USA | EN

RED cybersecurity requirements

From 1st August 2025, all wireless devices placed on the EU market must comply with the Radio Equipment Directive (RED) cybersecurity requirements.
Secure Phone

What are the RED cybersecurity requirements?

More and more products are now employing radio technology in their applications. Many of these devices connected to the internet may face security risks, making it vulnerable to potential attacks and exploitation.

To mitigate these risks, the European Commission adopted a Delegated Act of the Radio Equipment Directive activating Articles 3(3)(d), (e) and (f) for certain categories of radio equipment to increase the level of cybersecurity, personal data protection and privacy, and protection of financial transactions.

The RED delegated act activates Articles 3(3)(d), (e) and (f), which cover the following:

  • Article 3.3 (d) – radio equipment does not harm the network or its functioning nor misuse network resources, thereby causing an unacceptable degradation of service.
  • Article 3.3 (e) – radio equipment incorporates safeguards to ensure that the personal data and privacy of the user and of the subscriber are protected.
  • Article 3.3 (f) – radio equipment supports certain features ensuring protection from fraud.

The type of wireless products impacted by the RED cybersecurity requirements:

  1. Equipment that uses radio technology for communication over the internet such as mobile phones, tablets, electronic cameras, telecommunication equipment.
  2. IoT devices that can transmit data over the Internet.
  3. Toys and childcare equipment such as baby monitors.
  4. Wearable devices such as smartwatches or fitness trackers.
  5. Connected industrial devices.

The role of EN 18031-1, EN 18031-2 and EN 18031-3 in RED cybersecurity compliance

The EN 18031 series of standards is essential for achieving full RED Cybersecurity compliance for radio equipment. These standards guide manufacturers in implementing robust cybersecurity measures and protecting users and networks from potential threats.

  • EN 18031-1 specifies the general cybersecurity requirements for radio devices, ensuring that all equipment is secure, resilient, and compliant with the RED Cybersecurity framework.
  • EN 18031-2 focuses on privacy and data protection, providing requirements to safeguard personal and sensitive user data in line with RED Cybersecurity expectations.
  • EN 18031-3 addresses protection against fraud and network misuse, establishing technical measures to prevent exploitation of radio equipment and maintain network integrity under the RED Cybersecurity rules.

By following EN 18031-1, EN 18031-2, and EN 18031-3, manufacturers can design, test, and certify their radio equipment with confidence, ensuring compliance with all RED Cybersecurity requirements and enhancing trust with end-users. 

Get started with TÜV SÜD 

Start your Radio Equipment Directive cybersecurity journey with us.

What is the deadline to comply with red cybersecurity requirements?

The RED delegated act will enter into force in August 2025. While the harmonised standards are not yet published, you should consult with TÜV SÜD experts early in the product development process. This will help you plan the necessary steps and start evaluating your products early.

The timeline for compliance with RED cybersecurity requirements is as follows:

Implementation timeline for RED cybersecurity

How TÜV SÜD can help you with the RED cybersecurity requirements

TÜV SÜD provides testing and evaluation services based on standards such as EN 303 645 and IEC 62443. Our laboratories can perform a variety of tests and services to prepare for the incoming regulation. We are also actively involved with the development of cybersecurity standards globally.

In addition, TÜV SÜD is an EU Notified Body for the Radio Equipment Directive. Therefore, we can support you in complying with the requirements of the Radio Equipment Directive together with other regulations and standards applicable to radio equipment and devices, including assessments aligned with EN 18031-1, EN 18031-2 and EN 18031-3

Please contact TÜV SÜD if you need more information on:

  • Understanding if your radio equipment product is in the scope of RED cybersecurity.
  • What are the best practices presently, such as secure-by-design
  • Understanding the present status of standardization
  • How to plan to ensure confidence in the security of your product

FAQs about RED cybersecurity requirements

What is RED?
The Radio Equipment Directive (RED) is a European Directive which regulates the placing of radio equipment on the EU market. It sets out essential requirements and conformity assessment procedures that manufacturers and importers of radio equipment must adhere to before placing their products on the EU market. The existing RED essential requirements, radio performance, safety and electromagnetic compatibility (EMC), have recently been extended by a delegated regulation requiring cybersecurity compliance for certain products.
What do the RED cybersecurity requirements mean?

The RED cybersecurity requirement aims to increase the level of cybersecurity, personal data protection and privacy, and protection of financial transactions through the activation of Articles 3.3 (d), (e) and (f) as essential requirements:

  • Article 3.3 (d) - radio equipment does not harm the network or its functioning, nor misuse network resources, thus causing an unacceptable degradation of service.
  • Article 3.3 (e) - radio equipment includes safeguards to protect the personal data and privacy of the user and the subscriber.
  • Article 3.3 (f) - radio equipment supports certain features ensuring protection from fraud

What is outside the scope of RED cybersecurity requirements?

The following is completely excluded for RED Article 3.3 (d), (e) and (f):

  • Medical devices

The following are excluded for RED Article 3.3 (e) and (f):

  • Aviation
  • Motor vehicles
  • Electronic road toll systems

The following are excluded for RED Article 3.3 (e) and (f):

  • Radio products that are not connected to the internet, such as a DAB broadcast receiver and radar that are products under the scope of the RED, but are not in the scope of the RED cybersecurity requirements 
What should manufacturers do now?
While the extended period will allow more preparation time for manufacturers, the transition timeline should not result in a delay in preparing and assessing the cybersecurity health of their products. Manufacturers of wireless products are advised to consult with TÜV SÜD early in the product development process to plan the necessary steps and start evaluating their products now instead of waiting for the standards to be published. It is key to engage in advanced preparation and early actions.

Contact TÜV SÜD today to understand how we can help prepare for the incoming RED cybersecurity requirements. We can also further assist in increasing security for your products.

Knowledge highlights

Article

Cybersecurity and information technology security services concept. Login or sign in internet concepts.

#Service knowledge #Future insights #Cybersecurity #Consumer Products and Retail

ETSI EN 303 645 Cybersecurity for Consumer IoT