RED Cybersecurity (Delegated Reg. 2022/30)

← All instruments
in forceproduct
Type
delegated regulation
Layer
product
Status
in force
In force
2025-08-01
Key date
superseded by CRA in 2027
Last verified
2026-07-16

RED cybersecurity requirements — the IoT stopgap before the CRA

The Radio Equipment Directive (RED, 2014/53/EU) has governed radio equipment placed on the EU market for over a decade — safety, health, spectrum. Delegated Regulation (EU) 2022/30 switched on its dormant cybersecurity provisions (Art. 3(3)(d)(e)(f)), which became mandatory on 1 August 2025 after a delay. Until the CRA is fully applicable (Dec 2027), this is the operative product-cybersecurity rule for connected radio equipment.

Scope

Radio equipment that can communicate over the internet, directly or via other equipment: Wi-Fi and Bluetooth devices, mobile/cellular equipment, and most internet-connected consumer IoT (wearables, smart-home, connected toys, childcare devices). Notably relevant for the many IoT products that will also fall under the CRA.

The three activated requirements

  • Art. 3(3)(d) — network protection: the device must not harm the network or misuse network resources.
  • Art. 3(3)(e) — protection of personal data and privacy of users and subscribers.
  • Art. 3(3)(f) — protection against fraud: safeguards for money/value transfers.

Compliance

Presumption of conformity is achieved mainly through harmonised standards — the EN 18031 series (EN 18031-1/-2/-3) covers these requirements. Where standards are not fully applied, manufacturers need EU-type examination by a notified body. Conformity is expressed through the existing CE marking.

Why it exists (and its short life)

It was the fastest route to baseline security for connected devices while the broader CRA was still being negotiated. The CRA supersedes RED’s cybersecurity requirements once fully applicable (11 Dec 2027); the standards work (EN 18031 ↔ CRA harmonised standards) is deliberately aligned so RED compliance is a stepping stone rather than throwaway work.

Interplay

  • CRA: same products, broader duties; treat RED conformity as the on-ramp.
  • NIS2: RED/CRA secure the devices that NIS2 operators deploy.
  • GDPR: Art. 3(3)(e) overlaps with data-protection-by-design duties.

Sources