Comparison
CRA vs RED: which one applies to your product?
Reviewed August 2026 against Regulation (EU) 2024/2847, OJ L, 12.12.2024.
Short answer: our verified CRA text does not settle how the Cyber Resilience Act relates to the Radio Equipment Directive. If your product is radio equipment, treat the two as separate obligations until you get specific advice.
What each one regulates
The CRA applies to a product with digital elements: a software or hardware product and its remote data processing solutions, made available on the market where its intended or reasonably foreseeable use includes a data connection to a device or network.
“a software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”
Directive 2014/53/EU (the Radio Equipment Directive, RED) sets essential requirements for equipment that intentionally transmits or receives radio waves: health and safety, electromagnetic compatibility, and efficient use of the radio spectrum. A separate delegated act made under RED also adds cybersecurity-related essential requirements for certain internet-connected radio equipment. Full text: Directive 2014/53/EU, OJ L 153, 22.5.2014 (RED).
Do they overlap, and which wins
The CRA names a closed list of other Union acts that take precedence over it for specific product categories: medical devices, in-vitro diagnostics, aviation-certified equipment, agricultural and two- or three-wheel vehicle approvals, marine equipment and road vehicle type-approval.
“This Regulation does not apply to products with digital elements to which the following Union legal acts apply:”
The quote above does not enumerate every act on that list, and no other entry in our verified corpus names the Radio Equipment Directive. So this page cannot tell you, from CRA text we have verified, whether radio equipment sits inside or outside that exclusion, or how the CRA’s essential cybersecurity requirements interact with RED’s own cybersecurity-related delegated act for radio equipment. The Regulation does not settle this for us here: do not assume either that RED displaces the CRA or that the two simply apply side by side without overlap.
This is a narrower gap than the GDPR, NIS2 or DORA comparisons on this site: for those regimes, the closed exclusion list our engine already applies (medical devices, in-vitro diagnostics, aviation, agricultural and two- or three-wheel vehicles, marine equipment, road vehicles) is enough to say plainly that they are not carve-outs. For RED, we do not have that same confidence either way, because our verified corpus simply does not reach the question. Treat that as an open item to check directly with a notified body or a lawyer, not as evidence for either outcome.
What this means in practice
- If your product is radio equipment, RED obligations for health and safety, electromagnetic compatibility and efficient use of the radio spectrum apply to you regardless of anything the CRA asks.
- Whether the CRA’s essential cybersecurity requirements replace, duplicate, or simply sit next to any cybersecurity-related requirements that already reach your radio equipment through RED is not something our verified CRA text settles; do not assume either answer.
- Run the Cybiq check for your CRA status on its own merits, does your product have a data connection, is it made available commercially, and so on, and treat any RED conformity work you already hold as a separate track for now.
- Ask a notified body or a lawyer familiar with both regimes before assuming your RED paperwork covers your CRA duties, or the other way round.
- Cybiq checks the CRA only: it does not assess your product’s compliance with RED, and this page does not resolve the boundary between them.
Orientation, not legal advice. Quoted spans come from Regulation (EU) 2024/2847 as published in the Official Journal and are re-verified against the live text by automated tests. Verify before relying on any item; for a binding assessment consult a qualified lawyer.