Back to Knowledge Base
Knowledge Base · fundamentals

What is RED Article 3(3): the cybersecurity rules already binding on connected devices

20 May 2026 6 min read RED

RED Article 3(3) is the part of the Radio Equipment Directive (2014/53/EU) that lets the Commission activate additional essential requirements. Delegated Regulation (EU) 2022/30 activated three of them — points (d), (e) and (f) — for internet-connected radio e

The short answer

RED Article 3(3) is the part of the **Radio Equipment Directive (2014/53/EU)** that lets the Commission activate additional essential requirements. **Delegated Regulation (EU) 2022/30** activated three of them — points (d), (e) and (f) — for internet-connected radio equipment.

**They have applied since 1 August 2025.** The original date was 1 August 2024; it was deferred by one year. That deferral is over.

This is the requirement most often missed, for a structural reason: **it is not a new law.** It is an addition to a directive manufacturers have complied with for years, so there was no new instrument to notice — only a change in what the existing CE marking now attests.

**Any device with a radio interface that connects to the internet is in scope of point (d).** That includes equipment nobody files under "cybersecurity regulation": a connected sensor, a smart appliance, a wireless speaker, a fitness tracker, a router.

The three requirements

**(d) — Network protection**

The equipment must not harm the network or its functioning, nor misuse network resources, thereby causing an unacceptable degradation of service.

**This is the broadest of the three**, and it applies to internet-connected radio equipment generally. In practice it is the requirement that makes default credentials, open management interfaces and unauthenticated update channels a conformity problem rather than a design preference.

**(e) — Protection of personal data and privacy**

The equipment must incorporate safeguards ensuring that the personal data and privacy of the user and of the subscriber are protected.

**Narrower scope**, aimed at categories including equipment designed or intended for childcare, toys, and wearables — the devices closest to a person, often a child.

**(f) — Protection from fraud**

The equipment must incorporate features ensuring protection from fraud. This targets equipment that enables its holder to **transfer money, monetary value or virtual currency**.

What is excluded

Delegated Regulation (EU) 2022/30 carves out equipment already governed by equivalent regimes — among them medical devices, civil aviation, and motor vehicle equipment covered by the relevant sectoral acts.

**The exclusions are narrow and sector-specific.** A consumer device is very unlikely to fall into one, and "our product is not a security product" is not among them.

How you prove conformity — and why this is the expensive part

Under RED, a manufacturer can self-declare conformity **where harmonised standards have been applied in full**. The relevant standards for Article 3(3)(d), (e) and (f) are the **EN 18031** series — EN 18031-1, EN 18031-2 and EN 18031-3 — cited in the *Official Journal* with **restrictions**.

Those restrictions are the whole issue. **Where a harmonised standard has not been applied, or is cited with a restriction covering the aspect that matters to your product, the presumption of conformity does not extend to that aspect.** The manufacturer then has to use a route involving a **notified body** — EU-type examination, or full quality assurance.

The practical consequences are commercial, not technical:

control, and demand rose sharply around the August 2025 date.

the absence of universal default credentials are architectural. On a device already in production, meeting them can mean a hardware revision.

  • **A notified body has a queue.** Assessment slots are a scheduling constraint you do not
  • **Retrofitting is harder than designing in.** Requirements like authenticated updates and

What it means for exporters

**Point (d) attaches to the product, not to the seller.** A manufacturer outside the EU placing a connected device on the Union market is bound by it, and the importer must verify that the manufacturer has carried out the conformity assessment.

**Certification obtained in another jurisdiction does not transfer.** A device certified to a national scheme elsewhere may well meet comparable technical requirements, but RED conformity is a separate legal act with its own documentation, its own declaration and its own marking. This is one of the most common and most costly assumptions in cross-border product launches.

How it relates to the Cyber Resilience Act

RED Article 3(3) and the CRA overlap: both impose cybersecurity requirements on products placed on the EU market, and a connected radio device can meet the definition of a product with digital elements.

The two are **sequenced rather than cumulative in intent** — the delegated regulation's cybersecurity requirements are expected to give way once the CRA applies in full on 11 December 2027. **Verify the current position before relying on it**, because the interaction is set out in the instruments themselves and has already been amended once.

**What is not in doubt is the interim.** Between now and the CRA's full application, RED Article 3(3) is the binding requirement for connected radio equipment, and it has been binding since August 2025.

What to establish first

1. **Determine whether your device has a radio interface and connects to the internet.** If both are true, point (d) applies. Start there, not with the product category. 2. **Check whether the EN 18031 restrictions touch your product's relevant aspects.** This single determination decides whether you self-declare or need a notified body. 3. **Book the notified body before finalising the launch date**, not after. Availability is the constraint, not the assessment itself. 4. **Audit for default credentials and unauthenticated update paths.** These are the two findings most likely to fail point (d), and both are architectural. 5. **Do not wait for the CRA.** The obligation in force today is RED, and market surveillance applies to products already on the market.

Tools available on NexCyber

Further reading

RED Article 3(3): cybersecurity requirements for IoT in detailWhat is the Cyber Resilience ActCE marking explainedOne evidence set across five EU regulationsRED regulation overview

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. Harmonised standards references and their restrictions are amended by publication in the Official Journal, and the interaction between Delegated Regulation (EU) 2022/30 and the Cyber Resilience Act is set in the instruments themselves — verify against the current texts. Consult your notified body, your competent authority or a qualified adviser.*

This is an educational explainer. For the canonical regulation reference, see the dedicated RED page — or run an assessment to see how it applies to your product.