Skip to content
Whitepaper

Understanding the cybersecurity requirements for RED, PSTI and CRA

Product cybersecurity is now mandatory for market access. This whitepaper from Element experts Michael Derby and Alex Toohie sets out which of the RED, PSTI, and CRA applies to your product, whether you can self-declare or need a Notified Body, and how to design compliance in from the start.

Download the full whitepaper below.

 

How RED, PSTI and CRA fit together

Three laws now sit over product cybersecurity, and each one has a different scope, so your first job is to work out which of them apply to you. The Radio Equipment Directive applies to radio equipment. The UK PSTI regime applies to consumer-connectable products in the UK market. The EU Cyber Resilience Act applies to almost any product with digital elements that connects to a device or network.

A single product often falls under more than one. A connected consumer device sold in Britain and the EU can face PSTI in Great Britain and the RED in Europe simultaneously, with the CRA close behind. Working this out early keeps you from discovering a Notified Body requirement late, which can force a redesign or delay a launch. If you make IoT and connected products, map your obligations market by market before you lock the design.

 

The Radio Equipment Directive cybersecurity requirements

Article 3.3 of the RED has always included a set of essential requirements that the European Commission can activate for specific product categories. Delegated Regulation (EU) 2022/30 activated three of them for cybersecurity purposes, and since 1 August 2025, they have applied as mandatory requirements to affected radio equipment.

Article 3.3(d) asks internet-connected radio equipment to protect the network from harm, so a weak device cannot become an entry point for attackers or get pulled into a botnet. Article 3.3(e) asks equipment that processes personal, traffic or location data to protect that data and the user's privacy, with extra weight where the data concerns children, or where the device is a toy, is worn or carried, or connects to the internet. Article 3.3(f) asks internet-connected equipment that handles money or virtual currency to protect against fraud.

"Internet-connected" here means the device can communicate over the internet itself, running the protocols needed to exchange data with it. The link does not have to be direct. A device that connects to the internet via other equipment remains in scope. Because these rules are in force and market surveillance authorities are enforcing them, products already on sale have to meet them, not only new launches. Market surveillance authorities can act against noncompliant products, ranging from restricting sales to ordering a withdrawal or recall, so the cost of failing to meet the requirements is not only reputational.

Our article on cybersecurity and the RED Article 3.3 essential requirements goes deeper on each requirement.

In practice, the RED cybersecurity requirements pull in a wide range of connected products. Mobile phones, tablets and laptops, smartwatches and fitness trackers, wireless toys and baby monitors, connected smoke and fire alarms, in-vehicle infotainment, and industrial sensors can all fall in scope, depending on how they connect and what data they handle. Radio products that do not connect to the internet, such as a DAB broadcast receiver or a radar unit, sit outside Articles 3.3(d), (e) and (f), and equipment made solely for military use is excluded.

 

The UK PSTI regime

The Product Security and Telecommunications Infrastructure regime was the first law anywhere to set specific cybersecurity requirements for a broad range of consumer products, and it has applied to products placed on the UK market since 29 April 2024. It covers consumer products that connect to the internet directly and those that connect through other devices.

PSTI sets one core technical requirement. Passwords have to be unique to each device or set by the user, never a shared factory default. Alongside that, you tell customers how to report security issues and how quickly they can expect a response; you publish the minimum period for which you will provide security updates and do not shorten it later; and you provide a signed statement of compliance with the product. PSTI points to ETSI EN 303 645 for its technical baseline. That standard and the test specification TS 103 701 that accompanies it are both free to download.

 

The EU Cyber Resilience Act

The Cyber Resilience Act extends beyond the RED. It applies to almost any product with digital elements that has a direct or indirect data connection to another device or network, with a short list of exceptions. It entered into force in 2024 and applies in two stages. From 11 September 2026 you have to report any actively exploited vulnerability and any severe security incident, telling ENISA and the relevant national CSIRT and giving affected users the steps they can take to limit the impact. The rest of the CRA applies in full from 11 December 2027. Element's guide to the Article 14 reporting obligations sets out the 24-hour, 72-hour and 14-day timeline in detail.

