Shape

RED directive and EN 18031: radio equipment cybersecurity since August 2025

CRA ComplianceBy AzertyUI Team

Even before the Cyber Resilience Act, a first text made cybersecurity mandatory for a large family of connected products: the RED directive (Radio Equipment Directive, 2014/53/EU), supplemented by Delegated Regulation (EU) 2022/30. Its cybersecurity requirements have applied since 1 August 2025.

Which products are in scope?

Radio equipment able to communicate over the internet, directly or indirectly, plus certain categories handling personal data or financial transactions. In practice: wireless sensors and gateways, industrial equipment communicating over Wi-Fi, Bluetooth or cellular networks.

The three requirements

  • Protect the network: the equipment must not harm the network or its operation.
  • Protect personal data and user privacy.
  • Protect against fraud for equipment involved in financial transactions.

The EN 18031 standards

The harmonised standards EN 18031-1, -2 and -3 turn these requirements into verifiable mechanisms: authentication management, secure updates, protection of communications and stored data, logging. They were referenced in the EU Official Journal in early 2025 with some restrictions: depending on design choices, notably around passwords, a notified body may still be required.

And the CRA?

The Cyber Resilience Act then extends the logic to all products with digital elements, with full requirements on 11 December 2027. Work done for RED (risk analysis, updates, secrets management) is directly reusable.

For machine and connected-equipment builders, the most efficient approach is to cover RED, the CRA and the Machinery Regulation in a single gap analysis.

Information current as of 29 September 2026. Regulations and timelines change: this article is not legal advice.

Related Tags

  • CE marking
  • Connected devices
  • CRA
  • EN 18031
  • Marquage CE
  • Objets connectés
  • RED

Share This Article

Shape