Context card
The Radio Equipment Directive: when sector law absorbs aspect requirements
Why does the cybersecurity part of the Radio Equipment Directive create parallel compliance paths?
The short answer
The Radio Equipment Directive (RED) is sector legislation: it covers one product group, radio equipment, but also carries aspect requirements that horizontal acts cover for all other products — safety, EMC and, since August 1, 2025, cybersecurity, privacy and fraud protection through Delegated Regulation (EU) 2022/30. When the horizontal Cyber Resilience Act covers the same aspect, the result is two routes for the same objective. The Commission resolved this overlap by repealing the RED cybersecurity delegated act with effect from December 11, 2027.
For: Product compliance managers, regulatory affairs specialists, engineers and technical writers working on connected products
Key points
- Sector legislation regulates a product group (radio equipment, machinery, medical devices); aspect or horizontal legislation regulates one concern across products (electrical safety, EMC, cybersecurity).
- RED Article 3(1) takes over the safety objectives of the Low Voltage Directive (without its voltage limits) and the EMC requirements, so radio equipment follows RED instead of those directives.
- Delegated Regulation (EU) 2022/30 activated Article 3(3)(d), (e) and (f) — network protection, personal data and privacy, fraud — for internet-connected and certain other radio equipment from August 1, 2025; EN 18031-1 to -3 are the harmonized standards.
- The CRA Annex I requirements cover these three aspects. The Commission adopted a repeal of 2022/30 in February 2026 with effect from December 11, 2027, when the CRA applies in full.
- Until then, manufacturers of connected radio equipment follow RED and prepare for the CRA in parallel; the date of placing on the market decides which regime applies.
The context
Sector and aspect
EU product law has two kinds of acts. Sector legislation covers a product group with everything that matters for it. Aspect legislation (horizontal legislation) covers one concern for every product in its scope — the Low Voltage Directive for electrical safety, the EMC Directive for electromagnetic compatibility, the Cyber Resilience Act for cybersecurity.
The architecture stays clean as long as each aspect has one home. It gets noisy when a sector act absorbs an aspect that a horizontal act also regulates: obligations are duplicated, scopes are drawn differently, and a manufacturer of a product under several acts follows parallel compliance paths for one objective.
What RED carries
The Radio Equipment Directive 2014/53/EU is sector legislation with aspect requirements built in:
- Article 3(1)(a): health and safety, including the objectives of the Low Voltage Directive without its voltage limits.
- Article 3(1)(b): electromagnetic compatibility.
- Article 3(2): efficient use of the radio spectrum — the genuinely sector-specific core.
- Article 3(3): further requirements that the Commission can switch on for categories of radio equipment by delegated act.
Delegated Regulation (EU) 2022/30 switched on Article 3(3)(d), (e) and (f). Since August 1, 2025, internet-connected radio equipment, toys and childcare equipment with radio functions, wearables and radio equipment for payments must meet cybersecurity, privacy and fraud requirements, supported by the harmonized standards EN 18031-1 to -3.
The overlap and its resolution
The CRA covers the same aspects horizontally for all products with digital elements. Two acts for one aspect is exactly the structural noise described above. The Commission therefore adopted a repeal of Delegated Regulation 2022/30 in February 2026, effective December 11, 2027, the day the CRA applies in full. From then on, the cybersecurity of radio equipment sits in the CRA, and references to the RED cybersecurity standards are to be withdrawn from the Official Journal, so they no longer give presumption of conformity.
What it means for documentation
For connected radio equipment placed on the market before December 11, 2027, the technical documentation shows conformity with RED including Article 3(3)(d)–(f). Products placed on the market from that date need the CRA route. A product that also falls under the Machinery Regulation or another sector act adds its own requirements on top. Mapping each requirement to the act it comes from — and the standard used to meet it — keeps the CE marking traceable. Naming an act or a standard never proves conformity by itself.
Questions readers ask next
- Did RED only become a safety law with the 2022 delegated act?
- No. Health and safety and EMC were part of RED from the start (and of its predecessor, the R&TTE Directive). The delegated act added cybersecurity, privacy and fraud protection — the aspect that the CRA now covers horizontally.
- Does the repeal mean RED cybersecurity work was wasted?
- No. The CRA requirements cover the same aspects, and work done for EN 18031 feeds the CRA risk assessment and documentation. Products placed on the market until December 10, 2027 remain assessed against RED.
Sources
- Directive 2014/53/EU on radio equipment — Official Journal of the European Union, May 22, 2014
- Commission Delegated Regulation (EU) 2022/30 supplementing Directive 2014/53/EU — Official Journal of the European Union, January 12, 2022
- Regulation (EU) 2024/2847 (Cyber Resilience Act) — Official Journal of the European Union, November 20, 2024
- European Commission repeals RED cybersecurity delegated regulation as CRA comes into full effect — CSA Group, February 25, 2026
Review log and changes
Every context card is checked against its sources before it is published, and again whenever it changes; the date under the byline is the last review. Corrections (something was wrong) and additions (something was missing) are logged below with date and time (Berlin time). Typos, formatting and link fixes are not listed.
Reviewed
No corrections or additions since publication.