The CRA sets tighter conformity routes for the products it considers important or critical, as listed in Annexes III and IV. It also carries real penalties, up to €15 million or 2.5% of worldwide annual turnover for breaches of its core obligations. In July 2026, the European Commission published more than 80 pages of guidance on how to apply the regulation, and ENISA is still building the single reporting platform on which the reporting duties rely, so the details here are worth watching as the deadline approaches.

 

Conformity assessment and Notified Bodies

For most RED requirements, you can declare conformity yourself through Internal Production Control. That self-declaration route stays open only if you fully apply harmonized standards cited in the Official Journal. The cybersecurity standards for the RED, the EN 18031 series, map to the three articles: EN 18031-1 covers network protection under Article 3.3(d), EN 18031-2 covers data and privacy under 3.3(e), and EN 18031-3 covers fraud under 3.3(f). The European Commission harmonized them, with restrictions, through Implementing Decision (EU) 2025/138 on 28 January 2025. If your product falls inside one of those restrictions, for example where a user is allowed not to set a password, or where a specific secure-update clause applies, the standard no longer gives you a presumption of conformity, and you can no longer self-declare. You then have to use a route that involves a Notified Body, either EU-Type Examination followed by Conformity to Type, or Full Quality Assurance. This is why product detail matters so much. A single feature can decide whether you need a Notified Body.

The Commission has also warned manufacturers to treat "voluntary" certificates with care. A certificate that is not an official EU-Type Examination Certificate carries no weight with market surveillance authorities, and can give a false impression that a product is compliant when it is not.

 

What a cybersecurity assessment involves

A product cybersecurity assessment is mostly a documentation exercise, with less hands-on testing. You provide documents that describe the security features your product implements, a test lab reviews them, and the two of you work through corrective actions until the documentation covers every relevant clause. EN 303 645 asks for an Implementation Conformance Statement and Implementation Extra Information for Testing. The EN 18031 standards ask for equivalent supporting evidence and structured decision trees instead.

Because every EN 18031 decision tree starts from your product's asset list, our whitepaper on testing to EN 18031 covers how to build that list correctly.

The testing that follows is grey-box testing, which sits between full knowledge of the product and none. You give the tester access to certain functions, update mechanisms, and cryptography so they can verify that the protections you describe are present and working. A functional assessment confirms that each claimed protection operates as stated, for example, that data on an external interface is encrypted rather than sent in plain text, or that a PIN pad locks after repeated incorrect entries. A completeness assessment confirms that nothing has been left out by using inspections and network scanning to check for interfaces or features not mentioned in the documentation.

No standard here requires penetration testing, and no law forces you to use a third-party lab, though most manufacturers do, for the same reasons they use one for EMC. Element conducts this testing as an ISO/IEC 17025 accredited laboratory.

 

How to approach compliance

A practical path runs in a set order. Start with a cybersecurity risk assessment, since it decides which requirements apply and shapes the rest of the work. Choose your standard next, usually the EN 18031 series, and check whether any of its restrictions catch your product. Build the technical documentation as you go, rather than at the end. Test early, so a gap does not surface days before launch. Then, if a restriction removes your route to self-declaration, bring in a Notified Body for EU-Type Examination or Full Quality Assurance.

 

References

  1. Commission Delegated Regulation (EU) 2022/30, applying RED Articles 3(3)(d), (e) and (f). EUR-Lex.
  2. Regulation (EU) 2024/2847, the Cyber Resilience Act. EUR-Lex.
  3. Cyber Resilience Act reporting obligations, European Commission. digital-strategy.ec.europa.eu.
  4. Directive 2014/53/EU, the Radio Equipment Directive.
  5. ETSI EN 303 645 and ETSI TS 103 701, cyber security for consumer IoT. Freely available from ETSI.
  6. EN 18031-1, EN 18031-2 and EN 18031-3:2024, harmonized with restrictions for RED Articles 3.3(d), (e) and (f).
  7. Product Security and Telecommunications Infrastructure Act 2022 and the PSTI Regulations 2023. legislation.gov.uk.
  8. Commission Implementing Decision (EU) 2025/138, harmonizing EN 18031-1, -2 and -3 with restrictions, 28 January 2025.

