Your EU partner for CE marking, certification & compliance

Radio Equipment Directive 2014/53/EU (RED)

Any product that intentionally emits or receives radio waves - Wi-Fi, Bluetooth, Zigbee, NFC, GNSS, cellular, remote controls - falls under the RED. Since 1 August 2025 many of them must also meet cybersecurity requirements.

Article 3 essential requirements Cybersecurity since 1 August 2025 USB-C since 28 December 2024 Notified Body sometimes required

Essential requirements (Article 3)

ArticleRequirementTypical standards
3(1)(a)Health and safety, including the LVD objectives without the lower voltage limitEN IEC 62368-1, EN 62311 / EN 62479 (RF exposure)
3(1)(b)Electromagnetic compatibilityEN 301 489-1 plus the relevant part
3(2)Effective and efficient use of radio spectrumFor example EN 300 328 (2.4 GHz), EN 301 893 (5 GHz), EN 300 220 (SRD)
3(3)(d)(e)(f)Network protection, personal data and privacy, protection from fraud - activated by Delegated Regulation (EU) 2022/30EN 18031-1, -2, -3

Cybersecurity since 1 August 2025

Delegated Regulation (EU) 2022/30 applies to internet-connected radio equipment; to radio equipment that processes personal, traffic or location data if it is internet-connected, a toy, childcare equipment or a wearable; and to internet-connected radio equipment that enables money transfers. The harmonised standards EN 18031-1, -2 and -3 were cited in the Official Journal with restrictions. Where a restriction applies to your product - for example around password options - the standard alone does not give a presumption of conformity, and a Notified Body must be involved for those requirements.

USB-C common charger

Directive (EU) 2022/2380 amended the RED: since 28 December 2024, mobile phones, tablets, digital cameras, headphones, headsets, handheld game consoles, portable speakers, e-readers, keyboards, mice, portable navigation systems and earbuds that can be recharged by cable must have a USB-C receptacle. Laptops have been covered since 28 April 2026. They must also be offered without a charger, with a pictogram and label showing this.

When a Notified Body is needed

For Article 3(1)(a) and (b), the manufacturer can always self-assess. For Article 3(2) and 3(3), self-assessment (Module A) is only allowed where harmonised standards have been applied in full. Otherwise the manufacturer must use EU-type examination (Modules B + C) or full quality assurance (Module H).

Product information

Frequently asked questions

Does my Bluetooth product need to meet RED cybersecurity requirements?

If it can communicate over the internet directly or via another device, it is covered by the network-protection requirement. If it also processes personal, traffic or location data - or is a toy, childcare product or wearable that processes such data - the privacy requirement applies too. Check the exact scope in Article 1 of Delegated Regulation (EU) 2022/30.

Is a Notified Body mandatory under the RED?

Not always. It is mandatory where the harmonised standards for Article 3(2) or 3(3) have not been applied in full, including where EN 18031 restrictions apply to the product.

Does a product with a radio also need LVD and EMC compliance?

The RED covers safety and EMC itself through Article 3(1). The LVD and the EMC Directive do not apply in addition, but RoHS and Ecodesign may.

What about the Cyber Resilience Act?

The Cyber Resilience Act (EU) 2024/2847 will set horizontal cybersecurity requirements for products with digital elements. Its main obligations apply from 11 December 2027; reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026.

Related guides

Note: This guide provides general information about EU product legislation, not legal advice. Check the current legal texts on EUR-Lex for your product. Last reviewed 5 October 2026.

Check what your product needs for the EU market

Tell us where your company is based, your product sector and how far your documentation is. Before any engagement, we send you a proposed compliance route.

Free scope check