For twenty years, CE marking on a radio product answered three questions: is the device electrically safe, does it avoid interfering with its neighbours, does it use the radio spectrum correctly. Cybersecurity was not part of the picture.
Since 1 August 2025, that is no longer true. A connected thermostat, an industrial sensor, a charging station or a communicating toy must now demonstrate a level of digital security before being placed on the European market. For a Swiss manufacturer that exports, this is a new condition of market access, not an optional good practice.
This article explains what these requirements cover, how to know whether your product is affected, and why you must not confuse them with the Cyber Resilience Act.
Where does this obligation come from?
The RED Directive, formally Directive 2014/53/EU, governs the placing on the market of radio equipment in the European Union. Its Article 3(3) contains a list of additional essential requirements that remain dormant until the Commission activates them.
That is exactly what happened. Delegated Regulation (EU) 2022/30, adopted on 29 October 2021, activated three of these requirements, points d, e and f. Its application was originally set for 1 August 2024, then postponed by one year through Delegated Regulation (EU) 2023/2444, to allow time for the harmonised standards to be ready. The date that matters today is therefore 1 August 2025.
These three requirements can be summarised as follows:
- point d: the equipment must not harm the network or degrade its functioning in an unacceptable way;
- point e: the equipment must include safeguards protecting users’ personal data and privacy;
- point f: the equipment must incorporate functions protecting against fraud.
A single product may be affected by only one of these requirements, by two, or by all three. This is the first piece of analysis to carry out, and it shapes everything that follows.
Am I affected? The question of scope
The Directive defines radio equipment as an electrical or electronic product that intentionally emits and/or receives radio waves for the purpose of radio communication or radio determination. In practice, as soon as your product has WiFi, Bluetooth, LoRa, 4G or NB-IoT, you are a manufacturer of radio equipment, even if you never thought of yourself that way.
The Delegated Regulation then targets three families of products, matching the three activated points.
Point d covers radio equipment able to communicate, directly or indirectly, via the internet: a connected thermostat, a surveillance camera, a LoRaWAN gateway, a remotely controlled charging station, an industrial controller reporting its measurements to the cloud.
Point e covers childcare equipment, radio toys, wearable equipment worn on the body, and more broadly connected equipment that processes personal data or location data. A baby monitor, a connected watch, an interactive toy, an occupancy sensor in a building.
Point f covers connected equipment enabling transfers of monetary value: a communicating payment terminal, a charging station with integrated payment, a connected vending machine.
The RED Directive applies to the product placed on the market of the Union, not to the manufacturer's domicile. A manufacturer based in Vaud or Fribourg selling into Germany, France or Italy carries exactly the same obligations as a German manufacturer. If you export, you are affected. Also pay attention to the role played by your European distributors and importers: responsibility for the product's conformity remains yours.
The Regulation also provides for exclusions. Its Article 2 excludes from its scope radio equipment already governed by the medical devices regulations (EU) 2017/745 and (EU) 2017/746, by civil aviation regulation (EU) 2018/1139, by motor vehicle type-approval (EU) 2019/2144, and by toll systems (EU) 2019/520. A communicating medical device therefore does not escape cybersecurity, but it is addressed within its own sector-specific framework.
The three EN 18031 standards: what are they for?
An essential requirement is written in general terms. It states the expected outcome, not the way to reach it. This is where harmonised standards come in, to bridge that gap.
Three standards have been developed, and their references were published in the Official Journal of the European Union through Implementing Decision (EU) 2025/138 of 28 January 2025. Each addresses one of the three requirements.
| Standard | Requirement covered | Products targeted | General objective |
|---|---|---|---|
| EN 18031-1 | Article 3(3)(d) | Radio equipment connected to the internet | Preventing the device from harming the network or acting as a relay for an attack |
| EN 18031-2 | Article 3(3)(e) | Equipment processing personal data, toys, childcare equipment | Protecting users’ personal data and privacy |
| EN 18031-3 | Article 3(3)(f) | Equipment enabling transfers of monetary value | Preventing fraud and manipulation of transactions |
These standards are paid documents, sold by standardisation bodies. Their content cannot be reproduced here, and there is in any case little value in skimming through their clauses. What matters for a business leader is their underlying logic.
