Sectors and use cases

Importing smart home products from China: RED and 2025 cybersecurity

Since 1 August 2025, every smart home device sold in the European Union must meet three cybersecurity requirements added to the RED directive, on top of the rules already in force on electrical safety, radio waves and electromagnetic compatibility. This article details this framework, the standard that can prove compliance with it, the timeline of the Cyber Resilience Act that will take over, and the points to check with the factory before placing an order.

Updated September 26, 2026

What counts as a smart home device under European regulation?

Under European law, a smart home device is a piece of radio equipment as soon as it transmits or receives waves to communicate with another device or a network. A remotely controllable plug, a surveillance camera, a motion or smoke sensor, a thermostat, a bulb or a robot vacuum connected via Wi-Fi, Bluetooth, Zigbee or Thread all fall under this definition, whatever their household function.

This classification triggers a precise framework: the product must comply with the RED directive before it is placed on the European market, and since 1 August 2025, an additional layer of cybersecurity requirements applies to consumer connected devices.

  • Remotely controllable plugs and power strips
  • Surveillance cameras and connected doorbells
  • Motion, opening, smoke or air-quality sensors
  • Home robots: vacuums, mowers, connected kitchen assistants
  • Connected lighting, thermostats and thermostatic radiator valves
  • Baby monitors and sleep trackers
  • Connected locks and intercoms

The RED directive has governed these products since 2016

The RED directive, Radio Equipment Directive 2014/53/EU, governs the placing on the market of any radio equipment in the European Union. It has applied since 13 June 2016 and replaced the R&TTE directive 1999/5/EC. Its original objective covers three areas: user safety and health, efficient use of the radio spectrum, and the device's electromagnetic compatibility.

Even before cybersecurity, a connected device must already meet these basic requirements to carry CE marking. The manufacturer, or the importer acting as one when no manufacturer established in the Union takes on that role, must produce an EU declaration of conformity and a technical file available to the authorities.

  • CE marking affixed to the product and, where size allows, on the packaging
  • EU declaration of conformity drawn up by the manufacturer or its agent
  • Technical file kept and available on request from the authorities
  • User manual and contact details of the manufacturer or importer

Read next CE Marking on Imports: What It Covers and How to Verify

The cybersecurity requirements mandatory since 1 August 2025

Delegated regulation (EU) 2022/30 adds three essential requirements to article 3(3), points d, e and f of the RED directive. They entered into application on 1 August 2025 for consumer connected devices, wearables, connected toys and baby monitors.

These three requirements add to, without replacing, the RED's existing framework. A product that does not meet them cannot carry CE marking, even if it otherwise satisfies the usual radio and electrical requirements.

  • Point d: the equipment must not harm the network or disrupt its operation
  • Point e: the equipment must protect the user's personal data and privacy
  • Point f: equipment that processes monetary transactions must provide safeguards against fraud

Read next GPSR Regulation 2023/988: Importer Obligations

The EN 18031 standard, the most direct path to compliance

The EN 18031 series of harmonised standards, published in the Official Journal of the European Union on 30 January 2025, breaks the three requirements above down into verifiable technical criteria: EN 18031-1 for the network, EN 18031-2 for data and privacy, EN 18031-3 for anti-fraud safeguards. Since 1 August 2025, complying with it creates a presumption of conformity with delegated regulation 2022/30.

In most cases, meeting EN 18031 allows for self-declaration: the manufacturer carries out the assessment itself, compiles the technical file and signs the EU declaration of conformity, with no notified body involved. A notified body becomes necessary if the product departs from a restrictive clause of the standard, for example if it allows no password to be set: the automatic presumption then falls away, and an EU type-examination becomes required.

  • EN 18031-1: access management, passwords, firmware updates, protection against denial of service
  • EN 18031-2: encryption of personal data, user account management, privacy by default
  • EN 18031-3: only for equipment that processes payments or monetary transactions

Read next Product technical documentation: what the importer must hold · Product specification: the tech pack the factory follows

EMC, electrical safety: the texts that apply alongside

For a connected device with a radio function, Wi-Fi or Bluetooth for example, electromagnetic compatibility is covered by the RED itself. For an electrical device with no radio function, it is the EMC directive 2014/30/EU that applies separately for emissions and immunity.

A mains-powered connected device also remains subject to the low voltage directive 2014/35/EU for electrical risks, as well as the RoHS and WEEE directives on hazardous substances and end-of-life, like any electronic product. These texts add to the RED, they do not replace it.

In France, ANFR monitors the radio equipment market: a fine capped at 1,500 euros for an individual, 7,500 euros for a company, plus possible criminal penalties. The Cyber Resilience Act provides for a separate regime, up to 15 million euros or 2.5% of worldwide turnover.

