilience Act covers products with digital elements more broadly, with main obligations from 11 December 2027. The RED cybersecurity requirements are currently set to give way to the CRA from that date, so check the latest position.
In the citation of the standards in the Official Journal of the European Union, in the notes attached to the reference. The Commission's summary list for the RED brings the citations together, but the Official Journal is the legal source. Read the note itself, not only the title of the standard.
This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.
Cyber Resilience Act dates: vulnerability reporting since 11 September 2026, main obligations from 11 December 2027, and how the CRA fits with CE marking.
When EU law requires a notified body: modules A to H, rules for LVD, EMC, RED, ATEX, PED and machinery, how to check NANDO and what a notified body issues.
How harmonised standards give presumption of conformity: Official Journal citation, Annex Z scope, editions and cessation dates, restrictions, EN vs ISO/IEC.
Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.
Thanks, you are on the list. We will be in touch before launch.