Regulatory guide · EU and US
CE, RED Cybersecurity, CRA and FCC: Market Access for Connected Devices (2026)
To sell a connected radio device in the EU you need CE marking under the Radio Equipment Directive 2014/53/EU, which since 1 August 2025 includes cybersecurity requirements usually shown with the EN 18031 standards; from 11 December 2027 the Cyber Resilience Act takes over those obligations for almost all products with digital elements, and its vulnerability and incident reporting duties already apply from 11 September 2026. In the US the same device needs FCC equipment authorization — an FCC ID for the transmitter under Part 15 — and, for most retail and business channels, a safety evaluation to UL/IEC 62368-1.
Key facts
| Requirement | Market | Applies from | Typical evidence |
|---|---|---|---|
| CE under RED 2014/53/EU (safety, EMC, radio) | EU/EEA | In force | Test reports to harmonised standards, technical file, EU declaration of conformity |
| RED cybersecurity, Delegated Reg. (EU) 2022/30 | EU/EEA | 1 August 2025 until 10 December 2027 | EN 18031-1/-2/-3 assessment, or notified body |
| Cyber Resilience Act reporting (Art. 14) | EU/EEA | 11 September 2026 | Process to report exploited vulnerabilities and severe incidents |
| Cyber Resilience Act, full obligations | EU/EEA | 11 December 2027 | Annex I requirements, SBOM, vulnerability handling, support period, CE marking |
| USB-C common charger | EU/EEA | 28 December 2024 (laptops 28 April 2026) | USB-C receptacle and charging behaviour for covered devices |
| Removable portable batteries (Art. 11) | EU/EEA | 18 February 2027 | End-user removable and replaceable, unless an exemption applies |
| FCC Part 15 authorization | US | In force | FCC ID via a TCB for transmitters; SDoC for unintentional radiators |
| Product safety to UL/IEC 62368-1 | US (channel-driven) | In force | NRTL listing or CB report as the channel requires |
Dates were checked against EUR-Lex, the European Commission and the FCC in September 2026 (sources at the end). This page is general engineering guidance, not legal advice; confirm scope for your product with a notified body or test lab.
The EU cybersecurity timeline in one view
| Date | What happens |
|---|---|
| 10 December 2024 | Cyber Resilience Act (Regulation (EU) 2024/2847) enters into force |
| 28 January 2025 | EN 18031-1, -2 and -3:2024 referenced in the Official Journal with restrictions (Implementing Decision (EU) 2025/138) |
| 1 August 2025 | RED Delegated Regulation (EU) 2022/30 applies: cybersecurity becomes part of CE marking for in-scope radio equipment |
| 16 February 2026 | Commission adopts a delegated regulation repealing (EU) 2022/30 with effect from 11 December 2027 |
| 11 June 2026 | CRA provisions on notification of conformity assessment bodies apply |
| 11 September 2026 | CRA reporting of actively exploited vulnerabilities and severe incidents applies — also to products already on the market |
| 11 December 2027 | CRA fully applies; RED cybersecurity delegated regulation repealed |
The practical message for a product launching in 2026–2027: design once to the stricter CRA requirements, and use EN 18031 to demonstrate RED compliance until December 2027. Our blog post on the Cyber Resilience Act for IoT goes deeper into the CRA roadmap.
CE marking under the Radio Equipment Directive
Any product that intentionally transmits or receives radio waves falls under the Radio Equipment Directive rather than the separate EMC and Low Voltage Directives. Its essential requirements map to test standards like this for a typical Bluetooth or Wi-Fi product:
| RED article | Requirement | Typical harmonised standards |
|---|---|---|
| 3.1(a) | Health and safety (no lower voltage limit) | EN IEC 62368-1; RF exposure EN 62479 or EN 62311 |
| 3.1(b) | Electromagnetic compatibility | EN 301 489-1 with the relevant part (e.g. -17 for Bluetooth/Wi-Fi) |
| 3.2 | Efficient use of radio spectrum | EN 300 328 (2.4 GHz), EN 301 893 (5 GHz), EN 300 220 (sub-GHz SRD) |
| 3.3(d)(e)(f) | Network protection, personal data, fraud (via 2022/30) | EN 18031-1, -2, -3 |
If you apply harmonised standards in full, you can use internal production control (Module A): test, compile a technical file, sign the EU declaration of conformity and affix the CE mark. Other EU laws usually apply in parallel: RoHS, WEEE, REACH, the Batteries Regulation, and — for chargers and many small devices — the common charger rules that made USB-C mandatory from 28 December 2024.
