EU Radio Equipment Directive

The RED makes wireless a cybersecurity requirement.

Since 1 August 2025, any device with a radio (Wi-Fi, Bluetooth, cellular) on the EU market has to meet the RED cybersecurity essential requirements. Delegated Regulation (EU) 2022/30 activated Article 3.3(d), (e), (f); EN 18031 defines how you prove it. ELTON runs the discovery, proves exploitability, produces the evidence. ELTON is an exploitability management platform, delivered as a managed program. Our team runs the testing continuously. You get the platform, the evidence, and a TestLink™ appliance, with no new headcount.

The regulation

What the RED requires of radio equipment.

Delegated Regulation (EU) 2022/30 switched on three cybersecurity essential requirements in RED Article 3.3. They apply to internet-connected radio equipment, which is nearly every modern connected medical device, and became mandatory on 1 August 2025.

Article 3.3(d)

Network protection

The device must not harm the network or misuse its resources. No amplification, no degradation, no becoming a foothold that spreads onto hospital infrastructure.

Article 3.3(e)

Personal data and privacy

Safeguards for the personal data of the user and the subscriber. For a medical device, that is patient data, in transit and at rest, across every wireless interface.

Article 3.3(f)

Protection from fraud

Controls against unauthorized use and the manipulation of value or authorization. Access, identity, and integrity have to hold up over the air.

The ELTON mapping

Essential requirements, mapped to EN 18031 and evidenced.

Conformity runs through the harmonized standards EN 18031-1, -2, and -3, one per essential requirement. ELTON tests against them the way an attacker would, then hands you the proof, whether you self-assess or go through a notified body.

ESSENTIAL REQUIREMENTHARMONIZED STANDARDELTON · PRESUMPTION OF CONFORMITY3.3(d)Network protectionDoes not harm the network or misuse its resourcesEN 18031-13.3(e)Personal data & privacySafeguards user and patient dataEN 18031-23.3(f)Fraud protectionGuards value and monetary transfersEN 18031-3ELTON conformity evidenceContinuous AI discovery across the radio stackExploitability proven on the real deviceVEX status and reasoning for every findingTest cases and artifacts mapped to EN 18031CONFORMITY ROUTESelf-assessmentVia harmonized standards,evidence ready to fileNotified bodySame evidence package,handed to the assessor
Why it matters

Wireless is the attack surface regulators now name.

The old way

Assert it in a declaration

A self-declaration of conformity with no evidence behind the wireless claims is exactly what post-market surveillance and market-check authorities are now authorized to challenge.

With ELTON

Evidence it on the device

Every wireless interface is discovered, tested, and either proven exploitable or dismissed with reasoning. The EN 18031 mapping and the artifacts sit ready in one record, for the file and for any challenge.

Get conformant

Prove your radio equipment, do not just declare it.

Start with one wireless device. We build the twin, run discovery across the radio stack, and map the findings to EN 18031 so your RED file carries proof, not promises.

Questions

Common questions about the EU Radio Equipment Directive.

When did the RED cybersecurity requirements become mandatory?

1 August 2025. Since that date, any device with a radio (Wi-Fi, Bluetooth, cellular) on the EU market has to meet the RED cybersecurity essential requirements. Delegated Regulation (EU) 2022/30 activated Article 3.3(d), (e) and (f) for internet connected radio equipment, which is nearly every modern connected medical device.

What do RED Articles 3.3(d), (e) and (f) require?

Article 3.3(d) requires that the device does not harm the network or misuse its resources. Article 3.3(e) requires safeguards for the personal data of the user and the subscriber, which for a medical device means patient data in transit and at rest. Article 3.3(f) requires controls against unauthorized use and the manipulation of value or authorization.

What is EN 18031 and how does it relate to the RED?

EN 18031 is the set of harmonized standards that carries presumption of conformity, one part per essential requirement: EN 18031-1 for network protection, EN 18031-2 for personal data and privacy, EN 18031-3 for fraud protection. Conformity runs through those standards whether you self assess or go through a notified body.

Can we self declare RED cybersecurity conformity?

Yes, via the harmonized standards. But a self declaration with no evidence behind the wireless claims is exactly what post-market surveillance and market-check authorities are now authorized to challenge. The same evidence package supports either route, self assessment or handing it to a notified body.

How do you prove a wireless interface is secure rather than assert it?

Test it the way an attacker would. ELTON discovers every wireless interface, runs continuous discovery across the radio stack, and either proves a finding exploitable on the device or dismisses it with reasoning. Test cases and artifacts are mapped to EN 18031, so the RED file carries proof rather than promises.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON