CE marking for IoT consumer products — end-to-end
End-to-end CE marking process for consumer IoT — RED, EMC, LVD, RoHS, CRA (from 11 December 2027), and GPSR — sequenced from scope to vulnerability handling.
By Vladimír Vician
Most CE-marking guides treat radio, safety and cyber as if they were separate workstreams. They are not. A smart bulb's regulatory footprint is decided the moment you choose to embed Wi-Fi, accept mains power and run firmware updates — and the Radio Equipment Directive 2014/53/EU is the spine that holds the other directives together via Article 3(1).
This article walks the end-to-end process for a representative consumer IoT product. We use the standard examples — smart bulb, smart camera, voice assistant — and follow the sequence a manufacturer actually runs: scope → directive map → standards → conformity assessment → DoC → CE → post-market. The CRA, applying from 11 December 2027 per the Commission's CRA policy page, is layered onto that spine, not parallel to it.
Step 1 — Scope the product
Begin with a precise product description. Three attributes decide nearly every downstream regulatory question:
- Radio interfaces. Any Wi-Fi, Bluetooth, Zigbee, Thread, LTE-M or sub-GHz transmitter makes the product radio equipment under RED Article 2(1).
- Power source. Mains-powered (AC > 50 V or DC > 75 V) brings in the safety objectives of the Low Voltage Directive. Battery-only products generally do not — but USB-C from a wall adapter often does indirectly.
- Digital elements. Any embedded firmware, cloud connection or update channel makes the product a "product with digital elements" under CRA Article 3.
A smart bulb hits all three. A battery-powered Bluetooth thermometer hits only the first and third. Get this list wrong and your technical file is built on the wrong directives.
For a structured walk-through of the product description discipline, see technical-file-iot-template.
Step 2 — Map directives and regulations
For a typical consumer IoT product, the canonical stack is:
| Instrument | Role | Notes |
|---|---|---|
| RED 2014/53/EU | Radio essential requirements | Article 3(1)(a) safety, 3(1)(b) EMC, 3(2) spectrum, 3(3) cyber/privacy/fraud |
| EMC 2014/30/EU | EMC for non-radio equipment | Absorbed into RED 3(1)(b) for radio products |
| LVD 2014/35/EU | Electrical safety objectives | Absorbed into RED 3(1)(a) for radio products; applies standalone otherwise |
| RoHS 2011/65/EU | Hazardous substances | Independent CE-marking path; separate DoC |
| CRA 2024/2847 | Cybersecurity essential requirements | From 11 December 2027 |
| GPSR 2023/988 | Horizontal safety backstop | Catches risks not covered above |
The interaction between RED and CRA is the single most-misunderstood point in connected-radio compliance. We dedicate an entire article to it: red-cra-overlap-connected-radio.
Step 3 — Select harmonised standards
Harmonised standards confer a presumption of conformity. For RED Article 3(3) cybersecurity essential requirements, the references published in the Official Journal point to the EN 18031 family — adopted to operationalise the RED Delegated Regulation (EU) 2022/30.
| Essential requirement | Harmonised standard | Scope |
|---|---|---|
| RED 3(1)(a) — safety | EN 62368-1 | Audio/video and ICT equipment safety |
| RED 3(1)(b) — EMC | EN 55032, EN 55035 | Multimedia equipment emissions/immunity |
| RED 3(2) — spectrum | EN 300 328, EN 300 220, etc. | Per radio band (e.g. 2.4 GHz, sub-GHz) |
| RED 3(3)(d) — network | EN 18031-1 | Network protection requirements |
| RED 3(3)(e) — privacy | EN 18031-2 | Personal data and privacy |
| RED 3(3)(f) — fraud | EN 18031-3 | Protection from monetary fraud |
Detailed differences across EN 18031-1/-2/-3 are covered in en-18031-parts-1-2-3-comparison.
Step 4 — Run conformity assessment
Article 17 of the RED defines three conformity-assessment modules. The default for radio equipment is internal production control (Module A, Annex II). Article 17(4) is the trigger that forces a notified body. The directive states it plainly:
Where, in assessing the compliance of radio equipment with the essential requirements set out in Article 3(2) and (3), the manufacturer has not applied or has applied only in part harmonised standards the references of which have been published in the Official Journal of the European Union, or where such harmonised standards do not exist, radio equipment shall be submitted with regard to those essential requirements to either of the following procedures: (a) EU-type examination that is followed by the conformity to type based on internal production control set out in Annex III; (b) conformity based on full quality assurance set out in Annex IV.
Source: RED Article 17(4), Directive 2014/53/EU.
Practical translation:
- All harmonised standards applied in full → Module A (Annex II), self-assessment. No NB required.
- Standards partly applied, or none exist → Module B+C (Annex III) or Module H (Annex IV), notified body involvement required for the relevant essential requirements.
Most consumer IoT products today qualify for Module A because EN 18031-1/-2/-3 cover the Article 3(3) requirements. The path widens or narrows depending on which standards you choose to apply. See when-you-need-a-notified-body for the trigger conditions and conformity-assessment-modules-a-to-h for the underlying Decision 768/2008 modules.
For CRA conformity assessment (applicable from 11 December 2027), see cra-december-2027-readiness.
One email at launch · cancel any time
Step 5 — Compile the technical file
The RED Annex V technical-documentation list is the floor. CRA Article 31 + Annex VII adds cybersecurity-specific items. A consolidated consumer-IoT technical file typically holds:
- Product description, intended-use statement, photographs
- Block diagrams, schematics, PCB layouts
- Radio module datasheet, regulatory module ID (if integrated)
- Risk assessment per directive (see risk-assessment-ce-compliance)
- List of harmonised standards applied (with version + date)
- Test reports (EMC, radio, safety, EN 18031)
- Cybersecurity architecture, threat model, support-period statement
- Software bill of materials in CycloneDX or SPDX (see sbom-cyclonedx-vs-spdx-hardware)
- Vulnerability handling process per CRA Annex I Part II
- Draft DoCs and final signed DoCs
Retention is 10 years from the last unit being placed on the market. See technical-file-retention-requirements.
Step 6 — Issue the DoC and affix CE
Draft the EU Declaration of Conformity per RED Annex VI. The required fields include the manufacturer (and EC REP if non-EU), the product identifier, the legislation invoked (RED, RoHS, CRA from December 2027), the harmonised standards used, the notified-body number if any, and the signature with place + date. A worked example sits in sample-doc-walkthrough.
From 11 December 2027, the CRA permits a single combined DoC covering both the RED essential requirements and the CRA essential requirements, provided all referenced acts are listed. Until then, RoHS is typically declared on the same DoC; CRA cannot yet be invoked.
Affix the CE marking visibly to the product, the packaging and the documentation. Place a notified-body four-digit number next to CE only when an NB was involved (i.e. when Article 17(4) applied). For full DoC discipline see declaration-of-conformity-101.
Step 7 — Run post-market obligations
CE marking is not a single event. From the moment your first unit ships:
- Maintain corrective-action capability under Decision No 768/2008/EC.
- Update the DoC whenever a substantial modification occurs (see updating-a-doc-after-amendment).
- From 11 September 2026: report actively-exploited vulnerabilities and severe incidents to ENISA via the single reporting platform within the timelines in CRA Article 14. Details in cra-enisa-24-hour-reporting.
- From 11 December 2027: provide security updates for the support period declared in the technical file, refresh the SBOM (see sbom-update-frequency-cra), and operate the vulnerability-handling process described in CRA Annex I Part II.
Common mistakes
- Treating RED and CRA as parallel. They are sequenced. The RED Article 3(3) cyber essential requirements have been mandatory since 1 August 2025; CRA layers full lifecycle obligations from 11 December 2027.
- Skipping the directive map for "small" products. A USB-C smart plug still requires LVD safety analysis. A coin-cell tracker still falls under RED. There are no de-minimis exemptions for CE marking.
- Choosing Module A without verifying that every harmonised standard is applied in full. Article 17(4) RED is binary — partial application of any standard for Article 3(2) or 3(3) requirements is enough to require a notified body.
- Forgetting GPSR. It is horizontal and catches non-electrical risks (packaging, choking, chemical migration from enclosure). See top-10-ce-marking-mistakes.
- No support-period commitment. CRA Article 13(8) requires manufacturers to determine and disclose the support period during which security updates are provided. Absence of that commitment is a documentary defect.
How Cenitia helps
Cenitia compiles the directive map, drafts the harmonised-standards list, generates the technical file skeleton with the right Annex V + CRA Annex VII fields, produces a Module A or Module B+C DoC, and watches the Official Journal so that when a standard reference is republished (EN 18031 has already been amended once), your file is flagged for update.
For consumer IoT specifically, our wizard pre-loads the typical smart-bulb / smart-camera / voice-assistant product templates and walks you through scope, directive selection, standards, conformity-assessment routing, and DoC drafting — with every clause traced back to its EUR-Lex source.
One email at launch · cancel any time
Frequently asked questions
Does every consumer IoT product need a notified body?
Usually not. Under RED Article 17(1) of Directive 2014/53/EU, if you apply harmonised standards in full — including EN 18031-1/-2/-3 for the Article 3(3)(d)(e)(f) essential requirements — internal production control (Module A) is sufficient. Article 17(4) only triggers notified-body involvement when those standards are not applied, applied only in part, or do not exist.
What is the CRA deadline for consumer IoT?
Per the European Commission's Cyber Resilience Act policy page, the CRA entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026, and the main obligations (including the cybersecurity essential requirements in Annex I) apply from 11 December 2027.
Do I still need EMC and LVD declarations separately under RED?
No. RED Article 3(1) absorbs the EMC essential requirements (point b) and the safety objectives of the Low Voltage Directive (point a) for radio equipment, regardless of voltage. The single EU DoC issued under RED covers those essential requirements; you do not draft an additional EMC or LVD DoC for the same radio product.
How does GPSR interact with RED and CRA for connected products?
Regulation (EU) 2023/988 is horizontal and applies to the safety risks not covered by sector-specific legislation. For a smart bulb, RED + LVD + CRA cover most risks; GPSR catches residual hazards such as choking risk in packaging or chemical hazards from a non-RoHS-substance enclosure additive.
What if my smart bulb is already on the market when CRA applies?
CRA transitional provisions distinguish between products placed on the market before and after 11 December 2027. Products on the market before that date are generally subject to the new obligations only when they undergo a substantial modification. Vulnerability handling obligations (Article 14) apply broadly. See our companion article on existing products for the detail.
Which harmonised standards apply to the RED Article 3(3) cyber requirements?
EN 18031-1 (network protection), EN 18031-2 (personal-data and privacy protection) and EN 18031-3 (fraud protection) operationalise the RED Delegated Regulation (EU) 2022/30. They are mandatory for connected radio equipment from 1 August 2025 and provide the cleanest route into Module A self-assessment.
Related from the Library
- ce-marking-101 — the foundational CE marking process for any product class
- red-cra-overlap-connected-radio — how RED Article 3(3) and CRA Annex I interact
- en-18031-parts-1-2-3-comparison — choosing the right parts of EN 18031
- technical-file-iot-template — file structure for a connected consumer product
- cra-december-2027-readiness — operational checklist for the 11 December 2027 deadline
Further reading
- Directive 2014/53/EU (RED) on EUR-Lex — full text of the Radio Equipment Directive
- Regulation (EU) 2024/2847 (CRA) on EUR-Lex — full text of the Cyber Resilience Act
- Cyber Resilience Act policy page, European Commission — official Commission summary and timelines
- Directive 2014/30/EU (EMC) on EUR-Lex — Electromagnetic Compatibility Directive
- Directive 2011/65/EU (RoHS) on EUR-Lex — Restriction of Hazardous Substances
- Regulation (EU) 2023/988 (GPSR) on EUR-Lex — General Product Safety Regulation
- Commission Delegated Regulation (EU) 2022/30 on EUR-Lex — RED Article 3(3)(d)(e)(f) activation
Last reviewed: 5 July 2026. Cited regulations watched continuously by Cenitia — when one amends, this article is flagged for update.
