Two regulations. One product. One deadline already passed.
RED Article 3(3)(d)(e)(f) became mandatory on 1 August 2025. If your internet-connected radio equipment was placed on the EU market after that date without cybersecurity compliance, you are in violation now.
CRA follows in December 2027 — and it is significantly more demanding. But the overlap between RED Article 3(3) and CRA Annex I means that building your RED compliance programme now creates the foundation for CRA. You are not starting from zero in 2027.
RED Article 3(3) — what is required now
For internet-connected radio equipment (including consumer IoT, wearables, routers, smart home devices):
- (d) Network security — device must not harm network functioning, cannot be weaponised into a botnet
- (e) Personal data protection — encryption, data minimisation, secure credential management
- (f) Fraud protection — authentication, signed firmware updates, session management
Compliance path: self-assess against ETSI EN 303 645 (13 provisions), draw up technical documentation, issue EU Declaration of Conformity, affix CE marking.
→ RED Article 3(3) compliance guide
CRA — what is coming December 2027
CRA applies to all "products with digital elements" placed on the EU market. For IoT manufacturers this means:
Annex I Part I (13 essential security requirements): no default passwords, secure updates, minimal attack surface, encryption, software integrity, audit logging, resilience.
Annex I Part II (operational obligations): SBOM (machine-readable, transitive depth), CVD policy (publicly accessible, operationally active), vulnerability log, ENISA notification workflow (from September 2026 for Article 14).
Conformity assessment: Default class = self-assessment. Important Class I = self-assessment with harmonised standard or third-party. Important Class II = notified body required.
RED × CRA overlap — what you can reuse
| Obligation | RED (ETSI EN 303 645) | CRA Annex I | |---|---|---| | No default passwords | §5.1 | Part I §2(2) | | CVD policy | §5.2 | Part II §1 + Art. 14 | | Secure software updates | §5.3 | Part I §2(7) | | Data encryption | §5.5 | Part I §2(4) | | Minimal attack surface | §5.6 | Part I §2(5) | | Software integrity | §5.7 | Part I §2(1) |
Strategy: Implement ETSI EN 303 645 now for RED CE marking. Use the same controls as the foundation for CRA Annex I. The gap from EN 303 645 to full CRA Annex I is real (SBOM, vulnerability reporting, 10-year retention, more detailed requirements) — but the overlap means the hard architectural work is already done.
What NexCyber provides for IoT manufacturers
- Scope determination: CRA product class + RED applicability in one assessment
- Gap assessment: ETSI EN 303 645 × 13 provisions AND CRA Annex I × 13 requirements mapped simultaneously
- SBOM tracking: completeness check against CRA Annex I Part II requirements
- CVD policy evidence: operational status tracked as a compliance artefact
- MRCC: Machine-Readable Compliance Certificate per product × regulation × version — verifiable CE + CRA readiness signal for buyers
Key dates for IoT manufacturers
| Date | Event | |---|---| | 1 August 2025 | RED Article 3(3) — mandatory now for new products | | 11 September 2026 | CRA Article 14 ENISA vulnerability reporting | | 11 December 2027 | Full CRA obligations |
Tools
- CRA Scope Checker — CRA class + RED applicability
- SBOM Readiness Checker — Annex I Part II completeness
- EU Market Access Score — cross-regulation readiness
Related answers
- RED Article 3(3) IoT compliance
- SBOM under CRA
- CRA Article 14 vulnerability reporting
- Audit-ready evidence for CRA
NexCyber — EU Market Access Compliance Platform