CE marking for industrial sensors and gateways
EMC, LVD, RED, RoHS, ATEX, Machinery Regulation and CRA stack for industrial sensors, gateways and edge devices placed on the EU market.
By Vladimír Vician
Industrial sensors, fieldbus gateways and edge controllers are deceptively simple to CE-mark. Each housing typically attracts three to six EU instruments at once: Directive 2014/30/EU on electromagnetic compatibility, Directive 2014/35/EU on low voltage (above 50 V AC or 75 V DC), Directive 2014/53/EU for the radio variant, Directive 2011/65/EU (RoHS) for material restrictions, Directive 2014/34/EU (ATEX) if the device is sold into Ex zones, and the Machinery Regulation (EU) 2023/1230 if the sensor is sold as a safety component.
From 11 December 2027 every product with digital elements placed on the EU market is also caught by the Cyber Resilience Act, Regulation (EU) 2024/2847. That is the new horizontal layer on top of the existing sectoral CE stack — and it is the one most teams underestimate.
The CE stack for an industrial sensor — directive by directive
EMC Directive 2014/30/EU
Directive 2014/30/EU (OJ L 96, 29.3.2014, p. 79) is the universal layer. Article 6 requires equipment to meet the essential requirements in Annex I — namely that generated electromagnetic disturbance does not exceed the level above which equipment cannot operate as intended, and that the equipment has an adequate level of intrinsic immunity. Article 2 excludes radio equipment, which is regulated under the RED instead.
The directive itself is environment-neutral. The "industrial environment" idea sits in the harmonised standards, where the EN 61000-6-x series and EN 55032 (emissions for multimedia equipment) split products into residential/light-industrial and heavy-industrial classes. Choose the class that matches the actual deployment, not the most permissive one — choosing wrongly is one of the most common audit findings on industrial gear.
Low Voltage Directive 2014/35/EU
The LVD applies when the equipment's working voltage is "between 50 and 1 000 V for alternating current and between 75 and 1 500 V for direct current" — Article 1 of Directive 2014/35/EU. Many 24 V DC sensors sit below the threshold and therefore escape the LVD entirely. PoE gateways, panel-mount controllers and AC-powered head-ends usually fall in scope.
Radio Equipment Directive 2014/53/EU
If your gateway transmits intentionally — Wi-Fi, BLE, LoRaWAN, NB-IoT, sub-GHz — RED 2014/53/EU replaces both the EMC Directive and the LVD for that product. RED also activates the Article 3(3) delegated acts on cybersecurity and personal-data protection, which since EN 18031-1/-2/-3 became enforceable on 1 August 2025 cover network protection, personal data and financial fraud prevention.
RoHS Directive 2011/65/EU
Industrial monitoring and control instruments are explicitly in scope under category 9 of Annex I to Directive 2011/65/EU. The restricted-substance list (lead, mercury, cadmium, chromium VI, PBB, PBDE plus four phthalates added by Delegated Directive 2015/863) applies to homogeneous materials and must be declared on the DoC alongside other applicable EU acts.
ATEX Directive 2014/34/EU
Directive 2014/34/EU covers equipment and protective systems intended for use in potentially explosive atmospheres. Article 1 also captures safety, controlling and regulating devices required for the safe functioning of such equipment, and components intended to be incorporated into them.
| Equipment-Group | Categories | Typical use | Conformity assessment (per Article 13) |
|---|---|---|---|
| I (mines) | M1, M2 | Underground / firedamp surface installations | M1: EU-type examination + production QA or product verification |
| II (other) | 1, 2, 3 | Process industries, petrochemical, dust atmospheres | Cat 1: EU-type examination + QA / verification; Cat 3: internal production control |
An ATEX sensor stacks ATEX on top of EMC, RoHS and — where applicable — RED. The notified body for the ATEX route is separate from any RED notified body.
