Radio Equipment Directive (RED) vs Cyber Resilience Act
Understand the overlap, differences, and compliance synergy between Radio Equipment Directive (RED) and the EU Cyber Resilience Act (CRA).
Core Definition
While Radio Equipment Directive (RED) focuses heavily on device regulation principles, the Cyber Resilience Act specifically targets the cybersecurity of products with digital elements. Compliance with Radio Equipment Directive (RED) provides a strong foundation, but does not completely satisfy CRA requirements. You will still need to ensure CRA-specific mandates like SBOM generation, secure by default configurations, and 24-hour vulnerability reporting to ENISA.
Key Compliance Steps for Radio Equipment Directive (RED)
- Map Existing Controls: Identify which Radio Equipment Directive (RED) controls map directly to CRA Annex I requirements (e.g., risk assessments and access control).
- Identify CRA Gaps: The CRA has strict product-centric requirements (like 5-year security updates and SBOMs) that Radio Equipment Directive (RED) might not explicitly mandate.
- Combine Documentation: Leverage your Radio Equipment Directive (RED) evidence as part of the CRA Technical Documentation package to ease compliance efforts.
How This Plays Out in Practice
RED's Article 3(3)(d)-(f) delegated act already requires cybersecurity provisions for radio equipment, and CRA was designed not to duplicate that assessment for the same product.
What to Watch For
RED only covers radio equipment specifically; software-only products or non-radio hardware fall outside RED but squarely inside CRA.
Assess Your CRA Readiness
Evaluate your product's Cyber Resilience Act readiness using our interactive tool. Find exactly which of the 22 security requirements apply directly to Radio Equipment Directive (RED).