Certain radio equipment is currently subject to cybersecurity requirements activated under the Radio Equipment Directive. The Commission has now created a defined transition: Delegated Regulation 2022/30 remains relevant through 10 December 2027 and is repealed from 11 December 2027 as the CRA's horizontal product-security framework becomes generally applicable.
The RED Cybersecurity Rules Apply to a Narrower Product Context
The Radio Equipment Directive, Directive 2014/53/EU, regulates radio equipment placed on the Union market. Its essential requirements include provisions that can address network protection, privacy and protection from fraud. Commission Delegated Regulation (EU) 2022/30 activated the cybersecurity-related requirements in Article 3(3)(d), (e) and (f) for specified categories of radio equipment. The CRA has a broader horizontal concept: it covers relevant products with digital elements where the statutory scope conditions are met, including software and hardware that may have no radio functionality at all. A connected radio product can therefore fall within both legal landscapes during the transition period, but the scope analysis for each instrument is different and should not be collapsed into one generic connected-device test.
The RED Cybersecurity Requirements Have Applied Since 1 August 2025
The cybersecurity requirements activated through Delegated Regulation (EU) 2022/30 have applied to relevant categories of radio equipment since 1 August 2025. For internet-connected radio equipment, the network-protection requirement in Article 3(3)(d) can apply. Privacy and personal-data protection under Article 3(3)(e) apply to specified equipment capable of processing relevant data, including certain internet-connected equipment, childcare products, toys with radio functions and wearable radio equipment. Article 3(3)(f) addresses fraud protection for specified internet-connected radio equipment capable of enabling transfers of money, monetary value or virtual currency. Manufacturers working in 2026 therefore cannot ignore the existing RED cybersecurity regime simply because the CRA's main application date is still in the future.
The CRA Creates a Wider Horizontal Product-Security Framework
The CRA is not limited to radio equipment or the three cybersecurity subjects activated under the RED delegated regulation. Annex I establishes a broader set of product cybersecurity and vulnerability-handling requirements covering matters such as secure design, protection from unauthorised access, confidentiality, integrity, availability, attack-surface reduction, security logging where applicable, secure updates and vulnerability management. Manufacturers also need a cybersecurity risk assessment, technical documentation, a defined support period, conformity assessment and post-market processes. This wider lifecycle structure is one reason the Commission decided that maintaining the RED delegated cybersecurity regime alongside the fully applicable CRA would create unnecessary overlap. The CRA becomes the horizontal cybersecurity framework while the underlying Radio Equipment Directive continues to regulate other radio-equipment requirements.
Delegated Regulation 2026/339 Creates the Transition
In February 2026, the Commission adopted Delegated Regulation (EU) 2026/339 specifically to address the relationship between the two cybersecurity regimes. The measure states that the CRA Annex I requirements include the elements addressed by the RED cybersecurity requirements in Article 3(3)(d), (e) and (f). To provide legal certainty and avoid simultaneous cybersecurity obligations covering the same issues, Regulation 2026/339 repeals Delegated Regulation 2022/30 with effect from 11 December 2027. The date is deliberate because it matches the general application date of the CRA. The repeal concerns Delegated Regulation 2022/30. It does not repeal Directive 2014/53/EU itself, so manufacturers of radio equipment still need to analyse the other applicable RED requirements.
Products Placed on the Market Before the CRA Transition Still Matter
The 2026 repeal regulation also preserves market surveillance and control for radio equipment that was or is placed on the Union market during the RED cybersecurity period. It states that repeal does not affect surveillance of compliance with Article 3(3)(d), (e) and (f) for relevant equipment placed on the market between 1 August 2025 and 10 December 2027. Manufacturers should therefore retain the conformity evidence supporting products placed on the market under the RED cybersecurity regime. The arrival of 11 December 2027 does not retrospectively erase the legal requirements that applied when those products were placed on the market. Product history and market-placement dates remain important for determining which conformity evidence and surveillance framework applies.
The Transition Does Not Mean Every Radio Product Automatically Falls Under the CRA
The policy transition from RED cybersecurity rules to the CRA should not be confused with a universal scope transfer. CRA applicability still depends on the CRA's own definition of a product with digital elements, the product's intended or reasonably foreseeable use, the relevant connection to a device or network, the circumstances in which it is made available on the Union market and any applicable exclusion or special rule. Likewise, the RED remains relevant where the product qualifies as radio equipment. A manufacturer may therefore need a combined regulatory map covering radio-spectrum and radio-equipment conformity requirements under the RED, cybersecurity requirements under the CRA and any additional sector-specific Union legislation. The correct compliance architecture is based on the product and applicable legal acts, not on choosing one regulation as the sole label for the device.
CE Marking Can Represent Compliance With Multiple EU Product Laws
Both the RED and CRA operate within the EU product-compliance environment and can contribute requirements that a product must satisfy before lawful market placement. The CRA recognises that products can be covered by multiple Union harmonisation acts and allows the EU declaration of conformity to cover the relevant Union legislation. In practice, connected radio equipment after the CRA transition may still need to demonstrate compliance with non-cybersecurity RED requirements while also satisfying CRA cybersecurity requirements. Compliance teams should therefore maintain one product-level map showing each applicable Union act, the conformity route used, standards or specifications relied upon and the evidence supporting each requirement. A CE mark should be understood as the end result of applicable conformity work rather than proof that only one regulation applies.
How Radio Equipment Manufacturers Should Prepare for 2027
Manufacturers should treat the period before December 2027 as a controlled migration rather than an abrupt regulatory switch. Continue maintaining RED cybersecurity conformity for products placed on the market while Delegated Regulation 2022/30 applies. At the same time, assess the CRA scope and classification of product families expected to be marketed after the CRA becomes generally applicable. Map current RED cybersecurity controls to CRA Annex I, identify additional CRA requirements, establish vulnerability-handling and support-period processes, and update technical documentation. Product release plans should record the intended market-placement date because a model placed on the market in 2027 can sit in a different legal transition position from a later version released after the CRA application date.
Official sources
Read the full legal text and Commission material for precise wording, qualifications and updates.