RED cybersecurity and EN 18031
Delegated Regulation (EU) 2022/30 activated three RED essential requirements from 1 August 2025. They apply to:
- Radio equipment that can communicate over the internet, directly or through another device (EN 18031-1).
- Radio equipment that processes personal, traffic or location data — including internet-connected devices, toys, childcare equipment and wearables (EN 18031-2).
- Internet-connected radio equipment that enables the transfer of money, monetary value or virtual currency (EN 18031-3).
The EN 18031 standards were cited in the Official Journal on 28 January 2025 with restrictions. The most consequential for product teams: if the user can choose not to set a password (or keep a default one), the standard does not give a presumption of conformity for that product, and the manufacturer must use a notified body (Implementing Decision (EU) 2025/138). Similar restrictions apply to parental controls for toys and childcare products and to some update mechanisms under EN 18031-3.
What the standards look for in practice
- No universal default passwords; unique per-device credentials or a forced change at first use.
- Secure update mechanism: authenticated, integrity-checked firmware updates with rollback protection.
- Protection of stored secrets and personal data (secure element or protected storage, encryption at rest where relevant).
- Secure communication: current TLS or equivalent, no unauthenticated remote interfaces.
- Minimised attack surface: debug ports (JTAG/SWD, UART consoles) locked or disabled in production.
- Logging, resilience to denial of service and documented access control.
The Cyber Resilience Act
The Cyber Resilience Act applies to “products with digital elements” — hardware and software, wired or wireless — placed on the EU market. Compared with the RED delegated regulation it adds lifecycle duties:
- Meet the Annex I essential cybersecurity requirements by design, based on a documented risk assessment.
- Handle vulnerabilities: a disclosure policy, a contact point, and security updates delivered free of charge for a declared support period (at least five years unless the product’s expected use is shorter).
- Include a software bill of materials (SBOM) in the technical documentation.
- From 11 September 2026, report actively exploited vulnerabilities and severe incidents through the single reporting platform: an early warning within 24 hours of becoming aware, a notification within 72 hours, and a final report later.
- Use the conformity assessment route for the product’s class: most products can self-assess; ‘important’ products (Annex III — for example routers, smart-home security products such as door locks, cameras and baby monitors, and certain health-monitoring wearables) need harmonised standards or third-party assessment; ‘critical’ products follow stricter routes.
The reporting obligation applies to products already on the market, so a manufacturer shipping connected devices into the EU needs a working vulnerability-intake and reporting process now, not in 2027 (European Commission).
United States: FCC Part 15 and the FCC ID
In the US, the Federal Communications Commission regulates radio-frequency devices under 47 CFR Part 15:
- Intentional radiators (Bluetooth, Wi-Fi, LoRa, cellular) need Certification: testing at an FCC-recognised lab, then a grant from a Telecommunication Certification Body (TCB), which produces the FCC ID (grantee code plus product code).
- Unintentional radiators (any digital device) use Supplier’s Declaration of Conformity (SDoC) to the Part 15 Subpart B Class A (business) or Class B (residential) limits.
- Modular approval: integrating a module that holds its own grant avoids re-certifying the transmitter if you follow the grant conditions (approved antennas, integration instructions). The host still needs Subpart B compliance and a “Contains FCC ID” label.
- RF exposure: body-worn and handheld devices must meet the exposure limits in 47 CFR 1.1310 or qualify for an exemption; this can require SAR evaluation.
- Covered List: the FCC does not authorize equipment on its Covered List. On 22 December 2025 it added foreign-produced uncrewed aircraft systems and UAS critical components — check module and component vendors against the list early.
Canada’s ISED requirements (RSS-Gen, RSS-247 and others) are usually tested in the same lab session as FCC.
