September 17, 2025
Within six weeks this summer, two pieces of EU legislation began to apply that change how connected devices are designed and sold in Europe. On 1 August 2025 the cybersecurity requirements of the Radio Equipment Directive became mandatory. On 12 September 2025, last Friday, the Data Act started to apply.
Both were adopted years ago, yet many manufacturers, especially those based outside the EU, are only now working out what they mean in practice. Since early 2024 we at EMBIQ have been working with a connected-device manufacturer from outside the EU on its European launch, described in an earlier post, and cybersecurity reached that project long before the legal deadline. Here is what the rules require, what we saw in practice and what comes next.
Commission Delegated Regulation (EU) 2022/30 activated three essential requirements of the Radio Equipment Directive that had existed only on paper. It was due to apply in August 2024; Delegated Regulation (EU) 2023/2444 moved the date to 1 August 2025.
They cover radio equipment that can communicate over the internet, directly or through another device; the privacy requirement also covers childcare equipment, radio toys and wearables.
The harmonised standards EN 18031-1, -2 and -3, one per requirement, were published by CEN and CENELEC in August 2024 and cited in the Official Journal by Commission Implementing Decision (EU) 2025/138 of 28 January 2025, with restrictions. The most important applies to all three parts: if a product uses the option in clauses 6.2.5.1 and 6.2.5.2 that allows the user not to set or use any password, the standard gives no presumption of conformity. Other restrictions concern parental control for toys and childcare equipment (EN 18031-2) and secure updates (EN 18031-3). Where a restriction applies, or a standard is applied only in part, the manufacturer needs a notified body.
Every unit placed on the EU market from 1 August 2025 must meet these requirements. Units placed earlier are not affected retroactively, but the same model shipped today is.
Regulation (EU) 2023/2854 entered into force on 11 January 2024 and applies from 12 September 2025. Users of connected products and related services have the right to access the data their use generates and to have it shared with a third party of their choice. The data holder may use readily available non-personal data only under a contract with the user. Two dates matter:
Micro and small enterprises are largely exempt, and the Data Act also covers unfair contract terms and switching between cloud providers. For subscription services the terms of service need a review, and the engineering side, from data models, APIs and export formats to third-party authorisation and consent flows alongside the GDPR, belongs in the roadmap now.
The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on 10 December 2024 and extends cybersecurity requirements to almost all products with digital elements, including software. Rules on notified bodies apply from 11 June 2026. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents; from 11 December 2027 all obligations apply, including security by design and security updates over the support period. Work done now for the RED is a direct investment in CRA readiness. And since 13 December 2024 the General Product Safety Regulation has required an economic operator established in the EU for every consumer product.
For connected devices, 2025 is the year EU compliance became a question of software, data and processes, not only radio and safety. Treat the RED, the Data Act and the CRA as one programme and you do the work once. If you are preparing a connected product for these requirements, see our product and technology Europeanization and IoT services or talk to us.
Quote a project! Get advice.
Drop us a line or book a short intro call — we’ll get back to you with the right people on our side.
E-mail usinfo@embiq.comBook an intro call (opens in a new tab)Let’s investigate your project concept and its current status together.
Expect an initial project scope proposal, time and cost estimation from us.
The consultancy will be protected by the NDA.