Cybersecurity compliance for connected devices: RED now, CRA very soon

Cybersecurity compliance for connected devices: RED now, CRA very soon

August 24, 2026

By Joe Lomako, Cyber Lead, TÜV SÜD UK

Some exciting new stuff is going on in cyber world! Manufacturers of connected products are facing new obligations for demonstrating cybersecurity compliance in Europe. With two regulations coming up back-to-back, manufacturers need to understand the complexities of both, so they can ensure a seamless implementation.

Where we are now? – RED

The Radio Equipment Directive (RED) introduced new cybersecurity requirements for internet-connected radio equipment on 1 August 2025 (through a delegated act) on three points of security:

1) Protecting network integrity
2) Safeguarding personal data
3) Preventing fraud.

Most radio devices (with some exceptions) connecting to the internet – directly or through other equipment – are in scope. The RED also includes toys, wearables and childcare products that process personal data, even when they do not connect.
Three harmonised standards — EN 18031-1,-2 and -3:2024 — were produced by the EU standards organisations to assist in demonstrating compliance.

What’s coming – the CRA

From 11 December 2027, the Cyber Resilience Act (CRA) replaces the cybersecurity requirements of the RED and opens a broader range of products which will be in scope. This includes “products with digital elements” like hardware, software, components, remote data processing and open source, depending on its application. The CRA demands “secure-by-design” across the entire product lifecycle, with security updates and timely vulnerability remediation. The scope of products falls into different categories depending on risk: “default”, “important (Class I and II)” and “critical”. Each of these product types requires different compliance routes, again depending on risk.

An earlier date matters too! From 11 September 2026, there is an obligation on manufacturers to report actively exploited vulnerabilities via a single reporting platform, with accompanying supply information requirements. Should a vulnerability be exploited, manufacturers will have 24 hours to issue a first report, 72 hours to follow up with an interim report, and 14 days/one month to create a final report, depending on severity of the exploit. Penalties for non-compliance can be severe, with up to €15M or 2.5% of total worldwide revenue.

A business problem, not just a technical one

Traditionally, regulatory compliance was seen as a technical problem. The CRA, however, is a requirement for the lifecycle of the product, and has both process (business) and technical (engineering) requirements that must be fulfilled. What used to be the responsibility of a lonely compliance manager now requires input from engineering, quality, legal, finance, and supply chain. Ultimately, the buck stops at the C-level ensuring a top-down level of support.

Start now — delay is the expensive option

There is a lot to do to keep up with both RED and CRA. Companies need to start today if they have not done so already. Every time a new regulation appears many leave it to the last minute, causing panic, avoidable extra cost and increasing the scope for error. So, Eat That Frog and get CRA-ing.

 

[fusion_tb_comments template_order=”” avatar=”square” headings=”show” hide_on_mobile=”small-visibility,medium-visibility,large-visibility” class=”hideme” id=”” heading_size=”2″ heading_color=”” hue=”” saturation=”” lightness=”” alpha=”” border_size=”” border_color=”” padding=”40″ link_hover_color=”” link_color=”” text_color=”” meta_color=”” margin_top=”” margin_right=”” margin_bottom=”” margin_left=”” animation_type=”” animation_direction=”left” animation_color=”” animation_speed=”0.3″ animation_delay=”0″ animation_offset=”” /]

Related Posts