Product safety: UL and IEC 62368-1
IEC 62368-1 (edition 4, 2023) is the hazard-based safety standard for audio/video and ICT equipment. It classifies energy sources — electrical (ES1–ES3), power (PS1–PS3), thermal and mechanical — and requires safeguards between each source and the user. In the EU it is used for RED article 3.1(a) as EN IEC 62368-1; in the US and Canada as UL 62368-1 / CSA C22.2 No. 62368-1; in India as IS/IEC 62368-1:2023. One well-planned evaluation, usually through the IECEE CB Scheme, can feed all three markets.
Batteries add their own layer: IEC 62133-2 for portable lithium cells and packs, UN 38.3 transport testing before you can ship, and the EU Batteries Regulation, whose Article 11 requires portable batteries to be removable and replaceable by the end user from 18 February 2027 unless an exemption applies (Regulation (EU) 2023/1542).
What to design in early
| Area | Decide early | Why |
|---|---|---|
| Radio | Pre-certified module vs chip-down design | A module with FCC/CE/ISED grants removes most intentional-radiator testing |
| Antenna | Placement, keep-out, ground plane, enclosure material | Detuning causes both range and emissions problems |
| Power | Certified external adapter or limited power source; battery protection | Simplifies 62368-1 and avoids a separate adapter evaluation |
| EMC | Cable filtering, clock spreading, return paths, ESD entry points | Emissions and ESD failures are cheapest to prevent in layout |
| Security | Secure boot, unique credentials, signed OTA, protected keys, debug lock | Required for EN 18031 and the CRA; hard to retrofit |
| Software supply chain | SBOM tooling, dependency and CVE tracking | CRA documentation and vulnerability handling |
| Charging (EU) | USB-C receptacle and USB PD behaviour where required | Common charger rules for covered device categories |
| Battery (EU) | Removable/replaceable design or a documented exemption | Batteries Regulation Article 11 from 18 February 2027 |
| Labelling | FCC ID, CE, WEEE and battery marks; e-labelling options | Space on small products runs out quickly |
Typical timeline and cost
| Activity | Typical time | Planning cost |
|---|---|---|
| Pre-compliance EMC/radio scans | 1–2 weeks | Usually part of DVT engineering |
| FCC Part 15C with pre-certified module + Part 15B | 1–3 weeks testing + 1–2 weeks TCB | $3,000–$8,000 |
| CE under RED (safety, EMC, radio) | 2–4 weeks | $2,500–$7,000 |
| EN 18031 assessment and documentation | 2–6 weeks, overlapping | Mainly engineering effort; notified body extra if a restriction applies |
| IEC/UL 62368-1 safety evaluation | 3–6 weeks | $5,000–$15,000 |
| Re-test after a failure | 2–6 weeks | $2,000–$10,000 per failure |
Common pitfalls
- Treating cybersecurity as a documentation exercise after the hardware is frozen — secure boot and key storage are hardware decisions.
- Assuming a certified module makes the whole product compliant.
- Changing the antenna or enclosure after certification without checking whether a permissive change or re-test is needed.
- Shipping with a debug UART or unlocked SWD port.
- No owner for vulnerability reports once the CRA reporting duty applies.
- Planning EU launch of a sealed-battery product without checking the Batteries Regulation removability rules.
How Rapid Circuitry helps
We design connected products with certification and security built into the architecture — module selection, antenna and layout, secure boot and OTA, SBOM tooling — and run pre-compliance before the paid lab session. Formal testing and certification are carried out by accredited labs, notified bodies and TCBs; we prepare the design, technical documentation and samples. See our compliance testing, RF design, firmware development and IoT solutions pages, and the white paper on IoT security best practices.
Frequently asked questions
What do I need to comply with the EU Cyber Resilience Act for a connected device shipping in 2027?
Until 10 December 2027, a radio device placed on the EU market must meet the cybersecurity requirements of the Radio Equipment Directive’s delegated regulation (EU) 2022/30, usually shown with EN 18031. From 11 December 2027 the Cyber Resilience Act (Regulation (EU) 2024/2847) applies in full: the product must meet its essential cybersecurity requirements, go through the conformity assessment for its product class, carry CE marking on that basis, and be supported with security updates for a declared support period. Separately, the CRA’s obligation to report actively exploited vulnerabilities and severe incidents already applies from 11 September 2026, including to products already on the market.
