EU hardware compliance starts with the product’s intended use, connectivity, market role and applicable sector rules. A wireless sensor, a medical device and a factory operator do not share one universal regulatory checklist. The following timeline distinguishes product requirements from obligations on organisations and AI operators.
CRA: reporting now, product requirements later
The Cyber Resilience Act applies within its Article 2 scope, including products with a direct or indirect data connection, with specified sector exclusions. Article 14 reporting has applied since 11 September 2026 to actively exploited vulnerabilities and severe incidents affecting product security. The main requirements apply from 11 December 2027.
Plan scope and category classification, cybersecurity risk assessment, vulnerability handling, support and conformity evidence. Do not translate the requirements into a universal demand for a discrete TPM or a specific OTA implementation. See the CRA checklist for the permitted assessment routes and support-period conditions.
RED cybersecurity: applicable since August 2025
For radio equipment within the categories defined by Delegated Regulation 2022/30, the activated RED Article 3(3)(d), (e) and (f) requirements have applied since 1 August 2025. The scopes differ: network protection, personal-data/privacy protection for specified equipment, and protection against fraud for relevant monetary transactions.
EN 18031-1/-2/-3 can support the corresponding requirements, subject to the restrictions in their Official Journal citations. Standards are a voluntary route; the applicable legal essential requirements are mandatory. A radio-module certificate does not cover every aspect of the finished device. See EN 18031 and self-assessment.
AI Act: classify the intended use
Running inference locally does not establish AI Act compliance or automatically make the system high-risk. According to the Commission’s current application timeline, prohibitions and AI-literacy obligations began on 2 February 2025, GPAI-related obligations on 2 August 2025, and general application on 2 August 2026. Following the AI Omnibus changes, the high-risk Annex III rules apply from 2 December 2027 and regulated-product high-risk rules from 2 August 2028, subject to the relevant scope and transition provisions.
Identify whether you are a provider, deployer, importer or distributor, then map the obligations for the intended use. An industrial anomaly detector and a safety component can require different treatment. Medical-device and machinery rules may also be relevant independently of these dates.
ESPR and the Digital Product Passport
The Ecodesign for Sustainable Products Regulation establishes a framework for product-specific requirements. A Digital Product Passport is not automatically mandatory for every electronic product in 2026. Requirements and timing follow the applicable product-group measures and transitional arrangements.
Track your product group, material and repair information, and supplier data needed for the eventual applicable measure. Distinguish future preparation from a requirement already applying to the exact product.
NIS2 and the supply chain
NIS2 concerns entities within its sector, size and other scope conditions, implemented through national legislation. It is not a CE certificate for a chip or device. Customers covered by NIS2 may request supplier security evidence, but that does not make every hardware manufacturer an essential entity.
The EU Chips Act addresses semiconductor capacity and ecosystem policy; it does not impose a general CE obligation to use only EU-made silicon. Export controls and sanctions need their own transaction and technology assessment.
Build a product-specific compliance matrix
For each rule, record scope rationale, responsible organisation, application date, required evidence and assessment route. Tie this matrix to the exact hardware/firmware version. Revisit it after changes to intended use, connectivity or architecture, and before placing new units on the market.
CE, CRA and RED roadmap · EU compliance services · Discuss your roadmap
Frequently asked questions
Does every electronic product need a Digital Product Passport in 2026?
No. ESPR is a framework; product-specific measures establish applicable requirements and dates. Check the measure for the product group.
Are all AI Act high-risk rules already applicable?
No. The Commission’s current timeline distinguishes general application from high-risk Annex III rules on 2 December 2027 and regulated-product high-risk rules on 2 August 2028, with scope and transition conditions.
Is NIS2 a product certification?
No. NIS2 applies to covered entities through national legislation. It is separate from CE product conformity, although supply-chain security evidence may be requested.
Did CRA reporting wait until December 2027?
No. Article 14 reporting for actively exploited vulnerabilities and severe product-security incidents has applied since 11 September 2026.
Primary sources
Technical and regulatory references checked on 1 October 2026.
Related guides inEU Compliance & CE Marking
Explore all →EU Electronics Compliance: CE, CRA & RED
A product-specific CE roadmap for electronics: applicable legislation, evidence, assessment routes, RED cybersecurity and CRA responsibilities.
EU CRA Hardware Compliance Checklist
A risk-based CRA checklist for hardware: scope, product category, security requirements, SBOM, support period, reporting and conformity evidence.
CRA Vulnerability Reporting: Step-by-Step Guide
CRA Article 14 reporting in force since 11 September 2026: scope, 24/72-hour awareness deadlines, final reports, SRP and operational preparation.
EN 18031 Compliance: What "Self-Assessment" Actually Means for Connected Hardware
What EN 18031 self-assessment actually requires under Module A — and where the documented compliance gaps most often appear for connected hardware.
RED Delegated Act & EN 18031: Hardware Requirements
How the RED Delegated Act and EN 18031 define mandatory cybersecurity for radio equipment from August 2025 — with gaps that cannot be fixed in firmware.