CE marking is the manufacturer’s declaration that the product meets the EU legislation applicable to it. It is not a single certificate issued for every device by a laboratory. Identify the finished product, intended use, interfaces and responsible manufacturer before selecting tests.
Identify applicable legislation
For radio equipment, the RED addresses safety/health, electromagnetic compatibility and efficient spectrum use, with additional requirements for specified categories. Non-radio electronics may fall under other legislation, including EMC, electrical safety or sector-specific rules. RoHS and other applicable obligations must also be considered. Do not apply a single standard set to every electronic product without checking scope.
Select the assessment route
Article 17 RED distinguishes routes for different essential requirements. Internal production control can cover Article 3(1). For Articles 3(2) and 3(3), the ability to use that route depends on the applicable harmonised standards being applied as required. Where they are not applied, not fully applied or do not exist, use the prescribed EU-type examination plus conformity-to-type or full-quality-assurance route.
The manufacturer needs competent testing and sufficient evidence. A notified body is required when the selected legal route calls for it; an accredited laboratory is not universally mandated for every measurement in every internal-control assessment. Choose lab competence, accreditation scope and independent review according to the test and assessment needs.
RED cybersecurity and EN 18031
Activated cybersecurity requirements apply from 1 August 2025 to the categories in Delegated Regulation 2022/30. Parts EN 18031-1, -2 and -3 address different applicable requirements. Their Official Journal citations contain restrictions, so citing the standard is not enough to claim unrestricted presumption of conformity.
Applicability is assessed for units placed on the market. A design approved before August 2025 does not automatically exempt newly placed units from requirements now applicable to that product category. Check transition provisions and product configuration.
Reuse component evidence carefully
A radio module’s reports or declaration can support covered characteristics in the tested configuration. The finished product still needs assessment of integration, antenna, enclosure, power, interfaces and software behaviour. Keep traceability between the module evidence, integration constraints and the final build. A component’s CE marking or security certificate is not the final product’s conformity assessment.
Prepare the technical file and release controls
Maintain the product description, drawings, BOM, applicable requirements, risk assessment, standards and test results, software/firmware identification, instructions and assessment documents. Prepare and sign the EU declaration of conformity for the applicable legislation. Ensure production units match the evaluated configuration.
Pre-compliance measurements can reduce late redesign risk, but no fixed test price or “80% of failures found” figure is reliable without scope and data. Obtain laboratory quotations against the actual product, configurations and tests.
CRA and AI requirements
For products within CRA scope, prepare cybersecurity and vulnerability-handling evidence. Article 14 reporting has applied since 11 September 2026; the main requirements apply from 11 December 2027. A routine security update is not automatically a substantial modification: assess the change under the regulation’s definition.
AI obligations depend on use and role, not merely on including an AI accelerator. Consult the current Commission timeline and category-specific rules. Local inference does not replace GDPR obligations when personal data are processed.
Inovasense can coordinate the compliance matrix, technical documentation and laboratory work. EN 18031 evidence · CRA checklist · Discuss your product
Frequently asked questions
Does every CE-marked device need a laboratory certificate?
No. The legal conformity route determines the required assessment. Manufacturers need adequate evidence, and a notified body where the route requires it; CE marking is not one universal lab certificate.
Does a CE-marked radio module cover the finished device?
No. It can provide evidence within its tested scope, but the manufacturer must assess the final integration and all applicable requirements.
Are products designed before August 2025 automatically exempt from RED cybersecurity?
No. Check the requirements and transition provisions applicable when new units are placed on the market; an older design date alone is not an exemption.
Does every security update trigger a new CRA assessment?
No. A routine patch is not automatically a substantial modification. Assess whether the change meets the regulation’s definition and whether the conformity evidence remains valid.
Primary sources
Technical and regulatory references checked on 1 October 2026.
Related guides inEU Compliance & CE Marking
Explore all →EU CRA Hardware Compliance Checklist
A risk-based CRA checklist for hardware: scope, product category, security requirements, SBOM, support period, reporting and conformity evidence.
CRA Vulnerability Reporting: Step-by-Step Guide
CRA Article 14 reporting in force since 11 September 2026: scope, 24/72-hour awareness deadlines, final reports, SRP and operational preparation.
EN 18031 Compliance: What "Self-Assessment" Actually Means for Connected Hardware
What EN 18031 self-assessment actually requires under Module A — and where the documented compliance gaps most often appear for connected hardware.
RED Delegated Act & EN 18031: Hardware Requirements
How the RED Delegated Act and EN 18031 define mandatory cybersecurity for radio equipment from August 2025 — with gaps that cannot be fixed in firmware.
EU Hardware Legislation 2026: Complete Guide
Which EU rules apply to your hardware? Distinguish CRA, RED, AI Act, ESPR and NIS2 scope, application dates and product-specific obligations.