Back to Knowledge Base
Knowledge Base · compliance-process

RED cybersecurity requirements — what changed

20 March 2026 6 min read RED

The Radio Equipment Directive's cybersecurity provisions, the EN 18031 harmonised-standards series, and CE-marking implications for connected radio products.

What changed

The Radio Equipment Directive's delegated cybersecurity provisions activate security, privacy and fraud-prevention requirements for certain internet-connected radio equipment — products that previously only had to meet radio-spectrum and safety rules now also have to address cybersecurity.

The three protection goals

  • Network protection — the device must not harm the network or misuse network resources.
  • Personal data and privacy protection for users.
  • Protection against fraud in connection with electronic payments and value transfers.

EN 18031 and conformity

The EN 18031 series provides harmonised standards that give a presumption of conformity with these requirements. Meeting the applicable parts of the standard is the practical route to demonstrating compliance and supporting CE marking; where you deviate, you carry the burden of justifying conformity another way.

What to do

  • Confirm whether your connected radio product is in scope.
  • Map your design against the relevant EN 18031 parts.
  • Keep the test and documentation evidence that backs your CE marking.

This is an educational explainer. For the canonical regulation reference, see the dedicated RED page — or run an assessment to see how it applies to your product.