Skip to content
Inovasense
EU RegulationCRAAI ActREDEcodesignDigital Product PassportNIS2Hardware ComplianceCE Marking

EU Hardware Legislation 2026: Complete Guide

4 min read
EU Hardware Legislation 2026: Complete Guide

EU hardware compliance starts with the product’s intended use, connectivity, market role and applicable sector rules. A wireless sensor, a medical device and a factory operator do not share one universal regulatory checklist. The following timeline distinguishes product requirements from obligations on organisations and AI operators.

CRA: reporting now, product requirements later

The Cyber Resilience Act applies within its Article 2 scope, including products with a direct or indirect data connection, with specified sector exclusions. Article 14 reporting has applied since 11 September 2026 to actively exploited vulnerabilities and severe incidents affecting product security. The main requirements apply from 11 December 2027.

Plan scope and category classification, cybersecurity risk assessment, vulnerability handling, support and conformity evidence. Do not translate the requirements into a universal demand for a discrete TPM or a specific OTA implementation. See the CRA checklist for the permitted assessment routes and support-period conditions.

RED cybersecurity: applicable since August 2025

For radio equipment within the categories defined by Delegated Regulation 2022/30, the activated RED Article 3(3)(d), (e) and (f) requirements have applied since 1 August 2025. The scopes differ: network protection, personal-data/privacy protection for specified equipment, and protection against fraud for relevant monetary transactions.

EN 18031-1/-2/-3 can support the corresponding requirements, subject to the restrictions in their Official Journal citations. Standards are a voluntary route; the applicable legal essential requirements are mandatory. A radio-module certificate does not cover every aspect of the finished device. See EN 18031 and self-assessment.

AI Act: classify the intended use

Running inference locally does not establish AI Act compliance or automatically make the system high-risk. According to the Commission’s current application timeline, prohibitions and AI-literacy obligations began on 2 February 2025, GPAI-related obligations on 2 August 2025, and general application on 2 August 2026. Following the AI Omnibus changes, the high-risk Annex III rules apply from 2 December 2027 and regulated-product high-risk rules from 2 August 2028, subject to the relevant scope and transition provisions.

Identify whether you are a provider, deployer, importer or distributor, then map the obligations for the intended use. An industrial anomaly detector and a safety component can require different treatment. Medical-device and machinery rules may also be relevant independently of these dates.

ESPR and the Digital Product Passport

The Ecodesign for Sustainable Products Regulation establishes a framework for product-specific requirements. A Digital Product Passport is not automatically mandatory for every electronic product in 2026. Requirements and timing follow the applicable product-group measures and transitional arrangements.

Track your product group, material and repair information, and supplier data needed for the eventual applicable measure. Distinguish future preparation from a requirement already applying to the exact product.

NIS2 and the supply chain

NIS2 concerns entities within its sector, size and other scope conditions, implemented through national legislation. It is not a CE certificate for a chip or device. Customers covered by NIS2 may request supplier security evidence, but that does not make every hardware manufacturer an essential entity.

The EU Chips Act addresses semiconductor capacity and ecosystem policy; it does not impose a general CE obligation to use only EU-made silicon. Export controls and sanctions need their own transaction and technology assessment.

Build a product-specific compliance matrix

For each rule, record scope rationale, responsible organisation, application date, required evidence and assessment route. Tie this matrix to the exact hardware/firmware version. Revisit it after changes to intended use, connectivity or architecture, and before placing new units on the market.

CE, CRA and RED roadmap · EU compliance services · Discuss your roadmap

Frequently asked questions

Does every electronic product need a Digital Product Passport in 2026?

No. ESPR is a framework; product-specific measures establish applicable requirements and dates. Check the measure for the product group.

Are all AI Act high-risk rules already applicable?

No. The Commission’s current timeline distinguishes general application from high-risk Annex III rules on 2 December 2027 and regulated-product high-risk rules on 2 August 2028, with scope and transition conditions.

Is NIS2 a product certification?

No. NIS2 applies to covered entities through national legislation. It is separate from CE product conformity, although supply-chain security evidence may be requested.

Did CRA reporting wait until December 2027?

No. Article 14 reporting for actively exploited vulnerabilities and severe product-security incidents has applied since 11 September 2026.

Primary sources

Technical and regulatory references checked on 1 October 2026.

Related guides inEU Compliance & CE Marking

Explore all →