Skip to content
folhas.io
secure by design for connected products· Articles

Articles

CRA and RED: the radio-equipped device now lives under two regimes

Since August 2025, any radio equipment connected to the internet has had to meet the RED's cybersecurity requirements. The CRA will replace them, but until December 2027 the two regimes coexist, and work done under one does not automatically count under the other.

Published

Anyone building devices with radio (Wi-Fi, Bluetooth, LoRa, NB-IoT, cellular) is not waiting for the CRA to have cybersecurity obligations. They already have them, since 1 August 2025, by way of the Radio Equipment Directive.

The regime that already applies

Delegated Regulation (EU) 2022/30 activated three dormant essential requirements of Article 3(3) of the RED (Directive 2014/53/EU):

  • (d) network protection: for any radio equipment that communicates over the internet, directly or through other equipment;
  • (e) protection of personal data and privacy: when the equipment processes personal, traffic or location data; with extended reach to childcare equipment, toys and wearables;
  • (f) protection from fraud: when the equipment enables the transfer of money, monetary value or virtual currency.

The harmonised route is the EN 18031 series: part 1 (network protection, 31 requirements), part 2 (privacy, 40 requirements) and part 3 (fraud, 34 requirements), cited in the Official Journal on 30 January 2025. Applying the standard in full, the manufacturer gains presumption of conformity and can self-declare.

With a catch that trips up teams every month: the OJ citation came with restrictions. Among them, the presumption of conformity falls away if, when applying certain clauses, the user can set no password at all, or if parental control is not ensured in the categories that require it. Wherever a restriction removes the presumption, self-declaration closes for that requirement, and a notified body steps in under Annex III of the RED. Reading the notices of the citation decision is not optional.

What changes with the CRA

The CRA absorbs this ground: at full application, on 11 December 2027, Delegated Regulation 2022/30 is repealed and the cybersecurity of radio equipment “moves house” to the CRA, which is broader (all products with digital elements, with or without radio, plus software sold as a product) and deeper (life-cycle obligations, vulnerability handling, support period, reporting).

Timeline 2024 to 2028: EN 18031 is mandatory under the RED from August 2025 until it is repealed in December 2027; under the CRA, 24 and 72 hour reporting applies from September 2026 and full application arrives in December 2027; the two regimes coexist in that interval.
The coexistence window: EN 18031 is already binding, and the CRA does not wait for full application to demand reporting.

Until then, coexistence. And two uncomfortable facts about that coexistence:

  1. EN 18031 work carries no presumption over to the CRA. The two presumption-of- conformity systems are distinct; the CRA’s harmonised standards are different ones and are, for the most part, still being drafted. What does carry over is the underlying engineering work, such as access control, update management and data protection, which will remain largely reusable. It is the documentation that will have to be remapped.
  2. Article 14 of the CRA does not wait for full application. The reporting obligations apply from 11 September 2026 also to products already on the market, including those that never went through EN 18031 because they predate August 2025.

How not to do the work twice

The sequence we recommend to anyone with a radio device in development:

  1. Close out EN 18031 first. It has been a live obligation since August 2025 and cannot wait for the CRA. Treat the citation’s restrictions as design requirements (never allow passwordless operation where the clause forbids it).
  2. Map each EN 18031 requirement to the corresponding essential requirement in Annex I of the CRA at the moment it is documented, not in 2027. The marginal cost of keeping the traceability matrix now is small; rebuilding it later is a project.
  3. Design the technical documentation once, with two views. A single technical file (risk analysis, architecture, tests, SBOM) from which the RED view and the CRA view are extracted. Two parallel files always diverge.

What this means for manufacturers

For a small manufacturer, the strategic reading is this: the RED DA is the dress rehearsal for the CRA with a reduced scope. Whoever treats EN 18031 as a minimal checklist will pay for the CRA in full in 2027; whoever treats it as the first iteration of the same product security management system arrives in December 2027 with most of the work done and documented. The difference lies in doing the work once or twice, not in the effort of each pass.

Sources