COMPARISON · CRA
CRA vs the RED Delegated Regulation on cybersecurity
For manufacturers of connected radio equipment, understanding which requirement set governs which aspect of the product avoids duplicated conformity work.
LAST REVIEWED
What is different
- Scope: the RED Delegated Regulation applies specifically to radio equipment as defined under the Radio Equipment Directive 2014/53/EU; the CRA applies broadly to products with digital elements, radio or otherwise.
- Legal instrument: the RED cybersecurity requirements are introduced via a delegated act amending essential requirements under an existing directive; the CRA is a standalone Regulation.
- Requirement depth: the RED delegated act sets three targeted essential requirements — network protection, personal data and privacy protection, and fraud protection; the CRA sets a comprehensive set of security-by-design, vulnerability handling and lifecycle requirements.
- Conformity route: RED conformity typically uses harmonised standards and CE marking under the RED framework; the CRA has its own conformity assessment procedures, including self-assessment and, for certain products, third-party assessment.
What overlaps
Both regimes require CE marking based on demonstrated conformity with essential cybersecurity requirements, both expect a technical documentation file, and both are concerned with protecting the product, the network it connects to, and the data it processes. Where a radio product falls under both instruments, the legislation is designed to avoid double assessment: the CRA states that products already meeting equivalent RED cybersecurity requirements are treated as satisfying the corresponding CRA requirements, subject to the exact provisions in force.
In practice this means the underlying engineering evidence — secure development records, vulnerability handling process, risk assessment — can largely be built once and mapped to whichever instrument's essential requirements apply to a given product line.
Which applies to you
- Your product is radio equipment under the RED and does not otherwise fall under CRA transitional exclusions: check which instrument's essential requirements are currently in force for your product category and timeline.
- Your product has digital elements but is not radio equipment (e.g. a wired industrial controller): the CRA applies; the RED delegated act does not.
- Your product is radio equipment with significant embedded software and network functions: build one security engineering file and map it to both sets of essential requirements rather than treating them as separate programmes.
- You are unsure which regime governs a specific requirement for your product: confirm the current transitional provisions, since the interaction between the RED delegated act and the CRA has been the subject of legislative adjustment.
Frequently asked questions
Do I need to comply with both the RED delegated act and the CRA?
If your product is radio equipment with digital elements, the relevant essential requirements are coordinated so that meeting one set can be treated as satisfying the corresponding requirements of the other, avoiding duplicate assessment. The precise mapping depends on which provisions are in force for your product category and should be confirmed for your specific case.
Is the RED delegated act cybersecurity requirement mandatory now?
The RED Delegated Regulation (EU) 2022/30 introduced cybersecurity essential requirements with their own application timeline, agreed before the CRA existed. Manufacturers of radio equipment should confirm current applicability dates alongside the CRA's own phase-in schedule.
Does CE marking under RED cover CRA obligations?
CE marking under the RED addresses the RED's own essential requirements. It does not automatically discharge every CRA obligation, such as vulnerability reporting duties, though technical work supporting RED cybersecurity conformity can generally be reused for CRA conformity assessment.
Which products are 'radio equipment' under the RED?
Radio equipment is broadly defined under Directive 2014/53/EU as any product that intentionally emits or receives radio waves for communication or radiodetermination. This includes most Wi-Fi, Bluetooth and cellular-connected consumer and industrial devices.