
Importing smart home products from China: RED and 2025 cybersecurity
Since 1 August 2025, every smart home device sold in the European Union must meet three cybersecurity requirements added to the RED directive, on top of the rules already in force on electrical safety, radio waves and electromagnetic compatibility. This article details this framework, the standard that can prove compliance with it, the timeline of the Cyber Resilience Act that will take over, and the points to check with the factory before placing an order.
What counts as a smart home device under European regulation?
Under European law, a smart home device is a piece of radio equipment as soon as it transmits or receives waves to communicate with another device or a network. A remotely controllable plug, a surveillance camera, a motion or smoke sensor, a thermostat, a bulb or a robot vacuum connected via Wi-Fi, Bluetooth, Zigbee or Thread all fall under this definition, whatever their household function.
This classification triggers a precise framework: the product must comply with the RED directive before it is placed on the European market, and since 1 August 2025, an additional layer of cybersecurity requirements applies to consumer connected devices.
- Remotely controllable plugs and power strips
- Surveillance cameras and connected doorbells
- Motion, opening, smoke or air-quality sensors
- Home robots: vacuums, mowers, connected kitchen assistants
- Connected lighting, thermostats and thermostatic radiator valves
- Baby monitors and sleep trackers
- Connected locks and intercoms
The RED directive has governed these products since 2016
The RED directive, Radio Equipment Directive 2014/53/EU, governs the placing on the market of any radio equipment in the European Union. It has applied since 13 June 2016 and replaced the R&TTE directive 1999/5/EC. Its original objective covers three areas: user safety and health, efficient use of the radio spectrum, and the device's electromagnetic compatibility.
Even before cybersecurity, a connected device must already meet these basic requirements to carry CE marking. The manufacturer, or the importer acting as one when no manufacturer established in the Union takes on that role, must produce an EU declaration of conformity and a technical file available to the authorities.
- CE marking affixed to the product and, where size allows, on the packaging
- EU declaration of conformity drawn up by the manufacturer or its agent
- Technical file kept and available on request from the authorities
- User manual and contact details of the manufacturer or importer
Read next CE Marking on Imports: What It Covers and How to Verify
The cybersecurity requirements mandatory since 1 August 2025
Delegated regulation (EU) 2022/30 adds three essential requirements to article 3(3), points d, e and f of the RED directive. They entered into application on 1 August 2025 for consumer connected devices, wearables, connected toys and baby monitors.
These three requirements add to, without replacing, the RED's existing framework. A product that does not meet them cannot carry CE marking, even if it otherwise satisfies the usual radio and electrical requirements.
- Point d: the equipment must not harm the network or disrupt its operation
- Point e: the equipment must protect the user's personal data and privacy
- Point f: equipment that processes monetary transactions must provide safeguards against fraud
The EN 18031 standard, the most direct path to compliance
The EN 18031 series of harmonised standards, published in the Official Journal of the European Union on 30 January 2025, breaks the three requirements above down into verifiable technical criteria: EN 18031-1 for the network, EN 18031-2 for data and privacy, EN 18031-3 for anti-fraud safeguards. Since 1 August 2025, complying with it creates a presumption of conformity with delegated regulation 2022/30.
In most cases, meeting EN 18031 allows for self-declaration: the manufacturer carries out the assessment itself, compiles the technical file and signs the EU declaration of conformity, with no notified body involved. A notified body becomes necessary if the product departs from a restrictive clause of the standard, for example if it allows no password to be set: the automatic presumption then falls away, and an EU type-examination becomes required.
- EN 18031-1: access management, passwords, firmware updates, protection against denial of service
- EN 18031-2: encryption of personal data, user account management, privacy by default
- EN 18031-3: only for equipment that processes payments or monetary transactions
Read next Product technical documentation: what the importer must hold · Product specification: the tech pack the factory follows
EMC, electrical safety: the texts that apply alongside
For a connected device with a radio function, Wi-Fi or Bluetooth for example, electromagnetic compatibility is covered by the RED itself. For an electrical device with no radio function, it is the EMC directive 2014/30/EU that applies separately for emissions and immunity.
A mains-powered connected device also remains subject to the low voltage directive 2014/35/EU for electrical risks, as well as the RoHS and WEEE directives on hazardous substances and end-of-life, like any electronic product. These texts add to the RED, they do not replace it.
In France, ANFR monitors the radio equipment market: a fine capped at 1,500 euros for an individual, 7,500 euros for a company, plus possible criminal penalties. The Cyber Resilience Act provides for a separate regime, up to 15 million euros or 2.5% of worldwide turnover.
Read next Importing electronics from China: LVD, EMC, RoHS, WEEE
The Cyber Resilience Act: what changes in 2026 and 2027
The Cyber Resilience Act, regulation (EU) 2024/2847 on products with digital elements, entered into force on 10 December 2024. Two milestones matter for smart home sourcing: from 11 September 2026, an obligation to report actively exploited vulnerabilities and serious incidents to ENISA or the national CSIRT; from 11 December 2027, full application of the essential requirements, conformity assessment, CE marking and the CRA's technical documentation.
Delegated regulation 2022/30, which currently carries RED cybersecurity, will be repealed on 11 December 2027 and absorbed into the CRA. A product already placed on the market before that date stays under the RED regime as long as it does not undergo a substantial modification after 11 December 2027; the reporting obligation, on the other hand, applies from 11 September 2026, regardless of the date it was placed on the market.
- 10 December 2024: Cyber Resilience Act enters into force
- 1 August 2025: RED cybersecurity requirements and EN 18031 presumption fully applicable
- 11 September 2026: obligation to report vulnerabilities and serious incidents
- 11 December 2027: full application of the CRA, repeal of the RED cybersecurity regime
Choosing the factory and organising tests before export
A factory that already produces connected devices for European brands has normally had its items tested by an accredited laboratory and holds EN 18031 reports that can be reused or adapted. A factory discovering these requirements at the time of your order carries a higher risk of delay and non-compliance.
The firmware update policy deserves particular attention: protecting the network assumes the device can receive security patches after it is placed on the market. Have the factory state in writing the length of time it commits to providing these updates.
- EN 18031 test report on the areas applicable to the product (network, data, fraud)
- Written firmware update policy and support duration
- Radio technical sheet: frequencies used, transmission power, protocol
- Draft EU declaration of conformity before starting series production
- CE marking correctly affixed to the product and to the packaging
Read next Golden sample: the reference sample that settles disputes · Verify a Chinese Factory: License, Capital, and Visit
What Sorva does for you
Sorva is a brokerage and trading house between Europe and China, with a Chinese-speaking team in Guangzhou and an office in Paris. Our regulatory compliance study checks the product's RED classification, the applicable EN 18031 presumption and the texts that apply alongside it, EMC, low voltage, RoHS, before any production commitment. A technical product file then gathers the documents expected by the authorities: test reports, declaration of conformity, radio sheet.
In most cases you pay no fees on the goods themselves: you open a file, we negotiate the purchase for you with the factory and we take a commission on their ex-works value. The compliance study and the technical file remain separate services, useful as early as supplier selection.
Remember that since 1 August 2025, a smart home device must meet, on top of the standard RED directive, three cybersecurity requirements that the EN 18031 standard can demonstrate by self-declaration in most cases. First thing to do: ask the factory for its EN 18031 test reports and its firmware update policy before confirming the order.
Let's talk about your project
Frequently asked questions
01What is the RED directive?
02Which smart home devices are covered by the cybersecurity requirements since 2025?
03Since when have the RED directive's cybersecurity requirements been mandatory?
04Is a notified body required to import a smart home device?
05What is the difference between the RED directive and the Cyber Resilience Act?
06Does electromagnetic compatibility also apply to smart home devices?
07What documents must the Chinese factory provide to prove RED compliance?
The service that matches
- CommissionVolume commissionYou open a file, we find and negotiate the factory. We are paid only on the goods you order.€150file opening feeView service
- Engineering studiesRegulatory compliance studyWhat your product must meet in its destination country, written up and sourced, before the first order.€390per product and destination countryView service
- Engineering studiesProduct technical fileWhat must be built, what must be tested, what must be labelled, what must be signed.€1,290per productView service