Does EN 18031 apply to my Bluetooth Low Energy device?
It depends on what the device does, not on the radio technology. The RED delegated regulation covers radio equipment that can communicate over the internet directly or via another device, certain radio equipment that processes personal, traffic or location data (including toys, childcare equipment and wearables), and radio equipment that enables transfers of money or virtual currency. A BLE wearable that syncs personal data to a phone app is typically in scope; a BLE device with no data processing and no path to the internet may not be. Document the scoping decision in your technical file.
Can I avoid FCC testing by using a pre-certified wireless module?
A module with an FCC modular grant lets you avoid re-certifying the transmitter, provided you follow the grant’s conditions, such as using an approved antenna and following the integration instructions. The host product still needs Part 15 Subpart B verification or Supplier’s Declaration of Conformity for unintentional emissions, must carry a label such as ‘Contains FCC ID’, and may need additional evaluation if it co-locates several transmitters or changes the RF exposure conditions.
Is CE marking self-declared?
Often, yes. Under the Radio Equipment Directive a manufacturer can use internal production control (Module A) if it applies harmonised standards in full for all essential requirements, then signs an EU declaration of conformity and affixes the CE mark. A notified body is required when harmonised standards are not applied or applied only in part — for example where an EN 18031 restriction removes the presumption of conformity for your design.
What is the difference between RED cybersecurity (EN 18031) and the Cyber Resilience Act?
The RED delegated regulation applies only to radio equipment and covers network protection, personal data and fraud from 1 August 2025. The Cyber Resilience Act applies to almost all products with digital elements, wired or wireless, and adds lifecycle obligations: vulnerability handling, security updates for a support period, a software bill of materials in the technical documentation, and incident reporting. The European Commission adopted a regulation on 16 February 2026 repealing the RED delegated regulation from 11 December 2027, when the CRA fully applies.
Do I need UL certification to sell electronics in the US?
For most consumer electronics there is no general federal requirement for a UL mark, but FCC authorization is mandatory for radio and digital devices. In practice many retailers, online marketplaces, insurers and workplace buyers require a listing from a Nationally Recognized Testing Laboratory to a safety standard such as UL 62368-1, and external power supplies and batteries attract their own requirements. Plan for a safety evaluation to UL/IEC 62368-1 unless you are certain your channel does not require it.
How long does FCC and CE certification take for a connected device?
With a pre-certified radio module and a design that passes pre-compliance, formal testing typically takes 1–3 weeks per market and an FCC grant through a Telecommunication Certification Body a further one to two weeks. Allow 6–10 weeks end to end for FCC, CE and a 62368-1 safety report, and more if the product fails and needs a fix and re-test.
Sources
- EUR-Lex — Radio Equipment Directive 2014/53/EU — consolidated legal text
- EUR-Lex — Delegated Regulation (EU) 2022/30 (RED cybersecurity) — applies from 1 August 2025
- EUR-Lex — Implementing Decision (EU) 2025/138 (EN 18031 series) — published 28 January 2025, with restrictions
- European Commission — Delegated Regulation of 16.2.2026 repealing (EU) 2022/30 — repeal effective 11 December 2027
- EUR-Lex — Cyber Resilience Act, Regulation (EU) 2024/2847 — in force 10 December 2024
- European Commission — Cyber Resilience Act — reporting from 11 September 2026; main obligations from 11 December 2027
- European Commission — CRA reporting obligations — checked September 2026
- European Commission — The EU common charger — USB-C from 28 December 2024; laptops from 28 April 2026
- EUR-Lex — Batteries Regulation (EU) 2023/1542 — Article 11 removability from 18 February 2027
- FCC — Equipment authorization — certification and SDoC procedures (checked September 2026)
- FCC — Covered List — equipment not eligible for authorization (checked September 2026)
- IEC — IEC 62368-1:2023 — audio/video, ICT equipment safety, edition 4