Cybersecurity for Radio Equipment Directive

RED cybersecurity requirements and Compliance with EN 18031-1, EN 18031-2 and EN 18031-3

Comply with RED 2014/53/EU to gain access to the EU radio equipment market

Comply with RED 2014/53/EU to gain access to the EU radio equipment market

From 1st August 2025, all wireless devices placed on the EU market must comply with the Radio Equipment Directive (RED) cybersecurity requirements.

What are the RED cybersecurity requirements?

More and more products are now employing radio technology in their applications. Many of these devices connected to the internet may face security risks, making it vulnerable to potential attacks and exploitation. 

To mitigate these risks, the European Commission adopted a Delegated Act of the Radio Equipment Directive activating Articles 3(3)(d), (e) and (f) for certain categories of radio equipment to increase the level of cybersecurity, personal data protection and privacy, and protection of financial transactions.  

  • Article 3.3 (d) - radio equipment does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service.
  • Article 3.3 (e) - radio equipment incorporates safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected.
  • Article 3.3 (f) - radio equipment supports certain features ensuring protection from fraud.

which devices are covered by THE RED cybersecurity requirements?

RED cybersecurity devices

  1. Equipment that uses radio technology for communication over the internet such as mobile phones, tablets, electronic cameras, telecommunication equipment 
  2. IoT devices that can transmit data over the internet
  3. Toys and childcare equipment such as baby monitors
  4. Wearable devices such as smartwatches or fitness trackers
  5. Connected industrial devices


 

Plan your RED Cybersecurity compliance roadmap with TÜV SÜD.  Contact us now.

 

The Role of EN 18031-1, EN 18031-2 and EN 18031-3 in RED Cybersecurity Compliance

The EN 18031 series of standards is essential for achieving full RED Cybersecurity compliance for radio equipment. These standards guide manufacturers in implementing robust cybersecurity measures and protecting users and networks from potential threats.

  • EN 18031-1 specifies the general cybersecurity requirements for radio devices, ensuring that all equipment is secure, resilient, and compliant with the RED Cybersecurity framework.
  • EN 18031-2 focuses on privacy and data protection, providing requirements to safeguard personal and sensitive user data in line with RED Cybersecurity expectations.
  • EN 18031-3 addresses protection against fraud and network misuse, establishing technical measures to prevent exploitation of radio equipment and maintain network integrity under the RED Cybersecurity rules.

By following EN 18031-1, EN 18031-2, and EN 18031-3, manufacturers can design, test, and certify their radio equipment with confidence, ensuring compliance with all RED Cybersecurity requirements and enhancing trust with end-users. 

What is the deadline to comply with red cybersecurity requirements?

RED directive


how can TÜV SÜD help you with the red cybersecurity requirements?

TÜV SÜD provides testing and evaluation services based on standards such as EN 303 645 and IEC 62443. Our laboratories can perform a variety of tests and services to prepare for the incoming regulation. We are also actively involved with the development of cybersecurity standards globally.

In addition, TÜV SÜD is an EU Notified Body for the Radio Equipment Directive. Therefore, we can support you in complying with the requirements of the Radio Equipment Directive together with other regulations and standards applicable to radio equipment and devices, including assessments aligned with EN 18031-1, EN 18031-2 and EN 18031-3

Please contact TÜV SÜD if you need more information on:

  • Understanding if your radio equipment product is in the scope of RED cybersecurity.
  • What are the best practices presently, such as secure-by-design 
  • Understanding the present status of standardization 
  • How to plan to ensure confidence in the security of your product

FAQs about RED Cybersecurity requirements

  • What is RED?

    The Radio Equipment Directive (RED) is a European Directive which regulates the placing of radio equipment on the EU market. It sets out essential requirements and conformity assessment procedures that manufacturers and importers of radio equipment must adhere to before placing their products on the EU market. The existing RED essential requirements, radio performance, safety and electromagnetic compatibility (EMC), have recently been extended by a delegated regulation requiring cybersecurity compliance for certain products.

  • What do the RED cybersecurity requirements mean?

    The RED cybersecurity requirement aims to increase the level of cybersecurity, personal data protection and privacy, and protection of financial transactions through the activation of Articles 3.3 (d), (e) and (f) as essential requirements:

    • Article 3.3 (d) - radio equipment does not harm the network or its functioning, nor misuse network resources, thus causing an unacceptable degradation of service.
    • Article 3.3 (e) - radio equipment includes safeguards to protect the personal data and privacy of the user and the subscriber.
    • Article 3.3 (f) - radio equipment supports certain features ensuring protection from fraud

    What is outside the scope of RED cybersecurity requirements?

    The following is completely excluded for RED Article 3.3 (d), (e) and (f):

    • Medical devices

    The following are excluded for RED Article 3.3 (e) and (f):

    • Aviation
    • Motor vehicles
    • Electronic road toll systems

    The following are excluded for RED Article 3.3 (e) and (f):

    • Radio products that are not connected to the internet, such as a DAB broadcast receiver and radar that are products under the scope of the RED, but are not in the scope of the RED cybersecurity requirements 

     

  • What should manufacturers do now?

    While the extended period will allow more preparation time for manufacturers, the transition timeline should not result in a delay in preparing and assessing the cybersecurity health of their products. Manufacturers of wireless products are advised to consult with TÜV SÜD early in the product development process to plan the necessary steps and start evaluating their products now instead of waiting for the standards to be published. It is key to engage in advanced preparation and early actions.

    Contact TÜV SÜD today to understand how we can help prepare for the incoming RED cybersecurity requirements. We can also further assist in increasing security for your products.

    Click here for more FAQs 

EXPLORE

ETSI EN 303 645 Cybersecurity Standard for Consumer IoT Products
Infographics

ETSI EN 303 645 cybersecurity standard

Learn more about the first global cybersecurity standard for consumer IoT products.

Learn More

VIEW ALL RESOURCES

Next Steps

Site Selector