Partly. Evidence produced against EN 18031 for network protection, personal data protection and fraud protection maps onto CRA Annex I Part I and belongs in the CRA technical file. The post-market duties in Annex I Part II do not carry forward, because the RED Delegated Regulation never asked for them.
That distinction decides how much of your compliance budget is already spent and how much is still ahead of you. It is also the point where most manufacturers set their expectations too high.
Key takeaways
- Delegated Regulation (EU) 2022/30 made the RED cybersecurity requirements mandatory on 1 August 2025, and the Commission adopted its repeal on 16 February 2026 with effect from 11 December 2027.
- EN 18031 evidence transfers into the CRA technical file as product-property evidence, covering roughly the Annex I Part I half of the essential requirements.
- The vulnerability handling and reporting duties have no RED DA equivalent, and the first of them binds on 11 September 2026, fifteen months before the CRA applies in full.
- A portfolio of 50 products can generate 500 to 1,000 exploitability assessments a year under Article 14, each on a 24-hour clock, before firmware versions are counted.
- Self-assessment under the CRA default class removes the notified body, not the technical file.
What RED DA actually requires
Delegated Regulation (EU) 2022/30 activated three of the essential requirements in Article 3(3) of the Radio Equipment Directive for connected radio equipment. Point (d) covers network protection, point (e) covers protection of personal data and privacy, and point (f) covers protection from fraud. Those requirements became mandatory on 1 August 2025.
The EN 18031 series is the practical route to showing conformity. The Commission harmonised all three parts through Commission Implementing Decision (EU) 2025/138 of 28 January 2025.
| Standard | Requirement it supports | Scope |
|---|---|---|
| EN 18031-1:2024 | Article 3(3)(d), network protection | Internet-connected radio equipment |
| EN 18031-2:2024 | Article 3(3)(e), personal data and privacy | Internet-connected radio equipment, childcare equipment, toys, wearables |
| EN 18031-3:2024 | Article 3(3)(f), fraud protection | Equipment processing virtual money or monetary value |
One detail in that decision is easy to miss and expensive to discover late. The references were published with restrictions. Clauses 6.2.5.1 and 6.2.5.2 of the standards allow a manufacturer to let a user decline to set a password, and presumption of conformity does not extend to that option. A product that relies on it does not get the benefit of the harmonised standard for that clause, and the gap has to be closed another way.
The scope of the assessment is also wider than the phrase "radio testing" suggests. The questions reach hardware, firmware, cloud communication, mobile applications, authentication and update mechanisms.
Why the RED DA is being withdrawn
CRA Annex I already contains every element of the essential requirements in Article 3(3), points (d), (e) and (f) of the Radio Equipment Directive. Leaving both instruments in force would mean two conformity routes over the same ground.
So the Commission adopted a delegated regulation on 16 February 2026 that repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, the date the Cyber Resilience Act applies in full.
Read that as a transition, not a reprieve. Between now and 10 December 2027 the RED cybersecurity requirements still apply to radio equipment in scope. From 11 December 2027 the same product needs a CRA conformity assessment instead.
What carries forward, and what does not
The CRA splits its essential requirements into two parts, and the split is what determines reuse.
| CRA Annex I | Subject | Does RED DA work cover it? |
|---|---|---|
| Part I | Product properties, secure configuration, access control, confidentiality and integrity of data, attack surface, update mechanism | Largely. EN 18031 evidence maps onto most of it |
| Part II | Vulnerability handling across the support period, SBOM, coordinated disclosure policy, security updates, reporting | No. RED DA set no post-market obligation |
Part I is a photograph of the product at the moment it ships. Part II is a process that has to keep running for the whole support period. Test reports demonstrate the first. Only an operating programme demonstrates the second.
The 24-hour clock starts before the rest of the CRA
Article 14 of Regulation (EU) 2024/2847 applies from 11 September 2026. It runs three deadlines from the point of awareness: an early warning within 24 hours, a detailed notification within 72 hours, and a final report within 14 days for an actively exploited vulnerability.
It applies to products already on the market. There is no grace period tied to your next product launch, and no exemption for a device certified under RED DA last year.
The arithmetic that should set your tooling budget
Take 50 products on the market in Europe. Assume 10 to 20 actively exploited vulnerabilities a year land somewhere in the software supply chain those products share. Every one of them has to be assessed against every product.
50 products x 10 to 20 exploited vulnerabilities = 500 to 1,000 assessments per year
Each assessment starts a 24-hour clock. And that figure counts only current firmware. Work at that volume needs automation and a defined process, not goodwill from an engineering team that already has a roadmap.
Primary sources and full article
Read the complete worked guide and source references on CVD Portal: Does RED DA Work Count Toward CRA Compliance?.