Skip to content

RED 3.3: repeal scheduled for 11 December 2027

News · Regulatory evolution

Adopted on 16 February 2026 and published in the Official Journal on 29 April 2026, Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30, the act that switched on articles 3.3(d), 3.3(e) and 3.3(f) of the RED directive. The repeal takes effect on 11 December 2027, the date the Cyber Resilience Act applies in full. The Commission's stated reason is straightforward: avoid two overlapping cybersecurity regimes on the same radio product.

In short:

  • The repeal is dated, not immediate: the RED 3.3 regime stays fully applicable through 10 December 2027.
  • EN 18031-1, EN 18031-2 and EN 18031-3 remain the route to presumption of conformity, still cited with restrictions.
  • No restriction was lifted during 2026.
  • Between September 2026 and December 2027, a connected radio product falls under both frameworks on different grounds.

Delegated Regulation 2026/339 is a short instrument whose effect fits in one sentence: Delegated Regulation (EU) 2022/30 is repealed with effect from 11 December 2027. It enters into force on the twentieth day following publication, but the repeal itself is deferred to that date.

The construction should be read for what it is: an exercise in legal continuity, not a relaxation. The European legislator took the view that cybersecurity requirements for radio equipment are better handled by Regulation (EU) 2024/2847, which is horizontal and not limited to radio, than by a delegated act hanging off the RED directive. Aligning the dates avoids any window without obligations.

This is the point worth repeating, because the announcement of a repeal reads easily as a suspension. The RED 3.3 obligations have applied since 1 August 2025 and continue to apply:

  • Every connected radio device placed on the market must demonstrate compliance with the applicable articles 3.3(d), 3.3(e) and 3.3(f).
  • Presumption of conformity runs through full application of the EN 18031 series.
  • The restrictions attached to the OJEU citation by Implementing Decision (EU) 2025/138 remain in force. If your design lets the user skip creating a password (clauses 6.2.5.1 and 6.2.5.2), or if you rely on the authentication criteria in clause 6.3.2.4 of EN 18031-3, the presumption falls away and a notified body becomes necessary.

Second-edition amendments intended to narrow those restrictions were reported as being drafted, with a citation hoped for in early 2026. As of mid-August 2026, no such citation has appeared.

A guidance document published in February 2026 by the RED administrative cooperation group does offer concrete help: it sets out seven cases for determining whether a product falls within the category of internet-connected radio equipment.

The timetable creates a period where two frameworks coexist, each operating on a different register:

DateWhat applies
Since 1 August 2025RED 3.3(d)(e)(f) requirements, presumption via EN 18031
11 September 2026CRA reporting obligations: actively exploited vulnerabilities and severe incidents
11 December 2027CRA applies in full, CE marking under the regulation, and Regulation 2022/30 is repealed

In practical terms, from 11 September 2026 a manufacturer of connected radio devices must simultaneously maintain a RED 3.3 compliance file and a 24-hour reporting capability under the CRA. These are obligations of different natures: one bears on product design, the other on vulnerability handling after the product is on the market.

  1. Do not pause RED 3.3 work. A design shipping in 2027 will still have to satisfy article 3.3, and a product placed on the market before December 2027 continues to be judged on that basis.
  2. Design once for both frameworks. The CRA requirements are broader but follow the same logic of vulnerability management, signed updates and secure default configuration. A file built for the CRA covers most of RED 3.3.
  3. Check whether your design triggers an OJEU restriction. That, not the repeal, is what decides whether a notified body sits on your critical path.
  4. Stand up the reporting capability required from 11 September 2026 now: it does not depend on the RED regime and applies to products already in the field.

Sources & references

  1. Delegated Regulation (EU) 2026/339 of 16 February 2026 , EUR-Lex eur-lex.europa.eu/eli/reg_del/2026/339/oj
  2. Delegated Regulation (EU) 2022/30 , EUR-Lex eur-lex.europa.eu/eli/reg_del/2022/30/oj
  3. Regulation (EU) 2024/2847, Cyber Resilience Act , EUR-Lex eur-lex.europa.eu/eli/reg/2024/2847/oj
  4. Implementing Decision (EU) 2025/138, citation of the EN 18031 standards , EUR-Lex eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202500138