FAQ
Frequently asked questions
Does every consumer IoT product need a notified body?
Usually not. Under RED Article 17(1) of [Directive 2014/53/EU](https://eur-lex.europa.eu/eli/dir/2014/53/oj), if you apply harmonised standards in full — including EN 18031-1/-2/-3 for the Article 3(3)(d)(e)(f) essential requirements — internal production control (Module A) is sufficient. Article 17(4) only triggers notified-body involvement when those standards are not applied, applied only in part, or do not exist.
What is the CRA deadline for consumer IoT?
Per the European Commission's [Cyber Resilience Act policy page](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act), the CRA entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026, and the main obligations (including the cybersecurity essential requirements in Annex I) apply from 11 December 2027.
Do I still need EMC and LVD declarations separately under RED?
No. RED Article 3(1) absorbs the EMC essential requirements (point b) and the safety objectives of the Low Voltage Directive (point a) for radio equipment, regardless of voltage. The single EU DoC issued under RED covers those essential requirements; you do not draft an additional EMC or LVD DoC for the same radio product.
How does GPSR interact with RED and CRA for connected products?
[Regulation (EU) 2023/988](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023R0988) is horizontal and applies to the safety risks not covered by sector-specific legislation. For a smart bulb, RED + LVD + CRA cover most risks; GPSR catches residual hazards such as choking risk in packaging or chemical hazards from a non-RoHS-substance enclosure additive.
What if my smart bulb is already on the market when CRA applies?
CRA transitional provisions distinguish between products placed on the market before and after 11 December 2027. Products on the market before that date are generally subject to the new obligations only when they undergo a substantial modification. Vulnerability handling obligations (Article 14) apply broadly. See our companion article on existing products for the detail.
Which harmonised standards apply to the RED Article 3(3) cyber requirements?
EN 18031-1 (network protection), EN 18031-2 (personal-data and privacy protection) and EN 18031-3 (fraud protection) operationalise the [RED Delegated Regulation (EU) 2022/30](https://eur-lex.europa.eu/eli/reg_del/2022/30/oj). They are mandatory for connected radio equipment from 1 August 2025 and provide the cleanest route into Module A self-assessment.
Continue reading
Related guides
reference
EN 62368-1 — safety for audio/video and ICT equipment
EN IEC 62368-1 (3rd ed., 2018) is the hazard-based safety standard replacing EN 60950-1 and EN 60065 — energy classes, safeguards, LVD presumption of conformity.
8 min read
reference
IEC 62443 family overview for product manufacturers
Practical map of the IEC 62443 industrial cybersecurity standards — what -1-1, -2-1, -2-4, -3-2, -3-3, -4-1 and -4-2 cover, and which parts hardware manufacturers actually need.
10 min read
reference
EN 55032 — EMC emissions classes A and B for ITE
Reference on EN 55032 (CISPR 32) emissions classes A and B for multimedia equipment — limits, frequency ranges, and presumption of conformity under the EMC Directive.
8 min read
reference
General Product Safety Regulation 2023/988 — when it applies
Regulation (EU) 2023/988 GPSR applies from 13 December 2024, replacing Directive 2001/95/EC. Scope, traceability, online marketplaces, Safety Gate, recalls.
8 min read
Put this into practice
Free tools & references
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
- Do I need a Notified Body?Find out, per regulation, whether a Notified Body is required.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.