Machinery Regulation (EU) 2023/1230
Regulation (EU) 2023/1230 repeals Directive 2006/42/EC and starts applying 20 January 2027. It defines a "safety component" as a physical or digital component, including software, that fulfils a safety function and is independently placed on the market. Sensors sold as standalone safety components — light curtains, safety laser scanners, safety-rated proximity switches — must comply directly. Sensors integrated into a machine before placing on the market are assessed by the machine builder. Manufacturers must also adopt "proportionate measures" against malicious third-party action that could compromise safety.
The CRA layer — and why it is different
Regulation (EU) 2024/2847 sits on top of every directive above for any product with digital elements. Article 71 sets staged application:
"This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026 and Chapter IV (Articles 35 to 51) shall apply from 11 June 2026."
That gives you the 11 September 2026 reporting obligations for actively exploited vulnerabilities and severe incidents, and the full December 2027 obligation set for essential cybersecurity requirements, vulnerability handling and the DoC layer.
Annex III lists "important" products in two classes; Annex IV lists "critical" products requiring stronger assessment. Network management systems, identity management systems, hardware security modules, smartcards, microcontrollers with security-related functionality and industrial automation and control systems all appear in the upper tiers — see our Annex III walkthrough for the current categorisation. A general-purpose temperature sensor with an IP stack typically lands in the default tier (self-assessment). A safety PLC, a hardware-rooted gateway with HSM, or a managed industrial switch likely sits in Class II or Annex IV.
One email at launch · cancel any time
Cybersecurity essential requirements: IEC 62443 as the working baseline
Harmonised standards under the CRA are still being drafted. Until they land, IEC 62443 is the credible baseline for industrial sensors and gateways. The two parts that matter most for product manufacturers:
- IEC 62443-4-1 — secure product development lifecycle requirements across eight practice areas (security management, specification, design, implementation, verification, defect management, release, update).
- IEC 62443-4-2 — technical security requirements for IACS components, divided into 12 subject areas with security-level capabilities SL-C 1 through 4.
Aligning your gate reviews and SBOM workflow against 62443-4-1 from now means most CRA Annex I and Annex II evidence will already be on file when harmonised standards arrive.
A typical CE compliance matrix for three device archetypes
| Device | EMC 2014/30 | LVD 2014/35 | RED 2014/53 | RoHS 2011/65 | ATEX 2014/34 | Machinery 2023/1230 | CRA 2024/2847 |
|---|---|---|---|---|---|---|---|
| 24 V DC wired temperature sensor | yes | no | no | yes (cat 9) | only if Ex zone | only if standalone safety component | yes — default tier |
| Wi-Fi industrial gateway (PoE) | absorbed by RED | absorbed by RED | yes | yes | no | no | yes — likely important |
| Safety PLC with HSM | yes | yes | optional | yes | optional | yes (safety component) | yes — likely critical |
DoC layout for a multi-instrument device
Article 14 of the ATEX Directive, Article 14 of the EMC Directive and equivalent provisions in the LVD and RED all require a single EU Declaration of Conformity. List every Union act in scope, identify the harmonised standards relied on (with publication year), and from December 2027 add the CRA reference and conformity-assessment evidence. Our DoC 101 and sample DoC walkthrough show the layout.
Common mistakes
- Treating EMC class A vs class B casually. Many industrial sensors are shipped with Class B (residential) limits to be "safe" — but the corresponding immunity test set is inappropriate, and you end up with an over-engineered emissions design that still fails industrial immunity audits. Pick the class that matches deployment.
- Forgetting that RED supersedes EMC for radio equipment. Listing both Directive 2014/30/EU and Directive 2014/53/EU on the DoC for the same radio function is a red flag during market surveillance.
- Assuming ATEX equals "industrial." ATEX only applies to potentially explosive atmospheres. A factory automation sensor with no Ex marking does not need ATEX.
- Skipping CRA classification. Default-tier self-assessment is the lowest CRA burden, but only if the product is genuinely not in Annex III or IV. Industrial automation control systems and HSMs are explicitly upper-tier.