That logic is one of a risk analysis applied to the product. You identify what needs protecting in your device: credentials, cryptographic keys, user data, network interfaces, update mechanisms. You then establish which threats apply to each of these elements, and you show which mechanisms in your product address them. Each requirement of the standard is handled this way: either you demonstrate that an adequate mechanism exists, or you justify precisely why it does not apply to your product.
This is as much an exercise in documentation as in engineering. Most failures observed do not come from an unsafe product, but from a file unable to demonstrate what the product already does.
The references of the three standards were published with restrictions. They concern in particular situations where a user can forgo setting a password, and parental access control for certain equipment. In practice: if no restriction applies to you, you can declare conformity yourself through internal production control. If a restriction applies to you, a notified body must be involved, with the corresponding delay and cost. Check this point before you lock in your launch schedule.
Do not confuse this with the Cyber Resilience Act
This is the most common confusion, and it is costly because it leads people to wait.
Regulation (EU) 2024/2847, known as the Cyber Resilience Act, is a text separate from the RED Directive. It does not amend it and does not replace it today. It covers a much broader scope, all products with digital elements, whether radio or not, hardware or software. Its obligations and its deadlines are its own.
Three differences to remember:
- Scope. The RED Directive covers radio equipment. The Cyber Resilience Act covers all products with digital elements.
- Timeline. The requirements of the RED Directive have applied since 1 August 2025. Those of the Cyber Resilience Act are being phased in on their own schedule.
- Focus. The RED Directive concerns the product’s conformity at the moment it is placed on the market. The Cyber Resilience Act places more emphasis on the lifecycle, vulnerability management and reporting.
The practical conclusion is simple: deal with the RED Directive now, since it governs your current CE marking, but build your documentation knowing it will serve you again. The product risk analysis, the inventory of software components and the secure update process serve both texts. We will devote a separate article to the Cyber Resilience Act.
Where to start, in practice
If you are starting from scratch on an existing product, this order gives the best results.
- Qualify your product. Is it radio equipment within the meaning of the Directive? Which of points d, e and f apply to you? This single answer determines everything that follows.
- Check the exclusions. Does your product fall under one of the sector-specific regulations excluded by Article 2 of the Delegated Regulation?
- Draw up the inventory of what needs protecting. Credentials, keys, user data, communication interfaces, debug ports, update mechanism.
- Carry out the product risk analysis. Which threats, which realistic attack scenarios, which measures already exist in your design.
- Address the gaps. An identical default password across a whole product line, a debug interface left open, unsigned updates are the three most common gaps, and the easiest to fix early.
- Decide on the evaluation route. Internal control or notified body, depending on the applicable restrictions.
- Assemble the technical file. This is what a market surveillance authority will request, sometimes years after launch.
One last point of method. The security of your product also depends on your component and software module suppliers. A vulnerable third-party library in your firmware is your problem, not its author’s. This connects to the topic of supply chain attacks, and it is worth requiring the information you are missing from your suppliers.
If your product sends data back to your servers, your obligations do not stop at CE marking either: the processing of that data also falls under your FADP obligations in Switzerland. For industrial environments, the IEC 62443 standard provides a complementary framework.
This article summarises the state of the texts as of 18 July 2026, for the attention of executives and product managers. The exact qualification of a device, the applicability of the exclusions, and the choice of evaluation procedure depend on the precise characteristics of your device. Have your analysis validated before finalising your EU declaration of conformity.
The general climate does not encourage delay. The National Cyber Security Centre received 64,733 voluntary reports in 2025, against 62,954 in 2024. Poorly secured connected devices contribute to a share of these incidents, and European regulation simply translates that finding into a condition of market access.
To assess your company’s cybersecurity fundamentals, the cyber check-up gives you a score and your three priorities within a few minutes. The other texts applicable to Swiss businesses are grouped in the Regulations pillar.