September 17, 2025

RED cybersecurity and the Data Act: two EU rules connected-device makers met in 2025

Within six weeks this summer, two pieces of EU legislation began to apply that change how connected devices are designed and sold in Europe. On 1 August 2025 the cybersecurity requirements of the Radio Equipment Directive became mandatory. On 12 September 2025, last Friday, the Data Act started to apply.

Both were adopted years ago, yet many manufacturers, especially those based outside the EU, are only now working out what they mean in practice. Since early 2024 we at EMBIQ have been working with a connected-device manufacturer from outside the EU on its European launch, described in an earlier post, and cybersecurity reached that project long before the legal deadline. Here is what the rules require, what we saw in practice and what comes next.

RED cybersecurity: what changed on 1 August

Commission Delegated Regulation (EU) 2022/30 activated three essential requirements of the Radio Equipment Directive that had existed only on paper. It was due to apply in August 2024; Delegated Regulation (EU) 2023/2444 moved the date to 1 August 2025.

  • Article 3(3)(d): the device must not harm the network or misuse network resources;
  • Article 3(3)(e): it must include safeguards that protect personal data and privacy;
  • Article 3(3)(f): where it enables transfers of money, monetary value or virtual currency, it must support features that protect against fraud.

They cover radio equipment that can communicate over the internet, directly or through another device; the privacy requirement also covers childcare equipment, radio toys and wearables.

The harmonised standards EN 18031-1, -2 and -3, one per requirement, were published by CEN and CENELEC in August 2024 and cited in the Official Journal by Commission Implementing Decision (EU) 2025/138 of 28 January 2025, with restrictions. The most important applies to all three parts: if a product uses the option in clauses 6.2.5.1 and 6.2.5.2 that allows the user not to set or use any password, the standard gives no presumption of conformity. Other restrictions concern parental control for toys and childcare equipment (EN 18031-2) and secure updates (EN 18031-3). Where a restriction applies, or a standard is applied only in part, the manufacturer needs a notified body.

Every unit placed on the EU market from 1 August 2025 must meet these requirements. Units placed earlier are not affected retroactively, but the same model shipped today is.

What we saw in practice

  • Certificates age. The device's EU-type examination certificate under the RED, issued by a notified body in mid-2024, covers health, safety, EMC and radio spectrum. It says nothing about Article 3(3)(d), (e) or (f), because nothing required it at the time. For units placed on the market after 1 August that is no longer the full picture, and CE documentation is exactly what customs asked for at import on one of this summer's shipments.
  • Industry partners get there first. A year before the legal deadline, a vehicle-industry partner sent its own cybersecurity requirements for the device, covering the usual areas: secure boot and updates, key storage, debug interfaces, wireless pairing, penetration testing and vulnerability handling. Each requirement needed a clear position, and the gaps went into a risk assessment. The partner also assesses the supplier organisation, through TISAX or ISO/IEC 27001.
  • Hardware sets the ceiling. Most refusals and reservations had one cause: the microcontroller could not provide the isolation or secure execution environment asked for. Firmware cannot add security hardware the chip lacks; the cheapest moment to meet RED and CRA requirements is when the chip is chosen.

The Data Act: users get access to their device data

Regulation (EU) 2023/2854 entered into force on 11 January 2024 and applies from 12 September 2025. Users of connected products and related services have the right to access the data their use generates and to have it shared with a third party of their choice. The data holder may use readily available non-personal data only under a contract with the user. Two dates matter:

  • 12 September 2025: transparency before the contract. Users must be told what data the product generates, in what format and volume, and how they can access it; for related services, also who uses the data and why.
  • After 12 September 2026: access by design. Connected products and related services placed on the market after that date must make data available to the user by default, easily, securely, free of charge, in a structured, commonly used and machine-readable format, and, where relevant and technically feasible, directly.

Micro and small enterprises are largely exempt, and the Data Act also covers unfair contract terms and switching between cloud providers. For subscription services the terms of service need a review, and the engineering side, from data models, APIs and export formats to third-party authorisation and consent flows alongside the GDPR, belongs in the roadmap now.

What comes next: the Cyber Resilience Act

The Cyber Resilience Act, Regulation (EU) 2024/2847, entered into force on 10 December 2024 and extends cybersecurity requirements to almost all products with digital elements, including software. Rules on notified bodies apply from 11 June 2026. From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents; from 11 December 2027 all obligations apply, including security by design and security updates over the support period. Work done now for the RED is a direct investment in CRA readiness. And since 13 December 2024 the General Product Safety Regulation has required an economic operator established in the EU for every consumer product.

A short checklist

  1. Check your certificates: do they cover Article 3(3)(d), (e) and (f) for units shipped after 1 August 2025?
  2. Document a risk assessment per product; it serves the RED technical file today and CRA documentation tomorrow.
  3. Close the typical gaps: no shared default passwords, encrypted communication, authenticated updates, secure key storage, few exposed services; check the EN 18031 restrictions early.
  4. Inventory product data, publish the pre-contract information and design data access for products launched after 12 September 2026.
  5. Prepare vulnerability handling before September 2026: a contact point, a disclosure policy, a software bill of materials and a fast way to ship fixes.

For connected devices, 2025 is the year EU compliance became a question of software, data and processes, not only radio and safety. Treat the RED, the Data Act and the CRA as one programme and you do the work once. If you are preparing a connected product for these requirements, see our product and technology Europeanization and IoT services or talk to us.

Quote a project! Get advice.

Let’s talk about your project

Drop us a line or book a short intro call — we’ll get back to you with the right people on our side.

Book an intro call (opens in a new tab)
Call us+48 81 561 85 01
LublinEMBIQ Sp. z o.o.al. Kraśnicka 2720-718 Lublin, Poland
GrazEMBIQ GmbHBrückenkopfgasse 1/68020 Graz, Austria
Let’s inve

Let’s investigate your project concept and its current status together.

Expect an

Expect an initial project scope proposal, time and cost estimation from us.

The consul

The consultancy will be protected by the NDA.