Heavy weight! The EU RED cybersecurity authorization regulation will be abolished, and the Cyberresilience Regulation (CRA) will be enforced by 2027
Time:
2026-03-11
On December 11, 2027, the EU's Network Resilience Regulation (CRA) will be fully enforced, and the EU's RED Cybersecurity Authorization Regulation (EU) 2022/30 will be officially abolished. At that time, all "products with digital elements" will be uniformly included in CRA supervision, and devices with digital elements that do not meet CRA requirements will be prohibited from being sold in the EU market.
Recently, the European Commission has adopted a new authorization regulation draft, which proposes that the RED Cybersecurity Authorization Regulation (EU) 2022/30 will be officially abolished on December 11, 2027. This measure aims to avoid duplicate requirements in EU wireless device network security regulation and unify relevant requirements into CRA regulation.
Starting from December 11, 2027, the EU's Cyberresilience Regulation (CRA) will be fully enforced. CRA covers all "products with digital elements" - from smart cameras, routers to software components, with a much larger scope than specific wireless devices under RED. The basic network security requirements specified in CRA Annex I have fully covered the contents of Article 3.3 (d), (e), and (f) of the RED Directive, and are more detailed.

Current RED Network Security Requirements
The current Radio Equipment Directive (RED, 2014/53/EU) of the European Union is the fundamental regulation for market access of wireless equipment (such as Wi Fi devices, Bluetooth devices, mobile phones, IoT devices, etc.). And in Article 3 (3) (d), (e), and (f) of RED, requirements related to network security are proposed, including: preventing devices from causing damage to the network, protecting personal data and privacy, and preventing fraudulent behavior.
To address the potential network security risks of IoT devices, the European Union passed the Authorization Regulation (EU) 2022/30 in 2022, which stipulates that from August 1, 2025, wireless devices under the RED directive must meet the above network security requirements before they can be put on the market. This is seen as an important step taken by the EU in the field of IoT security.
EU Network Resilience Regulation CRA
On October 10, 2024, the European Union passed the Network Resilience Regulation (CRA, (EU) 2024/2847) to enhance the network security of connected devices. This regulation was published in the Official Journal of the European Union on November 20, 2024, came into effect in December 2024, and will be enforced on December 11, 2027.

This regulation requires all hardware and software products sold within the European Union that contain digital elements to comply with mandatory security requirements, ensuring that hardware and software products have fewer vulnerabilities when launched, and requiring manufacturers to take security issues seriously throughout the entire product lifecycle.
Key points:
1. Widely applicable:
far beyond RED, CRA applies to all products with digital elements that can be directly or indirectly connected to devices or networks, including hardware (such as smartphones, routers, smart appliances), software (such as operating systems, applications), and their remote data processing solutions. Except for products with specific industry regulations such as medical equipment, aviation, and automobiles.
2. Dual core obligations:
Product security attributes: The product must meet basic network security requirements during the design, development, and production stages, such as security default configuration, vulnerability protection, data protection, etc.
Vulnerability management process: Manufacturers must establish and comply with vulnerability handling processes within the product's "support cycle", including timely release of security updates, provision of vulnerability disclosure policies, etc.
3. Product Classification and Compliance Path: Based on the criticality of the product, CRA categorizes it into two types:
Important products (Annex III): such as operating systems, routers, smart home devices, firewalls, etc. This type of product requires stricter compliance assessment.
Key products (Annex IV): such as hardware security modules, smart meter gateways, etc. Such products may be required to be certified through the EU cybersecurity certification program in the future.
4. Manufacturer's key responsibilities:
Support period: The security support period of the product must be clearly defined and publicly disclosed, usually not less than 5 years.
Security updates: Free security updates are provided during the support period, and automatic updates are enabled by default (users can turn them off).
Event report: When a vulnerability that has been actively exploited or a serious incident that seriously affects product security is discovered, it must be reported to the relevant authorities (CSIRT) and the European Union Cybersecurity Agency (ENISA) within 24 hours.
CE mark: Products that meet CRA requirements must bear the CE mark to indicate compliance with EU regulations.
Transitional arrangements
From August 1, 2025 to December 10, 2027: Wireless devices still need to comply with the network security requirements of RED Article 3 (3) (d), (e), and (f). The EU has made it clear that market supervision agencies can still inspect and handle the cybersecurity compliance of these products in accordance with the RED directive. This ensures that there will be no regulatory vacuum during the transition period.
Starting from September 11, 2026, manufacturers must proactively report confirmed product security vulnerabilities and incidents through the EU unified vulnerability reporting platform (CRA early obligation).
Starting from December 11, 2027, the RED Network Security Authorization Regulation (EU) 2022/30 will be officially abolished, and wireless device network security requirements will be fully regulated by CRA. All hardware and software products containing digital elements must comply with CRA regulations.
Compliance recommendations
Starting from December 11, 2027, the EU's Cyberresilience Regulation (CRA) will be fully enforced. Devices with digital elements that do not meet CRA requirements will be prohibited from being sold in the EU market. Special note: RED compliance is not equivalent to CRA compliance, and relevant companies must conduct a gap analysis against the specific requirements of CRA to ensure full compliance with new obligations.
Manufacturer:
Product classification: Determine the risk categories of all products for sale and research under CRA.
Gap analysis: Compare the basic requirements and specific obligations of CRA to evaluate the gap between existing processes and products.
Improve process: Establish or improve the security development lifecycle, vulnerability management policies, and coordinate vulnerability disclosure processes.
Document preparation: Start preparing technical documents, network security risk assessment reports, and EU compliance statements.
Planning Support Cycle: Determine and plan a security support cycle of at least 5 years for each product.
Pay close attention to the coordinated standards, implementation guidelines, and frequently asked questions issued by the European Commission, ENISA, and domestic market regulatory agencies.
Importers and Distributors:
It is necessary to ensure that the products it launches on the market comply with CRA requirements and have CE markings and necessary documentation.
Consequences of Violation:
If there are situations that do not comply with the obligations stipulated in the regulations, depending on the type of infringement and the nature of the economic operator, they will face severe administrative penalties:
Manufacturers who fail to comply with basic safety requirements may be fined up to 15 million euros, or 2.5% of global annual revenue, whichever is higher.
Manufacturers, importers, or distributors who fail to comply with any other obligations under the regulations (such as failure to report vulnerabilities in a timely manner) may be fined up to 10 million euros, or 2% of global annual revenue, whichever is higher.
The EU's repeal of the RED cybersecurity authorization regulation marks a shift from "fragmented designation" to "horizontal uniformity" in cybersecurity legislation. Starting from December 11, 2027, the Network Resilience Regulations will become the security benchmark for all digital products. For enterprises, it is important to understand the requirements of CRA in advance, plan compliance strategies during the transition period, proactively plan and systematically respond, and ensure that products comply with CRA regulatory requirements.
Jiayu Testing can provide customers with EU CRA gap analysis evaluation and testing certification, RED network security testing certification services. If you need to understand the relevant requirements or obtain compliance solutions. Welcome to contact us at 400-9269-886!
Wechat Public
Account
Hotline
Hotline
Follow
The Public
Follow Us
- Back