Enforced since 1 August 2025, the cybersecurity requirements under Article 3.3 of the EU Radio Equipment Directive (RED, 2014/53/EU) have come into full force. Entering 2026, EU Member States are ramping up market surveillance sampling inspections. Cybersecurity compliance is no longer an “added-value feature”, but a hard marketaccess prerequisite for all connected wireless devices exported to the EU.
This article systematically breaks down key changes and practical compliance takeaways under the new CE-RED regulation.
CE-RED is the EU mandatory marketaccess regulation for radio equipment, formally known as the Radio Equipment Directive (2014/53/EU). It replaced the old R&TTE Directive and became fully enforceable in 2017.
Devices with the following functionalities exported to the EU shall comply with CE-RED: WiFi / Bluetooth / BLE - 2.4G / 433 MHz wireless remote control LoRa IoT modules / ZigBee smart networking 4G / 5G cellular communication- NFC radio frequency / wireless charging transmitter- Radar sensors / data transceivers
Simply put: any device actively transmitting or receiving radio signals falls under RED scope.

The key shift in 2026 is not the introduction of cybersecurity rules — these became legally binding back in August 2025. The major developments this year are:
1. Stricter law-enforcement: EU Member States are expanding market-check coverage, focusing heavily on cybersecurity compliance of consumer connected wireless devices.
2. Risk of invalidated certifications: Legacy certificates without cybersecurity assessment will be deemed noncompliant during 2026 market surveillance, which is the primary cause of recent large-scale product delistings.
The 2026 RED compliance system covers five dimensions:

Important reminder: Since 1 August 2025, connected devices must complete Article 3.3 cybersecurity assessment for EU market entry. Traditional RF + EMC + safety test reports alone cannot achieve full compliance.
Cybersecurity obligations do not apply to all wireless devices; they cover three categories:
1. Radio equipment capable of internet access — e.g. WiFi routers, smart cameras, smartwatches
2. Wireless devices processing personal or location data
3. Wireless terminals with payment or financial transaction functions
Quick logic for scope screening: Internet-connected device → comply with 3.3(d) at minimum - Processing personal data → additionally comply with 3.3(e) - Embedded payment function → additionally comply with 3.3(f)
Published August 2024 and listed in the EU Official Journal as harmonized standards in January 2025, EN 18031 is the primary technical reference for cybersecurity compliance.EN 18031-1 (Network Protection): access control, authentication, security-update mechanism, encrypted communication, log retention — prevent devices from being exploited as attack vectors - EN 18031-2 (Privacy Protection): governance of data processing, aligned with GDPR; special considerations for children-oriented devices, location and health data-EN 18031-3 (Anti-Fraud): transaction verification, multi-factor authentication to mitigate payment fraud risks
Critical note per EU Implementing Decision (EU) 2025/138: Selfdeclaration (DoC) privilege is withdrawn under the following three scenarios, requiring review by a Notified Body (NB):
1. Factory default blank passwords or no mandatory password change upon firsttime use
2. Children-targeted devices lacking parental-control functions
3. Payment terminals or smart devices with built-in payment features
These restrictions can be lifted via hardware-firmware design remediation, but extra lead time and budget need to be factored in.
Step 1: Scope identification Check whether your product supports internet access, processes personal data or integrates payment functionality.
Step 2: Gap analysis Evaluate existing design against EN 18031 security control points and generate a gap-assessment report.
Step 3: Select compliance route No triggering of restrictive conditions: Self-Declaration of Conformity (DoC) allowed - Restrictive conditions triggered: engage a Notified Body (NB) qualified for RED cybersecurity assessment
Step 4: Compile complete technical documentation Security design description, threat-model analysis, compliance evidence for each control, vulnerability scan records, end-user security guidelines. Incomplete documentation is frequently the biggest project bottleneck. It is recommended to embed security requirements at early R&D stage to avoid project delays caused by retrospective document preparation.
Step 5: Ongoing maintenance Technical documentation shall be retained for a minimum of 10 years. Substantial firmware modifications affecting security logic require reassessment; ordinary feature updates do not trigger re-evaluation.

The enforcement of CE-RED cybersecurity new rules marks an evolution of EU requirements for wireless products: shifting focus from “functional & non-interfering” to “secure & trustworthy”.