Read next Importing electronics from China: LVD, EMC, RoHS, WEEE

The Cyber Resilience Act: what changes in 2026 and 2027

The Cyber Resilience Act, regulation (EU) 2024/2847 on products with digital elements, entered into force on 10 December 2024. Two milestones matter for smart home sourcing: from 11 September 2026, an obligation to report actively exploited vulnerabilities and serious incidents to ENISA or the national CSIRT; from 11 December 2027, full application of the essential requirements, conformity assessment, CE marking and the CRA's technical documentation.

Delegated regulation 2022/30, which currently carries RED cybersecurity, will be repealed on 11 December 2027 and absorbed into the CRA. A product already placed on the market before that date stays under the RED regime as long as it does not undergo a substantial modification after 11 December 2027; the reporting obligation, on the other hand, applies from 11 September 2026, regardless of the date it was placed on the market.

  • 10 December 2024: Cyber Resilience Act enters into force
  • 1 August 2025: RED cybersecurity requirements and EN 18031 presumption fully applicable
  • 11 September 2026: obligation to report vulnerabilities and serious incidents
  • 11 December 2027: full application of the CRA, repeal of the RED cybersecurity regime

Choosing the factory and organising tests before export

A factory that already produces connected devices for European brands has normally had its items tested by an accredited laboratory and holds EN 18031 reports that can be reused or adapted. A factory discovering these requirements at the time of your order carries a higher risk of delay and non-compliance.

The firmware update policy deserves particular attention: protecting the network assumes the device can receive security patches after it is placed on the market. Have the factory state in writing the length of time it commits to providing these updates.

  • EN 18031 test report on the areas applicable to the product (network, data, fraud)
  • Written firmware update policy and support duration
  • Radio technical sheet: frequencies used, transmission power, protocol
  • Draft EU declaration of conformity before starting series production
  • CE marking correctly affixed to the product and to the packaging

Read next Golden sample: the reference sample that settles disputes · Verify a Chinese Factory: License, Capital, and Visit

What Sorva does for you

Sorva is a brokerage and trading house between Europe and China, with a Chinese-speaking team in Guangzhou and an office in Paris. Our regulatory compliance study checks the product's RED classification, the applicable EN 18031 presumption and the texts that apply alongside it, EMC, low voltage, RoHS, before any production commitment. A technical product file then gathers the documents expected by the authorities: test reports, declaration of conformity, radio sheet.

In most cases you pay no fees on the goods themselves: you open a file, we negotiate the purchase for you with the factory and we take a commission on their ex-works value. The compliance study and the technical file remain separate services, useful as early as supplier selection.

What to remember

Remember that since 1 August 2025, a smart home device must meet, on top of the standard RED directive, three cybersecurity requirements that the EN 18031 standard can demonstrate by self-declaration in most cases. First thing to do: ask the factory for its EN 18031 test reports and its firmware update policy before confirming the order.

Let's talk

Let's talk about your project

Frequently asked questions

01What is the RED directive?
The RED directive, Radio Equipment Directive 2014/53/EU, governs the placing on the European market of any radio equipment. It covers user safety and health, efficient use of the radio spectrum, and electromagnetic compatibility. It has applied since 13 June 2016 and replaces the former R&TTE directive.
02Which smart home devices are covered by the cybersecurity requirements since 2025?
In principle all consumer connected devices fall under these requirements as soon as they communicate by radio: cameras, sensors, remotely controllable plugs, home robots, baby monitors and wearables. Delegated regulation 2022/30 names these categories explicitly.
03Since when have the RED directive's cybersecurity requirements been mandatory?
Since 1 August 2025. That is also the date from which the harmonised standard EN 18031, published in the Official Journal on 30 January 2025, creates a presumption of conformity with these requirements when correctly applied by the manufacturer.
04Is a notified body required to import a smart home device?
Not necessarily. When the product fully meets the EN 18031 standard, the manufacturer can carry out a self-declaration of conformity with no notified body involved. Involving a notified body becomes mandatory if the product departs from a restrictive clause of the standard, for example if it allows no password to be set.
05What is the difference between the RED directive and the Cyber Resilience Act?
The RED governs radio devices, cybersecurity included since August 2025 via delegated regulation 2022/30. The Cyber Resilience Act, in force since 10 December 2024, extends this framework to any product with digital elements and will become fully applicable on 11 December 2027, absorbing the RED's cybersecurity component at that point.
06Does electromagnetic compatibility also apply to smart home devices?
Yes, but the applicable text depends on whether the device has a radio function. For a radio device, the RED itself covers electromagnetic compatibility. For an electrical device with no radio function, the EMC directive 2014/30/EU applies separately, in addition to the low voltage directive for electrical risks.
07What documents must the Chinese factory provide to prove RED compliance?
A complete file includes the EN 18031 test report, the radio technical sheet, a draft EU declaration of conformity, and a written firmware update policy. These documents should be requested before production, not after receipt.