[Home](/)/[Resources](/resources)/RED Cybersecurity Delegated Act

EURadio EquipmentRegulation guide

# RED Cybersecurity Delegated Act — Article 3.3(d)(e)(f)

Commission Delegated Regulation (EU) 2022/30 activates RED Article 3.3(d), (e), and (f) for Wi-Fi, Bluetooth, and cellular-connected products. From August 2025, radio equipment placed on the EU market must meet network protection, privacy, and fraud prevention requirements — on top of existing RED safety and spectrum requirements.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fred-cybersecurity-delegated-act)

At a glance

Regulation

(EU) 2022/30

Compliance date

1 August 2025

Articles activated

3.3(d), (e), (f)

Key standards

EN 18031-1/2/3

Conformity route

Module A (self-cert)

## Which products are in scope

The delegated regulation activates three distinct cybersecurity obligations, each with a different product scope. Most connected consumer and industrial products will fall under at least one article — manufacturers must assess each article independently, as a single product can be subject to more than one obligation.

### Article 3.3(d) — Network Non-Harm

**Scope:** Radio equipment that connects to the internet or to public electronic communications networks. Covers routers, smart home hubs, connected appliances, industrial IoT gateways, and any device that attaches to a broadband or cellular network.

**Obligation:** Equipment must not harm the network or misuse network resources. Requires controls over traffic generation, denial-of-service protection, and authenticated network access.

### Article 3.3(e) — Privacy and Personal Data Protection

**Scope:** Wearables and all radio equipment that processes or stores personal data, health data, or location data. Includes fitness trackers, smartwatches, connected health monitors, baby monitors, and consumer IoT devices that collect usage data.

**Obligation:** Devices must incorporate safeguards to protect personal data and privacy — including encryption of stored and transmitted data, minimal data collection by design, and secure credential storage.

### Article 3.3(f) — Fraud Prevention

**Scope:** Radio equipment that enables financial transactions, virtual currency transfers, or monetary value transfers. Covers contactless payment terminals, smart metering devices with billing functions, and consumer devices with integrated payment capabilities.

**Obligation:** Equipment must include mechanisms preventing fraudulent transactions — including transaction authentication, tamper resistance on financial logic, and protection against relay and replay attacks.

## Essential requirements under Article 3.3(d)(e)(f)

The delegated regulation does not prescribe specific technical solutions — it establishes outcomes that in-scope radio equipment must achieve. The EN 18031 series translates these outcomes into testable requirements. Key obligations across all three articles include:

01

Network non-harm (Article 3.3(d)): radio equipment connecting to electronic communications networks must not degrade network operation, misuse network resources, or facilitate denial-of-service conditions. Requires rate limiting, authenticated registration, and traffic controls.

02

Personal data protection (Article 3.3(e)): devices processing personal data must encrypt data in transit and at rest, implement data minimisation by design, protect authentication credentials, and ensure secure pairing and communication protocols.

03

Fraud prevention (Article 3.3(f)): equipment enabling financial transactions must authenticate transaction parties, resist relay and replay attacks, protect cryptographic keys in secure storage, and log transaction anomalies.

04

Secure software update mechanisms: devices must support integrity-verified over-the-air or wired firmware updates, with rollback protection and authenticated update servers — a cross-cutting requirement under all three articles.

05

Authentication and access control: all network-accessible interfaces must require authentication; default credentials must be unique per device or require mandatory change on first use; privileged access must be separated from user access.

06

Secure configuration and hardening: unused network services and physical interfaces must be disabled by default; security-relevant configuration changes must be logged; debug interfaces must be disabled or access-controlled in production firmware.

07

Vulnerability handling and disclosure: manufacturers must operate a coordinated vulnerability disclosure policy, maintain a software bill of materials (SBOM) for network-exposed components, and apply security patches within a defined support window.

## Conformity assessment and harmonised standards

The EN 18031 series is developed jointly by ETSI and CEN-CENELEC under a mandate from the European Commission. Publication in the Official Journal triggers presumption of conformity. Manufacturers should track publication status — the gap between regulation entry into force and harmonised standard publication is a critical compliance risk.

### EN 18031-1 — Internet-Connected Radio Equipment

**Developed by:** ETSI / CEN-CENELEC

Covers the security requirements for radio equipment connecting to the internet under Article 3.3(d) and (e). Defines test methods for network protection, access control, software update integrity, and cryptographic requirements. Developed from ETSI EN 303 645 as a precursor; EN 18031-1 is the harmonised standard under the delegated regulation.

### EN 18031-2 — Radio Equipment Processing Personal Data

**Developed by:** ETSI / CEN-CENELEC

Addresses privacy and personal data protection requirements under Article 3.3(e). Specifies security controls for data minimisation, encryption of personal data in transit and at rest, secure credential storage, and privacy-by-design test criteria for wearables and consumer IoT.

