For manufacturers planning EU market access in 2026, compliance pressure continues to rise. It is not market demand shrinking – but multiple regulations converging and taking effect simultaneously. Compliance frameworks built years ago are now falling behind the latest requirements. RED cybersecurity provisions are now in effect, CRA (Cyber Resilience Act) is entering the pre‑planning phase, and EN 18031 has become a hard threshold for wireless connected devices – multiple policies intersecting – one oversight creates compliance gaps.
Before August 2025, the vast majority of wireless devices did not require Notified Body involvement for CE. Manufacturers would complete tests against harmonised standards and self‑declare DoC – completing the compliance path.
With (EU) 2025/138, this model now has clear boundaries. Common misconception: as long as a device supports connectivity, a Notified Body is mandatory.
Core rule clarification:
·EN 18031 is now a RED harmonised standard – under the standard, Module A self‑declaration remains permitted.
The only scenario that invalidates the standard and mandates Notified Body involvement:
·The device ships with a fixed default password and does not force the user to change it on first boot.
Products with payment functions or child‑data collection – these correspond to specific EN 18031 sub‑sections – can still use self‑declaration – these are not NB triggers. Do not confuse the conditions.
The only exemption path:
·Pure one‑way receivers with no network connectivity can continue using Module A self‑declaration. Boundary: if a radio receiver also has Bluetooth or Wi‑Fi transmission capability, it remains a RED‑regulated wireless transmitter – this exemption does not apply.
2. EN 18031 – Now Fully in Effect
EN 18031 became effective on 1 August 2025 – but many manufacturers only began testing and remediation in 2026 due to information lag.
The standard comprises three parts: general security, data protection, and financial security – with 14 security objectives. Not all items require testing. Products without OTA remote‑update capability – corresponding clauses can be excluded – no need for extra test investment.
TLS protocol is the highest‑frequency remediation issue:
·The standard requires TLS 1.3 as preferred – TLS 1.2 may be retained for legacy peripheral compatibility.
·TLS 1.0 and 1.1 must be disabled – they cannot be enabled by default.
Many submissions fail because old protocols were not completely disabled in firmware. Reminder: retaining only TLS 1.2 and above is a baseline access condition – not an optimisation suggestion.
Password compliance bottom line: if the product allows password‑free access, or ships with a default password without forced‑change mechanism – this not only violates EN 18031 security clauses but also directly triggers mandatory Notified Body review – significantly increasing certification timeline and cost.
3. CRA – Cyber Resilience Act – Mandatory in 2027, But New Projects Must Plan Now
CRA's formal mandatory date is 11 December 2027 – but from 2026, its requirements are already influencing product development. The Act requires devices to maintain cybersecurity capability throughout the product lifecycle – after product retirement, related security documentation must be retained for 10 years.
Projects starting now – if you wait until the regulation is in effect to retroactively prepare compliance materials – workload multiplies. A prudent approach: reserve OTA security update channels at the design stage, and establish a standardised SBOM (Software Bill of Materials) output process. Without this foundation, 2027 will require large‑scale rework.
Another common misconception: EN 18031 test reports cannot directly substitute for CRA compliance materials. The two have different regulatory objectives and scopes – there is no official mutual recognition. However: EN 18031 test data and vulnerability assessment materials can serve as supporting evidence for CRA – they are not entirely unusable.
4. UK, Switzerland, Turkey – Do Not Mix with EU CE
·UKCA transition extended to 31 December 2027 – England, Scotland, Wales accept valid CE marks and reports during transition.
Two key limitations:
·Northern Ireland follows the Northern Ireland Protocol – CE is a long‑term requirement.
·If the UK updates harmonised standards independently, existing CE reports risk becoming invalid – do not wait until the deadline to plan UKCA.
·Switzerland does not directly accept EU CE reports. Wireless RF products require OFCOM notification – but most data can be reused – no need for full retesting – only local filing. Do not assume full re‑certification is required.
·Turkey – common misconception: Turkey uses EU‑aligned technical standards. Valid EU CE test reports and DoCs can serve as technical evidence for Turkish access – it is not a completely separate incompatible system. Additional requirements: local importer filing and Turkish‑language documentation – plan ahead to avoid customs delays.
5. EU Authorised Representative and Technical Documentation – Frequently Overlooked Risks
Overseas manufacturers (China, Hong Kong, Macau, Taiwan) without an EU‑based entity must appoint an EU Authorised Representative (EU‑REP).
Not every shipment is checked by customs – but if market surveillance, customer complaints, or safety investigations occur and no valid EU‑REP can be provided – the product is deemed non‑compliant.
DoC – English is recommended. France, Germany, and other member‑state authorities have the legal right to request a local‑language version – reserve translation budget in advance.
Document retention – distinguish clearly:
·Traditional RED: technical documents must be retained for 10 years after the last product is placed on the market.
·CRA: an independent Act – adds SBOM, vulnerability handling records, and security update policy retention – not simply extending the existing document retention period – but adding entirely new document types.
6. CE Certification Penalties – The Reality
Many sources claim CE non‑compliance can result in fines up to 4% of global annual revenue – this is not accurate.
The 4% revenue figure applies to GDPR, CRA, and the Digital Services Act – not RED. RED penalty provisions are set by individual EU member states – there is no uniform 4% cap for RED wireless products. Serious non‑compliance typically results in: goods detention, product delisting, mandatory recall, and administrative fines – risks remain substantial.
Looking ahead, CE compliance in 2026 is no longer just lab testing. Regulatory interpretation, supply‑chain management, and cross‑border legal responsibility – all are now part of the compliance system. Understanding the full framework is the only way to secure the EU market.
For CE certification 2026 EU new regulations, contact BlueAsia at 13534225140 (King) or king.guo@cblueasia.com.
Related News