 

Why download this whitepaper?

  • Expert analysis of the RED, PSTI and CRA cybersecurity requirements in one place.
  • A clear view of which law applies to which product, and where a Notified Body is required.
  • A practical description of what a cybersecurity assessment involves.

 

Download today to read more about:

  • Introduction to product cybersecurity.
  • Cybersecurity legislation and how the three laws fit together.
  • The UK PSTI regime.
  • The EU Radio Equipment Directive and Articles 3.3(d), (e) and (f).
  • The EU Cyber Resilience Act.
  • Other standards.
  • What a cybersecurity assessment involves.
  • How Element can help.  

 

What this means for your compliance planning

Three points carry across all three laws. First, work out early which of them apply to your product, because the answer sets your timeline and decides whether a Notified Body is involved. Second, treat product cybersecurity as part of design and documentation from the start, since both the RED risk assessment and the CRA expect it to run through the whole development process rather than sit as a final check. Third, keep watching the detail, because the harmonized standards, the Commission guidance and the CRA reporting platform are all still moving.

Element supports this work end-to-end, from advisory and gap analysis through to testing and certification. As an ISO/IEC 17025 accredited test lab and an ISO/IEC 17065 accredited certification body and Notified Body under the RED, Element assesses products against EN 303 645 and the EN 18031 series, reviews declarations of conformity and statements of compliance, and issues EU-Type Examination Certificates where a Notified Body route applies. For Cyber Resilience Act compliance testing or RED cybersecurity testing, our teams can set out the route for your product.

For the full analysis, including the decision tree that maps each product type to its obligations, download the whitepaper below.

If you integrate radio modules, the Radio Module Integration Guide covers how a module's own approvals affect the compliance of your finished product.

 

Download the full whitepaper as a PDF, to read offline or share with your team.  Download. 

 

Frequently asked questions

Do products already on the market need to comply?

Yes. The RED cybersecurity requirements and the CRA reporting duties both apply to products on the market, not only to new launches. If you cannot show that an existing product meets the RED requirements, it may need retesting before you can keep selling it in the EU.

 

Is EN 18031 mandatory?

No standard is mandatory in itself. EN 18031 is the harmonized route that gives you a presumption of conformity with the RED cybersecurity articles. You can meet the requirements another way, but the harmonized standard is usually the most direct path, as long as none of its restrictions applies to your product.

 

Does the CRA replace the RED?

The two run side by side for now. Delegated Regulation (EU) 2022/30, which sets out the RED cybersecurity requirements, is due to be repealed with effect from 11 December 2027, when the CRA applies in full, so that a single regime covers product cybersecurity rather than two regimes.

 

What are the penalties for missing the CRA reporting deadline?

The reporting duties start on 11 September 2026. Breaches of the CRA's core obligations can attract fines of up to €15 million or 2.5% of worldwide annual turnover, so the timeline is worth building into your vulnerability-handling process now.  

Related Services

IoT Testing Services and IoT Certification

Internet of Things (IoT) Testing and Certification

Element's IoT testing services and certification ensure compliance, accelerate market readiness, and provide global IoT network access. Learn More.

Radio

RED Directive Testing for CE Marking

Element's Radio Equipment Directive (RED) services provide testing, certification, and expert guidance to help manufacturers meet EU compliance requirements and secure CE marking for wireless products.

Engineer testing a connected device against Cyber Resilience Act requirements

Cyber Resilience Act Compliance Testing

Get your connected products ready for the EU Cyber Resilience Act. Element tests against EN 18031 and supports your path to CRA compliance.