The Radio Equipment Directive (RED) – Directive 2014/53/EU establishes a regulatory framework for placing radio equipment on the EU market. It ensures safety, electromagnetic compatibility, and efficient use of the radio spectrum.
Article 3.3 of the RED outlines additional essential requirements for specific categories of radio equipment beyond the core obligations. These include interoperability, access to emergency services, fraud prevention, data protection, and cybersecurity. Under Regulation (EU) 2022/30, certain clauses of Article 3.3: specifically 3.3(d), (e), and (f), will become mandatory from 1st August 2025 to address cybersecurity risks in connected devices.
EN 18031 1/ 2/ 3 (2024) is a newly harmonized standard series under the Radio Equipment Directive to address the cybersecurity requirements introduced by the RED Articles 3.3(d), (e), and (f).
eInfochips has developed a comprehensive RED 3.3 Assessment Framework that offers a structured approach to compliance. The framework begins with RED 3.3 Applicability Assessment, followed by Product Classification, Requirement mapping, Documentation and concludes with Gap analysis and recommendations report.
The applicability of Radio Equipment Directive (RED) is determined by evaluating factors such as whether the product is intended for the EU market, uses wireless communication technologies, processes personal data, or enables monetary transactions.
The framework begins with product identification and classification. Devices are assessed against EN 18031 categories. EN 18031-1 applies to internet-connected radio equipment requiring network protection. EN 18031-2 relates to devices handling personal data such as wearables and toys. EN 18031-3 covers radio equipment enabling monetary transactions or handling monetary value. This step clearly identifies the product category.
Once the classification is defined, a detailed gap analysis is performed against RED 3.3 requirements. This includes reviewing Security Architecture, System Security and Network & Cryptography.
Documentation is critical to demonstrate compliance with RED Article 3.3, particularly the new cybersecurity requirements. It typically includes a detailed product architecture overview, security design documentation, and a Software Bill of Materials (SBOM). Additional documentation includes product images, architecture and data flow diagrams, and evidence of applied harmonized standards. Supporting material should cover vulnerability assessments, VAPT (Vulnerability Assessment and Penetration Testing) reports, and a comprehensive risk assessment addressing threats and mitigations. Where applicable, EU-type examination certificates must detail the manufacturer, covered requirements, and test results. Finally, a Declaration of Conformity (DoC) is required to support the CE marking and demonstrate formal compliance with the directive.
The outcome of RED 3.3 Assessment from eInfochips is a detailed Gap Analysis Report that outlines key observations related to a product’s compliance status. The report provides actionable recommendations to meet RED 3.3 requirements and includes a clearly defined implementation roadmap. Additionally, the eInfochips team can support the execution of these recommendations, assisting with end-to-end compliance implementation.
eInfochips combines expertise in connected product engineering with in-depth regulatory knowledge to deliver a robust RED 3.3 Assessment Framework. From classification through documentation, the framework accelerates compliance, reduces market-entry risks, and strengthens customer trust in EU markets.
To begin your RED compliance journey, contact our experts for a consultation. We will help assess your product’s readiness, identify gaps, and guide you through the necessary steps to meet EU regulatory standards with confidence.
Schedule a 30-minute consultation with our Automotive Solution Experts
Schedule a 30-minute consultation with our Battery Management Solutions Expert
Schedule a 30-minute consultation with our Industrial & Energy Solutions Experts
Schedule a 30-minute consultation with our experts