- Stopping at IEC 62443-4-2 without 4-1. The secure development lifecycle is the part regulators and notified bodies will most want to audit. The technical SL-C levels are easier to demonstrate than the process maturity.
- Underestimating the 11 September 2026 reporting cut-off. Article 14 applies 15 months before the rest of the CRA. See our ENISA 24-hour reporting walkthrough.
How Cenitia helps
Cenitia builds the multi-directive compliance file for industrial IoT in one workflow: classify the device against EMC, LVD, RED, RoHS, ATEX, Machinery and CRA in a single intake, generate the Annex II technical file with linked harmonised standards (including IEC 62443-4-x evidence), and produce the DoC with every Union act stacked correctly.
When Regulation (EU) 2024/2847 or any of its harmonised standards amend, the platform flags every DoC and technical file that cited the affected clause, so your CE marking does not silently drift out of date. The CRA timeline and Annex III categorisation are tracked continuously.
One email at launch · cancel any time
Frequently asked questions
Which CE directives apply to a wired industrial Ethernet sensor?
At minimum EMC Directive 2014/30/EU and RoHS Directive 2011/65/EU. If the sensor is powered from a voltage in the LVD range (50–1000 V AC or 75–1500 V DC per Article 1 of Directive 2014/35/EU), the LVD applies too. From 11 December 2027, the CRA (Regulation (EU) 2024/2847) applies to any product with digital elements placed on the EU market.
Does the EMC Directive distinguish industrial from residential environments?
The Directive 2014/30/EU itself (OJ L 96, 29.3.2014) sets technology-neutral essential requirements in Annex I. The environment distinction lives in the harmonised standards, such as the EN 61000-6-x generic immunity and emission standards, which separate residential/light-industrial from heavy industrial classes. Choose the class that matches the intended electromagnetic environment.
When do I need ATEX 2014/34/EU on a sensor?
When the equipment is intended for use in potentially explosive atmospheres — Group I (underground mines and surface installations with firedamp or combustible dust) or Group II (other places, categories 1, 2 or 3). Article 13 of Directive 2014/34/EU links the conformity assessment module to the category; categories M1 and 1 require notified-body involvement.
Are industrial gateways "important" or "critical" under the CRA?
Annex III of Regulation (EU) 2024/2847 lists important products in Class I and Class II. Industrial automation and control systems, identity management systems and network management systems appear in Class II in the published text. PLCs and hardware security modules fall in the higher tiers. Annex IV lists critical products. Check the official EUR-Lex text before classifying — the Commission may further specify categories through implementing acts.
Do I still need EMC and RED if my gateway only does Wi-Fi?
Radio Equipment Directive 2014/53/EU absorbs the relevant EMC and electrical-safety essential requirements for radio equipment, so an in-scope Wi-Fi gateway follows the RED path rather than the EMC Directive separately. EMC essential requirements still apply, but conformity is demonstrated through the RED. EMC Directive 2014/30/EU explicitly excludes radio equipment from its scope in Article 2.
What cybersecurity standard should we plan against for industrial devices?
IEC 62443 is the recognised series for industrial automation and control systems. IEC 62443-4-1 covers the secure product development lifecycle and 62443-4-2 covers technical security requirements for IACS components. The harmonised standards under the CRA are still being developed, but 62443-4-x is the most credible starting point for industrial sensors and gateways.
Related from the Library
- CRA Annex III — important products — where industrial gateways and HSMs sit.
- IEC 62443 family overview — the de facto industrial cybersecurity series.
- RED–CRA overlap for connected radio — how the two regimes interact on wireless gateways.
- EN 18031 parts 1/2/3 comparison — harmonised RED cybersecurity standards.
- Technical file template for IoT — the documentation structure for connected devices.
Further reading
- Directive 2014/30/EU — EMC — official OJ text.
- Directive 2014/35/EU — Low Voltage Directive — official OJ text.
- Directive 2014/53/EU — Radio Equipment Directive — official OJ text.
