[Home](/)/[Resources](/resources)/CE certification for IoT devices

IoT complianceConnected devices

# CE Certification for IoT Devices: Complete Compliance Guide

IoT devices face a uniquely complex compliance landscape. Wireless connectivity, cloud services, data collection, and remote updates all introduce regulatory considerations beyond traditional hardware. This guide covers the full CE compliance stack for connected products entering the EU market.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fce-certification-for-iot-devices)

[Check my product requirements](/platform/start)

Problem

## IoT compliance is more than hardware certification

A traditional hardware product can be tested, documented, and shipped. An IoT device is never finished—it ships with firmware that can be updated, connects to cloud services that change, and may collect data that triggers additional legal considerations. This creates compliance complexity that traditional certification models were not designed for.

The Radio Equipment Directive (RED) now explicitly requires cybersecurity and data protection for radio equipment. The EU Cyber Resilience Act will introduce mandatory cybersecurity requirements for connected products. GDPR may apply depending on what data your device collects and how it is processed. Firmware updates can change the compliance status of a device already in the field.

Founders often treat IoT devices like any other hardware product: book a lab test, get a report, and assume compliance is handled. But IoT devices need a compliance strategy that accounts for wireless standards, cybersecurity design, data handling, update mechanisms, and the fact that the product will evolve after it ships.

Requirements

## The IoT compliance stack

### Radio Equipment Directive (RED)

Mandatory for any device with intentional radio transmission (Wi-Fi, Bluetooth, Zigbee, LoRa, cellular). Covers spectrum efficiency, interoperability, and cybersecurity under Article 3.3.

### EMC Directive

Required for all electrical and electronic equipment. Ensures your device does not emit excessive electromagnetic interference and is immune to reasonable disturbances from other equipment.

### RoHS Directive

Restricts 10 hazardous substances in electrical and electronic equipment. Requires material declarations from suppliers and, in some cases, analytical testing.

### GPSR

General Product Safety Regulation applies to all consumer products. Requires safety assessment, traceability, and recall capabilities from December 2024.

### Cybersecurity (RED Article 3.3)

RED requires protection against network threats, ensuring data protection and privacy in radio equipment. This means secure design, authentication, and update mechanisms.

### Battery regulations

If your IoT device contains batteries, EU battery regulations apply. This includes capacity labeling, removability requirements for certain products, and substance restrictions.

Process

## IoT compliance workflow

01

### Map connectivity and data flows

Document all wireless interfaces, cloud endpoints, data collected, processing locations, and update mechanisms. This mapping drives both compliance requirements and risk assessment scope.

02

### Design for cybersecurity

Implement secure boot, encrypted communications, authentication mechanisms, secure update delivery, and data protection measures. Document these controls in your risk assessment.

03

### Select radio and EMC standards

Choose harmonised standards for your specific radio technologies and frequency bands. Verify they are current in the Official Journal and cover all your wireless interfaces.

04

### Test at accredited labs

Commission radio, EMC, and safety testing. IoT devices often require multiple test campaigns for different radio bands and operating modes. Plan for potential design iterations based on test results.

05

### Document firmware and update strategy

The technical file must document firmware versioning, update mechanisms, security measures, and how updates will be managed without compromising compliance. This is increasingly important under RED.

06

### Compile and sign the technical file

Assemble all evidence including test reports, risk assessment, cybersecurity documentation, design records, and supplier declarations. Sign the EU Declaration of Conformity only when the file is internally defensible.

Structure

## IoT-specific documentation considerations

IoT devices require documentation that goes beyond traditional hardware. Your technical file should address these connected-product considerations.

01

Wireless interface specifications: bands, protocols, power levels, and antenna configurations

02

Cybersecurity measures: authentication, encryption, secure boot, and secure update mechanisms

03

Data handling: what data is collected, where it is processed, and how it is protected

04

Cloud service dependencies: third-party services, data locations, and service level agreements

05

Firmware versioning: how versions are tracked, which version corresponds to which compliance evidence

06

Update strategy: how updates are delivered, authenticated, and whether they can change compliance status

07

Network security: protection against unauthorized access, network attacks, and data breaches

08

Privacy by design: how data protection is built into the product architecture

## Learn this properly, not just for one product

In-depth courses and books that teach the process — not a one-off answer you'll need to look up again next time.

[Start the course — $149](/courses/03-ce-marking-for-iot-devices)See your free roadmap

[Prefer to read? Get the book — $24.99](/books/03-ce-marking-for-iot-devices)

## Frequently asked questions

### What CE directives do IoT devices need?

IoT devices typically need RED (for wireless), EMC (for electromagnetic compatibility), RoHS (for hazardous substances), and GPSR (for general product safety). Devices with batteries need battery regulations. Products handling personal data may need to consider GDPR implications in their design and documentation.

### Does CE marking cover cybersecurity for IoT devices?

RED Article 3.3 requires radio equipment to protect against network threats and ensure data protection and privacy. This means IoT devices need cybersecurity measures in their design, supported by risk assessment and technical documentation. Specific cybersecurity standards are evolving under the EU Cyber Resilience Act.

### Can IoT devices self-certify for CE marking?

Most IoT devices can self-certify under Module A when harmonised standards cover the risks. However, products with novel radio technologies, certain frequency bands, or missing harmonised standards may require Notified Body involvement. Always verify with your lab before assuming self-certification is sufficient.

### How does firmware updates affect CE compliance for IoT devices?

Firmware updates can change compliance status. If an update affects safety, radio performance, or cybersecurity, you may need to reassess compliance and update documentation. The technical file should document how firmware versioning is controlled and which versions correspond to which compliance evidence.

🇪🇺 CE Marking roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/03-ce-marking-for-iot-devices)[Prefer to read? Get the book — $24.99](/books/03-ce-marking-for-iot-devices)

Related guides

*   [CE compliance for smart home devicesA deep guide to CE compliance for smart home devices, including RED, EMC, LVD, RoHS, GPSR, cybersecurity, testing evidence, tec…](/guides/ce-compliance-for-smart-home-devices)
*   [EMC Directive complianceComplete guide to EMC Directive (2014/30/EU) compliance: emissions, immunity, testing requirements, and harmonised standards fo…](/guides/emc-directive-compliance)
*   [Low Voltage Directive explainedComplete guide to the EU Low Voltage Directive (LVD 2014/35/EU): scope, essential safety requirements, testing, and compliance …](/guides/low-voltage-directive-explained)
*   [CE marking for wearablesComplete guide to CE marking for wearable devices: RED, EMC, RoHS, GPSR, battery regulations, and skin contact requirements for…](/guides/ce-marking-for-wearables)
*   [CE for battery-powered devicesComplete guide to CE compliance for battery-powered devices: battery regulations, safety requirements, transport rules (UN 38.3…](/guides/ce-for-battery-powered-devices)

Educational resource only. CE responsibility remains with the manufacturer or authorised representative. Verify current law, standards, and product-specific evidence before signing.