With the popularization of Internet of Things (IoT) devices and the rapid development of wireless communication technology, cybersecurity and user privacy protection have become core issues in global regulation. Through the Radio Equipment Directive (RED) and its accompanying standard en 18031, the European Union has established strict security thresholds for wireless devices entering the European market, and it will be mandatorily enforced through ce marking certification starting from August 1, 2025.
Meanwhile, the EU Cyber Resilience Act (CRA), whose mandatory enforcement date is tentatively set for the second half of 2027, does not yet have a clearly defined specific definition of compliance. The CRA aims to supplement the cybersecurity areas currently not covered by RED, will in principle adopt RED's enterprise standards, and will make necessary additions and revisions to the standard provisions in the future.
Within the EU, both the red directive requirements and CRA regulations are mandatory. Any product sold in the EU market must comply with the requirements of these two regulations, which will directly relate to ce marking certification.
Delegated Regulation 2022/30/EU covers equipment that can communicate via the internet directly or through other equipment (indirectly), and radio equipment that may expose sensitive personal data. For example:
Mobile phones, tablets, and laptops
Wireless toys and childcare equipment, such as baby monitors
Wearable equipment, such as smartwatches and fitness trackers
The product scope corresponding to specific regulatory articles is as follows:
Article 3.3 (d): Equipment related to network protection
Article 3.3 (e): Equipment processing personal data, traffic data, or location data
Article 3.3 (f): Radio equipment that enables the holder or user to transfer money, monetary value, or virtual currency as defined in EU Directive 2019/713 Article 2 (d)
3.3.(d) en 18031-1:2024: Evaluates Security Assets and Network Assets.
3.3.(e) EN 18031-2:2024: Evaluates Security Assets and Privacy Assets.
3.3.(f) EN 18031-3:2024: Evaluates Security Assets and Financial Assets.
Access control mechanism
Authentication mechanism
Secure update mechanism
Secure storage mechanism
Secure communication mechanism
Resilience mechanism
Network monitoring mechanism
Traffic control mechanism
Confidential cryptographic keys
General device capabilities
Cryptography
Access control mechanism
Authentication mechanism
Secure update mechanism
Secure storage mechanism
Secure communication mechanism
General device capabilities
Cryptography
Logging mechanism
Deletion mechanism
User notification mechanism
Access control mechanism
Authentication mechanism
Secure update mechanism
Secure storage mechanism
Secure communication mechanism
Confidential cryptographic keys
General device capabilities
Cryptography
Logging mechanism
Manufacturers should start preparing for the August 2025 mandatory implementation deadline by reviewing existing products and reviewing new product designs to ensure they can comply with the new cybersecurity requirements and obtain the corresponding certifications before the mandatory implementation deadline. This move will mitigate business risks and help ensure a competitive advantage.
If products within the scope do not comply with the requirements, manufacturers may face a series of serious consequences, including but not limited to: product recalls, fines, market entry bans, and reputation loss.
Note 1: If the time for data confirmation and rectification is extended, the certification cycle will be postponed accordingly. It is recommended to reserve time for rectification.
Note 2: Currently, over 80% of products on the market will involve rectification. Therefore, it is recommended to reserve rectification time in the certification cycle and conduct a preliminary assessment half a year to one year in advance.
Note 3: Because the testing contents involved in different products vary and product design schemes are different, it is recommended to conduct a preliminary assessment test for each type of product in advance. After understanding the detailed requirements for that type of product, introduce the testing requirements into the product research and development stage to avoid massive rectifications during certification.
1. Which products require compliance?
Models that have never been shipped, and products shipped after the mandatory execution date (August 1, 2025), must complete testing and obtain certificates as required.
Products that have been shipped before, but still need to be shipped after the mandatory execution date (August 1, 2025), must complete testing and obtain certificates as required.
Products that have been shipped before and sold in the EU market, but will no longer be shipped after the mandatory execution date (August 1, 2025): No need to test and certify according to the new requirements.
2. If a product has passed EN 303 645, does it still need to comply with RED 3.3d/e/f?
If the product has already passed EN 303 645, it is necessary to supplement the difference testing of EN 18031 on this basis, and then obtain the Notified Body (NB) certificate to meet the compliance requirements.
3. How is the RED 3.3d/e/f certificate issued?
After the testing is completed, a test report is issued and submitted to the NB agency for certification. A separate certificate for RED 3.3d/e/f can be issued, or it can be issued together with the original EMC/Safety/RF certificates, etc.
Australia RCM Certification for Radio Devices
RED Cybersecurity EN 18031 Standard
Compliance Testing for EMC
What is Amazon Toy Compliance?
What is Cytotoxicity ISO 10993-5
What is Hemocompatibility Testing ISO 10993?
What is ISO 10993-5 Tests for In Vitro Cytotoxicit
Electronic Product IEC 62368-1 Safety Testing
24-hour online customer service at any time to respond, so that you worry!