EUREP

EU compliance for wireless devices

Equipment that sends or receives radio signals needs CE marking under the Radio Equipment Directive, which also covers electrical safety and EMC. Internet-connected devices must meet its cybersecurity requirements as well, and the Cyber Resilience Act applies in full from 11 December 2027.

Wireless camera on the turntable of an anechoic test chamber, a measurement antenna beside it
  • Radio Equipment DirectiveDirective 2014/53/EU
  • RED cybersecurityDelegated Regulation (EU) 2022/30
  • Cyber Resilience ActRegulation (EU) 2024/2847Applies from 11 December 2027
  • Market Surveillance RegulationRegulation (EU) 2019/1020
  • General Product Safety RegulationRegulation (EU) 2023/988
  • RoHS DirectiveDirective 2011/65/EU
  • WEEE DirectiveDirective 2012/19/EU
  • Common Charger DirectiveDirective (EU) 2022/2380

Three key facts on wireless devices

  • 2025

    Cybersecurity applies

    Since 1 August 2025, internet-connected radio equipment must meet the cybersecurity requirements of Delegated Regulation (EU) 2022/30.

  • 24 h

    Early warning

    Since 11 September 2026, actively exploited vulnerabilities are reported within 24 hours under the Cyber Resilience Act.

  • EN 18031

    Standards with limits

    Where a restriction of the standards applies, for example if users may skip setting a password, a notified body assesses the product.

Who does what

Radio equipment needs a business in the EU that holds the documents (Art. 4 of Regulation (EU) 2019/1020). Under the Cyber Resilience Act an authorized representative is optional.

You, the manufacturer

  • Design, radio tests and cybersecurity assessment
  • Technical file, EN 18031 evidence and declaration of conformity
  • Vulnerability handling and reporting under the Cyber Resilience Act
  • CE marking, labels and instructions

Written mandate

Representa, your EU Authorized Representative

  • Keeps declaration and technical file available for 10 years
  • Answers requests from market surveillance authorities
  • Passes on information about risks and corrective action
  • Our name and address on product, packaging or documents

Deadlines ahead

The next dates from the rules on this page.

  1. Reporting of actively exploited vulnerabilities and severe incidents

    Cyber Resilience Act

  2. 2 October 2026

  3. All Cyber Resilience Act requirements apply

    Cyber Resilience Act

Free compliance guide: 5 steps to enter the EU market

Download our free checklist and learn what you need before selling in Europe.

  1. 01Classification
  2. 02Documentation
  3. 03Representative
  4. 04Labeling
  5. 05Ongoing compliance

Wireless devices: frequently asked questions

Does EN 18031 apply to my Bluetooth device?

Only if the device itself exchanges data with the internet, directly or through another device such as a phone; plain Bluetooth headphones usually do not. Radio toys, childcare devices and wearables that process personal data are covered even without internet. The requirements have applied since 1 August 2025.

When do I need a notified body under RED?

For the radio and cybersecurity requirements: when you do not apply the harmonised standards in full, or a standard is cited with a restriction that affects your product. EN 18031 gives no presumption of conformity, for example, if users can choose not to set a password.

When does the Cyber Resilience Act apply?

Reporting of actively exploited vulnerabilities and severe incidents has applied since 11 September 2026. The other obligations of manufacturers apply from 11 December 2027, when the RED cybersecurity rules are repealed (Delegated Regulation (EU) 2026/339).

Is an authorized representative mandatory under the Cyber Resilience Act?

No, the Act makes it optional. Radio equipment still needs a business in the EU under Article 4 of Regulation (EU) 2019/1020, and an authorized representative is one way to provide it.

Does the UK accept CE marking for wireless devices?

Yes. Great Britain accepts CE marking under the Radio Equipment Directive. Connectable consumer products sold there must also meet the UK security rules for connectable products, in force since 29 April 2024.

Insights on this topic

Why companies choose Representa GmbH

  • Representa secured our EU Authorized Representative appointment within 48 hours, saving our shipment from costly delay.

    U.S. electronic device manufacturerEU Authorized Representative
  • They turned the CE Marking process into clear, actionable steps, helping us meet our launch timeline and pass compliance the first time.

    Canadian consumer electronics companyCE marking
  • Thanks to Representa, our products became fully GPSR-compliant well before the deadline, ensuring uninterrupted marketplace sales.

    Asian consumer and healthcare exporterGPSR Responsible Person
  • Our beauty cosmetics line faced labeling issues, but Representa's quick review and precise updates got us approved without delay.

    Global beauty, fashion and cosmetics brandCompliance consulting
  • The onboarding was fast and transparent. Representa made EU compliance simple and gave us confidence to expand across Europe.

    Canadian industrial equipment supplier
  • We were unsure how to manage new GPSR rules. Representa guided us step by step, keeping us fully compliant and avoiding delays.

    U.S. consumer goods manufacturerGPSR Responsible Person

Is your device ready for EN 18031?

Send us the product description and its connectivity. We check which rules apply and the role we can take for you.

Get in touch with our team of experts

Tell us what you manufacture and where you want to sell. We identify the requirements for EU and UK market access and come back to you with the next steps.

* Required