Radio Equipment Directive(RED) Assessment Framework

Navigate EU RED 3.3 Requirements with the RED Assessment
Framework from eInfochips

Why RED Compliance Matters

The Radio Equipment Directive (RED) – Directive 2014/53/EU establishes a regulatory framework for placing radio equipment on the EU market. It ensures safety, electromagnetic compatibility, and efficient use of the radio spectrum.

Article 3.3 of the RED outlines additional essential requirements for specific categories of radio equipment beyond the core obligations. These include interoperability, access to emergency services, fraud prevention, data protection, and cybersecurity. Under Regulation (EU) 2022/30, certain clauses of Article 3.3: specifically 3.3(d), (e), and (f), will become mandatory from 1st August 2025 to address cybersecurity risks in connected devices.

  • 3.3(d): Ensures network protection – radio equipment must not harm the network or its functioning nor misuse network resources.
  • 3.3(e): Incorporates safeguards to ensure that the personal data and privacy of the user and subscriber are protected.
  • 3.3(f): Includes features to protect against fraud


EN 18031 1/ 2/ 3 (2024) is a newly harmonized standard series under the Radio Equipment Directive to address the cybersecurity requirements introduced by the RED Articles 3.3(d), (e), and (f).

Our Offerings

eInfochips has developed a comprehensive RED 3.3 Assessment Framework that offers a structured approach to compliance. The framework begins with RED 3.3 Applicability Assessment, followed by Product Classification, Requirement mapping, Documentation and concludes with Gap analysis and recommendations report.

Determining RED Applicability

The applicability of Radio Equipment Directive (RED) is determined by evaluating factors such as whether the product is intended for the EU market, uses wireless communication technologies, processes personal data, or enables monetary transactions.

Product Identification and Classification

The framework begins with product identification and classification. Devices are assessed against EN 18031 categories. EN 18031-1 applies to internet-connected radio equipment requiring network protection. EN 18031-2 relates to devices handling personal data such as wearables and toys. EN 18031-3 covers radio equipment enabling monetary transactions or handling monetary value. This step clearly identifies the product category.

Gap Analysis

Once the classification is defined, a detailed gap analysis is performed against RED 3.3 requirements. This includes reviewing Security Architecture, System Security and Network & Cryptography.

  • [ACM] Access control mechanism
  • [AUM] Authentication mechanism
  • [SUM] Secure update mechanism
  • [SSM] Secure storage mechanism
  • [SCM] Secure communication mechanism
  • [LGM] Logging mechanism
  • [DLM] Deletion mechanism
  • [UNM] User notification mechanism
  • [RLM] Resilience mechanism
  • [NMM] Network monitoring mechanism
  • [TCM] Traffic control mechanism
  • [CCK] Confidential cryptographic keys
  • [GEC] General equipment capabilities
  • [CRY] Cryptography

Documentation

Documentation is critical to demonstrate compliance with RED Article 3.3, particularly the new cybersecurity requirements. It typically includes a detailed product architecture overview, security design documentation, and a Software Bill of Materials (SBOM). Additional documentation includes product images, architecture and data flow diagrams, and evidence of applied harmonized standards. Supporting material should cover vulnerability assessments, VAPT (Vulnerability Assessment and Penetration Testing) reports, and a comprehensive risk assessment addressing threats and mitigations. Where applicable, EU-type examination certificates must detail the manufacturer, covered requirements, and test results. Finally, a Declaration of Conformity (DoC) is required to support the CE marking and demonstrate formal compliance with the directive.

Gap Analysis Report

The outcome of RED 3.3 Assessment from eInfochips is a detailed Gap Analysis Report that outlines key observations related to a product’s compliance status. The report provides actionable recommendations to meet RED 3.3 requirements and includes a clearly defined implementation roadmap. Additionally, the eInfochips team can support the execution of these recommendations, assisting with end-to-end compliance implementation.

Why eInfochips?

eInfochips combines expertise in connected product engineering with in-depth regulatory knowledge to deliver a robust RED 3.3 Assessment Framework. From classification through documentation, the framework accelerates compliance, reduces market-entry risks, and strengthens customer trust in EU markets.

To begin your RED compliance journey, contact our experts for a consultation. We will help assess your product’s readiness, identify gaps, and guide you through the necessary steps to meet EU regulatory standards with confidence.

Talk To   Our Experts

Download Report

Download Sample Report

Download Brochure

Start a conversation today

Schedule a 30-minute consultation with our Automotive Solution Experts

Start a conversation today

Schedule a 30-minute consultation with our Battery Management Solutions Expert

Start a conversation today

Schedule a 30-minute consultation with our Industrial & Energy Solutions Experts

Start a conversation today

Schedule a 30-minute consultation with our Automotive Industry Experts

Start a conversation today

Schedule a 30-minute consultation with our experts

Please Fill Below Details and Get Sample Report

Reference Designs

Our Work

Innovate

Transform.

Scale

Partnerships

Quality Partnerships

Company

Products & IPs

Privacy Policy

Our website places cookies on your device to improve your experience and to improve our site. Read more about the cookies we use and how to disable them. Cookies and tracking technologies may be used for marketing purposes.

By clicking “Accept”, you are consenting to placement of cookies on your device and to our use of tracking technologies. Click “Read More” below for more information and instructions on how to disable cookies and tracking technologies. While acceptance of cookies and tracking technologies is voluntary, disabling them may result in the website not working properly, and certain advertisements may be less relevant to you.
We respect your privacy. Read our privacy policy.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.