Regulations / European Union
Regulations by jurisdiction
European Union: what binds a connected product
The EU has the densest connected-product rulebook anywhere: a horizontal cybersecurity law, a radio-equipment layer, a data-protection regime, and operator obligations that flow down to suppliers. Most of it is market-access law, meaning CE marking depends on it.
| Framework | Applies when | Who demands it | In force | Penalties |
|---|---|---|---|---|
| EU Cyber Resilience Act | Any product with digital elements placed on the EU market, consumer or industrial | Market access, mandatory (CE marking) | In force 10 Dec 2024; reporting duties from 11 Sep 2026; main obligations from 11 Dec 2027 | Up to EUR 15M or 2.5% of global turnover |
| ETSI EN 303 645 | Consumer IoT; referenced by market-access rules in the EU, UK, Singapore, Australia and Finland | Product baseline behind several national regimes; not itself enforceable | v3.1.3 current | None; penalties come from the law that cites it |
| EU Radio Equipment Directive, cybersecurity delegated act | Radio equipment sold in the EU that connects to the internet, processes personal data, or handles payments | Market access, mandatory (CE marking) | Applies from 1 Aug 2025 | National; typically withdrawal from market and fines |
| GDPR | Any product handling personal data of people in the EU, wherever the maker sits | Legal compliance; data-protection authorities | Applies since 25 May 2018 | Up to EUR 20M or 4% of global turnover |
| EU NIS2 Directive | Operators in essential and important sectors in the EU; obligations flow down to their suppliers | Operator obligations, passed to component suppliers by contract | Transposition deadline 17 Oct 2024 | Essential entities up to EUR 10M or 2%; important entities up to EUR 7M or 1.4% |
EU Cyber Resilience Act
Security by design, SBOMs, 24-hour reporting of actively exploited vulnerabilities to the CSIRT and ENISA, coordinated disclosure, post-market monitoring for the support period.
ETSI EN 303 645
13 outcome-focused provisions: credentials, updates, secure storage, communication, attack surface, resilience, telemetry, personal data, and more.
EU Radio Equipment Directive, cybersecurity delegated act
Network protection, personal-data and privacy protection, fraud protection, via harmonised standard EN 18031.
GDPR
Data minimisation, lawful basis and consent, right to erasure, data protection by design, stricter rules for health and biometric data (Article 9).
EU NIS2 Directive
Risk management, supply-chain security, incident reporting within 24 hours (early warning) and 72 hours (notification) for operators.
Comparisons
- CRA vs ETSI EN 303 645 — One is the law, the other is the checklist most conformity assessments will use to show the law is met.
- CRA vs NIS2 — The CRA binds the product; NIS2 binds the operator who deploys it.
- CRA vs RED delegated act — The RED delegated act arrived first, in August 2025, and covers only radio equipment; the CRA arrives in stages through 2027 and covers everything with digital elements.
- GDPR vs CRA — GDPR governs the data a device collects; the CRA governs how securely the device is built.
Check your own product
The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.
← All jurisdictions