IoT & Embedded

Get your connected product certified for the European market.

RED already applies. CRA reporting starts September 2026. We turn both into one certification path — certify once, reuse the evidence everywhere.

DEVICE PLATFORM EVIDENCE CERTIFICATE

The landscape

What applies to you

Two EU regulations, several voluntary schemes, four label regimes abroad. The short version:

You ship a radio-connected device in the EU

RED cybersecurity requirements apply since 1 August 2025. EN 18031 gives presumption of conformity — but it is harmonised with restrictions. Let the user skip password setup and self-assessment is gone: a notified body steps in. Manufacturers keep finding this out late.

RED · EN 18031

IN FORCE

You ship any product with digital elements

The CRA applies — hardware and software, consumer and industrial, no exceptions for size. Most products sit in the default category and can be self-assessed against Annex I. “Most” is not “yours” until someone has checked.

CRA

DEC 2027

You ship a smart lock, camera, baby monitor, toy or wearable

These are CRA “important products”, pinned down by Implementing Regulation 2025/2392. Class I self-assesses only with harmonised standards — which are still landing. Class II goes to a notified body. No exceptions, and notified-body capacity will be scarce.

CRA CLASS I / II

REG 2025/2392

You make chips, secure elements or IoT platforms

Tamper-resistant MCUs and MPUs are CRA Class II; secure elements sit on the critical list. EUCC has been issuing certificates since February 2025. SESIP (EN 17927) and PSA Certified are becoming purchase criteria — if you sell silicon, assurance is now part of the product.

EUCC · SESIP

CRA CLASS II

You sell consumer devices in the UK, US, Singapore or Japan

PSTI is in force, the US Cyber Trust Mark opens in 2026, CLS(IoT) and JC-STAR are linked by live mutual-recognition deals. One well-structured evidence set feeds all of them. Four separate compliance projects is a choice, not a necessity.

GLOBAL LABELS

MUTUAL RECOGNITION

The clock is running

The next 18 months decide whether CRA is a project or a crisis

RED work done right is a head start on CRA — but only if the evidence was built for reuse, not as a one-off.

1 Aug 2025 DONE

RED cybersecurity requirements mandatory

Every radio-connected device placed on the EU market must comply. Already enforced.

11 Jun 2026 DONE

CRA notified-body framework applies

Member States designate notifying authorities; conformity assessment bodies queue for notification.

11 Sep 2026 WEEKS AWAY

CRA reporting obligations begin

Actively exploited vulnerabilities and severe incidents must be reported to ENISA and your national CSIRT — 24-hour early warning, 72-hour notification. This bites before any product requirement does. If you have no PSIRT process, you are already late.

30 Oct 2026

First CRA vertical harmonised standards expected

Product-specific standards land first; horizontal ones follow in 2027 — uncomfortably close to the deadline.

11 Dec 2027

CRA applies in full

CE marking requires cybersecurity conformity. No conformity, no market.

How we work

From "which rules apply?" to a certificate on the market

1

Applicability analysis

Which regulations, which product class, which conformity route. One workshop, one defensible written position.

2

Gap assessment

Your product and processes against EN 18031 and CRA Annex I. What passes, what fails, what fixing it costs.

3

Certification-ready architecture

Secure boot, update mechanism, credential handling — decided early, so evaluation is a formality, not a redesign.

4

Evidence production

Risk assessments, technical files, test rationale — written the way evaluators and notified bodies expect to read them.

5

Evaluation management

We prepare the file, brief the lab, and sit on your side of the table throughout.

6

Continuous compliance

Vulnerability handling, PSIRT readiness for September 2026, certificates kept valid as the product evolves.

One evidence base, many certifications

RED evidence carries into CRA. A SESIP-certified platform carries into device-level claims. The same file feeds EN 303 645 labels worldwide. You pay for the engineering once.

EVIDENCE RED · EN 18031 CRA Annex I EN 303 645 SESIP / EUCC PSTI · CLS · JC-STAR Cyber Trust Mark

For the specialists

The detail behind the summary

If you already live in the CC world, start here.

EN 18031 in practice

Three scopes: -1 network protection (Art. 3.3(d)), -2 data and privacy (3.3(e)), -3 fraud prevention (3.3(f)). Harmonisation came with restrictions: presumption of conformity is lost where the standard lets the user decline security — password setup at onboarding, parental access controls, secure updates for products handling financial assets. Those cases route through a notified body.

A year of assessments has produced consistent failure patterns: decision trees applied without documented rationale, “not applicable” claims that collapse under review, out-of-box flows that quietly trigger a restriction.

Our position: we run your product through the decision trees the way an assessor will — before the assessor does.

Module A (internal control), B+C (EU-type examination) or H (full quality assurance) — but the product class constrains the choice. Default products self-assess. Important Class I self-assesses only with harmonised standards. Class II and critical products go to a notified body, full stop. Implementing Regulation 2025/2392 settled classification for all 26 categories.

The open risk is the standards gap: verticals from late October 2026, horizontals in 2027 — close to the deadline.

Our position: build to the draft standards and the existing evidence base (EN 18031, EN 303 645, IEC 62443-4-2 where relevant) now; map to the final texts when they land. Waiting is the expensive option.

SESIP — standardised as EN 17927 — evaluates IoT platforms at five assurance levels with a methodology derived from Common Criteria but scoped for connected devices. A SESIP or PSA Certified platform certificate lets device makers reuse the platform’s claims in their own evaluation (composite evaluation), cutting device-level cost and time.

For secure elements and tamper-resistant hardware, EUCC — issuing since February 2025 — is becoming the reference, and the likely anchor for CRA critical products.

Our position: if you build on certified silicon, your CRA file should say so. If you sell silicon, certification is now a purchase criterion — treat it as product, not paperwork.

ETSI EN 303 645 (v3.1.3) is the world’s common denominator for consumer IoT: it underpins UK PSTI, Singapore’s CLS(IoT), Japan’s JC-STAR, and aligns with the NIST criteria behind the US Cyber Trust Mark, opening in 2026. Mutual recognition is accelerating — Singapore–UK, Japan–Singapore and Japan–UK arrangements are live or signed as of mid-2026.

Our position: one evidence set built around EN 303 645 and EN 18031, maintained once, feeds four label regimes plus your EU obligations. Anything else is paying twice.

Talk to the person who will actually do the work

No sales rep, no discovery funnel. Thirty minutes with a certification expert, a clear read on your situation, and a written summary of what applies to you.

Contact us

Request this document

We’ll send you access by email.