RED already applies. CRA reporting starts September 2026. We turn both into one certification path — certify once, reuse the evidence everywhere.
The landscape
Two EU regulations, several voluntary schemes, four label regimes abroad. The short version:
RED cybersecurity requirements apply since 1 August 2025. EN 18031 gives presumption of conformity — but it is harmonised with restrictions. Let the user skip password setup and self-assessment is gone: a notified body steps in. Manufacturers keep finding this out late.
RED · EN 18031
IN FORCE
The CRA applies — hardware and software, consumer and industrial, no exceptions for size. Most products sit in the default category and can be self-assessed against Annex I. “Most” is not “yours” until someone has checked.
CRA
DEC 2027
These are CRA “important products”, pinned down by Implementing Regulation 2025/2392. Class I self-assesses only with harmonised standards — which are still landing. Class II goes to a notified body. No exceptions, and notified-body capacity will be scarce.
CRA CLASS I / II
REG 2025/2392
Tamper-resistant MCUs and MPUs are CRA Class II; secure elements sit on the critical list. EUCC has been issuing certificates since February 2025. SESIP (EN 17927) and PSA Certified are becoming purchase criteria — if you sell silicon, assurance is now part of the product.
EUCC · SESIP
CRA CLASS II
PSTI is in force, the US Cyber Trust Mark opens in 2026, CLS(IoT) and JC-STAR are linked by live mutual-recognition deals. One well-structured evidence set feeds all of them. Four separate compliance projects is a choice, not a necessity.
GLOBAL LABELS
MUTUAL RECOGNITION
The clock is running
RED work done right is a head start on CRA — but only if the evidence was built for reuse, not as a one-off.
Every radio-connected device placed on the EU market must comply. Already enforced.
Member States designate notifying authorities; conformity assessment bodies queue for notification.
Actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT — 24-hour early warning, 72-hour notification. This bites before any product requirement does. If you have no PSIRT process, you are already late.
Product-specific standards land first; horizontal ones follow in 2027 — uncomfortably close to the deadline.
CE marking requires cybersecurity conformity. No conformity, no market.
How we work
Which regulations, which product class, which conformity route. One workshop, one defensible written position.
Your product and processes against EN 18031 and CRA Annex I. What passes, what fails, what fixing it costs.
Secure boot, update mechanism, credential handling — decided early, so evaluation is a formality, not a redesign.
Risk assessments, technical files, test rationale — written the way evaluators and notified bodies expect to read them.
We prepare the file, brief the lab, and sit on your side of the table throughout.
Vulnerability handling, PSIRT readiness for September 2026, certificates kept valid as the product evolves.
RED evidence carries into CRA. A SESIP-certified platform carries into device-level claims. The same file feeds EN 303 645 labels worldwide. You pay for the engineering once.
For the specialists
If you already live in the CC world, start here.
Three scopes: -1 network protection (Art. 3.3(d)), -2 data and privacy (3.3(e)), -3 fraud prevention (3.3(f)). Harmonisation came with restrictions: presumption of conformity is lost where the standard lets the user decline security — password setup at onboarding, parental access controls, secure updates for products handling financial assets. Those cases route through a notified body.
A year of assessments has produced consistent failure patterns: decision trees applied without documented rationale, “not applicable” claims that collapse under review, out-of-box flows that quietly trigger a restriction.
Our position: we run your product through the decision trees the way an assessor will — before the assessor does.
Module A (internal control), B+C (EU-type examination) or H (full quality assurance) — but the product class constrains the choice. Default products self-assess. Important Class I self-assesses only with harmonised standards. Class II and critical products go to a notified body, full stop. Implementing Regulation 2025/2392 settled classification for all 26 categories.
The open risk is the standards gap: verticals from late October 2026, horizontals in 2027 — close to the deadline.
Our position: build to the draft standards and the existing evidence base (EN 18031, EN 303 645, IEC 62443-4-2 where relevant) now; map to the final texts when they land. Waiting is the expensive option.
SESIP — standardised as EN 17927 — evaluates IoT platforms at five assurance levels with a methodology derived from Common Criteria but scoped for connected devices. A SESIP or PSA Certified platform certificate lets device makers reuse the platform’s claims in their own evaluation (composite evaluation), cutting device-level cost and time.
For secure elements and tamper-resistant hardware, EUCC — issuing since February 2025 — is becoming the reference, and the likely anchor for CRA critical products.
Our position: if you build on certified silicon, your CRA file should say so. If you sell silicon, certification is now a purchase criterion — treat it as product, not paperwork.
ETSI EN 303 645 (v3.1.3) is the world’s common denominator for consumer IoT: it underpins UK PSTI, Singapore’s CLS(IoT), Japan’s JC-STAR, and aligns with the NIST criteria behind the US Cyber Trust Mark, opening in 2026. Mutual recognition is accelerating — Singapore–UK, Japan–Singapore and Japan–UK arrangements are live or signed as of mid-2026.
Our position: one evidence set built around EN 303 645 and EN 18031, maintained once, feeds four label regimes plus your EU obligations. Anything else is paying twice.
No sales rep, no discovery funnel. Thirty minutes with a certification expert, a clear read on your situation, and a written summary of what applies to you.
We’ll send you access by email.