RED Cybersecurity to CRA: Planning for the 2027 Transition

  News     |      2026-08-31 15:02

The EU has now fixed the handover date between the current Radio Equipment Directive cybersecurity framework and the broader Cyber Resilience Act (CRA). Commission Delegated Regulation (EU) 2026/339 is already in force and will repeal Delegated Regulation (EU) 2022/30 on 11 December 2027, the CRA’s general date of application.

This is a future transition, not an immediate withdrawal of the RED cybersecurity requirements. Radio equipment within the scope of Delegated Regulation 2022/30 and placed on the EU market between 1 August 2025 and 10 December 2027 still needs an appropriate RED scope assessment, conformity route and technical file. The repeal will not prevent market surveillance or controls for products placed on the market during that period.

What the 2026 measure changes

Delegated Regulation 2022/30 activates three RED essential requirements for specified categories or classes of radio equipment: network protection under Article 3(3)(d), personal-data and privacy protection under Article 3(3)(e), and protection from fraud under Article 3(3)(f). Regulation (EU) 2023/2444 moved its application date to 1 August 2025.

Regulation 2026/339 does one focused job: it sets 11 December 2027 as the repeal date for 2022/30. Aligning that date with the CRA’s general application helps prevent the two cybersecurity frameworks from imposing overlapping requirements for the same risk. Businesses should plan for continuity followed by a controlled handover—not treat the new act as permission to pause current RED work.

Start with a product-by-product scope review

The three RED cybersecurity requirements do not automatically apply to every wireless product in the same way. A portfolio review should separate network, data and payment functions:

  • Network protection: internet-connected radio equipment that can communicate over the internet directly or through another device is relevant to Article 3(3)(d).
  • Personal data and privacy: specified equipment capable of processing personal, traffic or location data is relevant to Article 3(3)(e). The scope also addresses qualifying childcare, toy and wearable radio equipment.
  • Fraud protection: internet-connected radio equipment enabling the transfer of money, monetary value or virtual currency is relevant to Article 3(3)(f).

Article 2 of 2022/30 also coordinates the framework with EU medical-device and in-vitro-diagnostic rules, and sets boundaries for some aviation, vehicle and electronic-road-toll equipment. The RED definition of radio equipment, the product’s actual functions and other applicable sector legislation all remain material.

Manage the 2025–2027 timeline as controlled evidence

  1. 1 August 2025: 2022/30 became applicable following the date change made by Regulation 2023/2444.
  2. 19 May 2026: Regulation 2026/339 entered into force. This confirmed the future repeal but did not switch off the current requirements.
  3. 10 December 2027: the final day before repeal. Records for in-scope products placed on the market during the applicable period should remain retrievable for possible controls.
  4. 11 December 2027: 2022/30 is repealed and the CRA generally applies. Whether a product is within the CRA and which obligations apply still depends on its definitions, product scope, economic-operator role and transitional provisions.

The CRA also contains phased milestones before general application, including provisions concerning conformity assessment bodies and vulnerability or incident reporting. The 2027 handover date should therefore sit inside a wider CRA readiness plan, not become the start date for all preparation.

A practical readiness plan for manufacturers and importers

  1. Map the portfolio. Record radio technologies, internet communication paths, account and data features, payment capability, intended use and EU market-placement dates by model.
  2. Document the scope rationale. Keep a reasoned position for each of Articles 3(3)(d), (e) and (f), including any sector-specific coordination or exclusion.
  3. Control technical-file versions. Link risk assessments, test evidence, software versions, update mechanisms, user information and declarations to the correct model and production release.
  4. Build a separate CRA gap list. Preserve the RED evidence created for the 2025–2027 period rather than replacing it with a generic CRA folder.
  5. Align supply-chain roles. Manufacturers, importers, distributors and software suppliers should know who controls each record, change decision and notification path.

How Qianxin can support the preparation

For a defined product, market and written scope, Qianxin can help identify relevant regulations and standards, map testing and technical-documentation preparation needs, review consistency across product and supply-chain information, and coordinate radio-equipment export-compliance activities. Product classification, legal roles, final CRA scope, conformity routes and any authority or notified-body expectations remain subject to the actual project.

This article provides general compliance information only. It is not product-specific legal advice or a final conformity assessment. Testing, reporting, certification and issuing activities depend on the project, the relevant laboratory scope and the written engagement.

Official Sources