- Directive 2014/34/EU — ATEX — official OJ text.
- Directive 2011/65/EU — RoHS — official OJ text.
- Regulation (EU) 2023/1230 — Machinery — official OJ text.
- Regulation (EU) 2024/2847 — Cyber Resilience Act — official OJ text.
Last reviewed: 5 July 2026. Cited regulations watched continuously by Cenitia — when one amends, this article is flagged for update.
FAQ
Frequently asked questions
Which CE directives apply to a wired industrial Ethernet sensor?
At minimum EMC Directive 2014/30/EU and RoHS Directive 2011/65/EU. If the sensor is powered from a voltage in the LVD range (50–1000 V AC or 75–1500 V DC per Article 1 of Directive 2014/35/EU), the LVD applies too. From 11 December 2027, the CRA (Regulation (EU) 2024/2847) applies to any product with digital elements placed on the EU market.
Does the EMC Directive distinguish industrial from residential environments?
The Directive 2014/30/EU itself (OJ L 96, 29.3.2014) sets technology-neutral essential requirements in Annex I. The environment distinction lives in the harmonised standards, such as the EN 61000-6-x generic immunity and emission standards, which separate residential/light-industrial from heavy industrial classes. Choose the class that matches the intended electromagnetic environment.
When do I need ATEX 2014/34/EU on a sensor?
When the equipment is intended for use in potentially explosive atmospheres — Group I (underground mines and surface installations with firedamp or combustible dust) or Group II (other places, categories 1, 2 or 3). Article 13 of Directive 2014/34/EU links the conformity assessment module to the category; categories M1 and 1 require notified-body involvement.
Are industrial gateways 'important' or 'critical' under the CRA?
Annex III of Regulation (EU) 2024/2847 lists important products in Class I and Class II. Industrial automation and control systems, identity management systems and network management systems appear in Class II in the published text. PLCs and hardware security modules fall in the higher tiers. Annex IV lists critical products. Check the official EUR-Lex text before classifying — the Commission may further specify categories through implementing acts.
Do I still need EMC and RED if my gateway only does Wi-Fi?
Radio Equipment Directive 2014/53/EU absorbs the relevant EMC and electrical-safety essential requirements for radio equipment, so an in-scope Wi-Fi gateway follows the RED path rather than the EMC Directive separately. EMC essential requirements still apply, but conformity is demonstrated through the RED. EMC Directive 2014/30/EU explicitly excludes radio equipment from its scope in Article 2.
What cybersecurity standard should we plan against for industrial devices?
IEC 62443 is the recognised series for industrial automation and control systems. IEC 62443-4-1 covers the secure product development lifecycle and 62443-4-2 covers technical security requirements for IACS components. The harmonised standards under the CRA are still being developed, but 62443-4-x is the most credible starting point for industrial sensors and gateways.
Continue reading
Related guides
guide
CE marking medical wearables — MDR + CRA overlap
How CE marking works for a medical wearable: MDR is binding, CRA is carved out by Article 2(2), and RED still applies to the wireless side.
9 min read
guide
CE marking for IoT consumer products — end-to-end
End-to-end CE marking process for consumer IoT — RED, EMC, LVD, RoHS, CRA (from 11 December 2027), and GPSR — sequenced from scope to vulnerability handling.
9 min read
reference
EN 62368-1 — safety for audio/video and ICT equipment
EN IEC 62368-1 (3rd ed., 2018) is the hazard-based safety standard replacing EN 60950-1 and EN 60065 — energy classes, safeguards, LVD presumption of conformity.
8 min read
reference
IEC 62443 family overview for product manufacturers
Practical map of the IEC 62443 industrial cybersecurity standards — what -1-1, -2-1, -2-4, -3-2, -3-3, -4-1 and -4-2 cover, and which parts hardware manufacturers actually need.
10 min read
Put this into practice
Free tools & references
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
- Do I need a Notified Body?Find out, per regulation, whether a Notified Body is required.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.