### EN 18031-3 — Radio Equipment Enabling Financial Transactions

**Developed by:** ETSI / CEN-CENELEC

Covers fraud-prevention requirements under Article 3.3(f). Specifies authentication requirements for financial transactions, protection of cryptographic keys used in payment functions, tamper-evidence requirements, and transaction integrity controls.

## Timeline and relationship to the Cyber Resilience Act

August 2025 marks a sharp compliance cliff for connected radio equipment. Manufacturers who have not started their EN 18031 assessment are already in a tight window. Planning for CRA alignment from the outset — rather than retrofitting after RED compliance — will save significant engineering and documentation cost.

### August 1, 2025 — Compliance Date

Radio equipment placed on the EU market after this date must comply with the essential requirements of Articles 3.3(d), (e), and (f) as activated by Delegated Regulation 2022/30. Products in the supply chain before this date benefit from a transitional sell-through period.

### Harmonised Standards Publication

The EN 18031 series must be published in the Official Journal of the EU to confer presumption of conformity. If standards are not published by the compliance date, manufacturers may use alternative technical specifications or other technical solutions — at increased documentation burden.

### Cyber Resilience Act — December 2027

The CRA applies to all products with digital elements placed on the EU market. For connected radio equipment, RED 2022/30 and CRA requirements overlap substantially. Manufacturers should design their security architecture to satisfy both simultaneously.

### Aligning RED and CRA Assessments

Security testing performed against EN 18031 will generate evidence reusable for CRA conformity assessments. Maintain a unified technical file covering both frameworks. CRA introduces mandatory Notified Body involvement for critical products — plan your assessment route to avoid duplicating test campaigns.

## Frequently asked questions

### Does RED 2022/30 apply to Bluetooth-only products?

Yes, if the Bluetooth-only product connects to a public electronic communications network (indirectly via a paired phone), processes personal data (e.g. a fitness tracker), or enables financial transactions. Most consumer Bluetooth wearables fall under Article 3.3(e) because they collect health or location data. A simple Bluetooth peripheral like a keyboard that processes no personal data and has no network connectivity may fall outside scope — but manufacturers should document their scope assessment carefully.

### How does EN 18031 relate to the ETSI standards already used for RED?

The EN 18031 series is a new suite of harmonised standards developed specifically for the cybersecurity essential requirements activated by Delegated Regulation 2022/30. They are separate from the radio spectrum standards (e.g. EN 300 328 for 2.4 GHz) used to satisfy RED Article 3.2. Manufacturers must satisfy both Article 3.2 (spectrum) and Article 3.3(d/e/f) (cybersecurity) — the EN 18031 standards address only the latter.

### Can we self-certify against RED 2022/30 or do we need a Notified Body?

Self-certification (Module A internal production control) is available for compliance with Articles 3.3(d), (e), and (f) provided harmonised standards covering those requirements are in force. Where no harmonised standard is available or the manufacturer departs from one, EU-type examination by a Notified Body (Module B + C) is required. Manufacturers should monitor Official Journal publications closely.

### What happens if the harmonised standards aren't published in time?

If the EN 18031 series is not published in the Official Journal by August 1 2025, manufacturers cannot rely on presumption of conformity from harmonised standards. They must demonstrate compliance through alternative means: third-party assessment against the normative requirements in the delegated regulation, use of other published specifications (e.g. ETSI EN 303 645 as a technical reference), or EU-type examination by a Notified Body. Market surveillance authorities will assess whether the technical solution demonstrably meets the essential requirements.

**Disclaimer:** This page is an educational resource only and does not constitute legal or regulatory advice. Compliance requirements depend on your specific product configuration, intended markets, and regulatory interpretation at time of assessment. Always consult qualified legal counsel and accredited test laboratories for product-specific compliance decisions.

🇪🇺 CE Marking roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇪🇺 CE Marking compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/08-cybersecurity-compliance-connected-electronics)[Prefer to read? Get the book — $24.99](/books/08-cybersecurity-compliance-connected-electronics)

Related guides

*   [EU Cyber Resilience ActEU Cyber Resilience Act for hardware: default-secure requirements, vulnerability disclosure, 24-hour incident notification, and the four Annex I product classes.](/guides/eu-cyber-resilience-act)
*   [EU NIS2 Directive for HardwareNIS2 Directive (EU) 2022/2555 extends cybersecurity obligations to manufacturers of connected products and critical infrastruct…](/guides/eu-nis2-directive-hardware)
*   [RED Directive ComplianceEverything you need to know about the Radio Equipment Directive: scope, essential requirements, testing, harmonised standards, …](/guides/red-directive-compliance)
*   [US IoT Cybersecurity ActGuide to the IoT Cybersecurity Improvement Act of 2020 — NIST SP 800-213A baseline, federal procurement requirements, and the F…](/guides/us-iot-cybersecurity-act)