Regulations / European Union

Regulations by jurisdiction

European Union: what binds a connected product

The EU has the densest connected-product rulebook anywhere: a horizontal cybersecurity law, a radio-equipment layer, a data-protection regime, and operator obligations that flow down to suppliers. Most of it is market-access law, meaning CE marking depends on it.

FrameworkApplies whenWho demands itIn forcePenalties
EU Cyber Resilience ActAny product with digital elements placed on the EU market, consumer or industrialMarket access, mandatory (CE marking)In force 10 Dec 2024; reporting duties from 11 Sep 2026; main obligations from 11 Dec 2027Up to EUR 15M or 2.5% of global turnover
ETSI EN 303 645Consumer IoT; referenced by market-access rules in the EU, UK, Singapore, Australia and FinlandProduct baseline behind several national regimes; not itself enforceablev3.1.3 currentNone; penalties come from the law that cites it
EU Radio Equipment Directive, cybersecurity delegated actRadio equipment sold in the EU that connects to the internet, processes personal data, or handles paymentsMarket access, mandatory (CE marking)Applies from 1 Aug 2025National; typically withdrawal from market and fines
GDPRAny product handling personal data of people in the EU, wherever the maker sitsLegal compliance; data-protection authoritiesApplies since 25 May 2018Up to EUR 20M or 4% of global turnover
EU NIS2 DirectiveOperators in essential and important sectors in the EU; obligations flow down to their suppliersOperator obligations, passed to component suppliers by contractTransposition deadline 17 Oct 2024Essential entities up to EUR 10M or 2%; important entities up to EUR 7M or 1.4%

EU Cyber Resilience Act

Security by design, SBOMs, 24-hour reporting of actively exploited vulnerabilities to the CSIRT and ENISA, coordinated disclosure, post-market monitoring for the support period.

ETSI EN 303 645

13 outcome-focused provisions: credentials, updates, secure storage, communication, attack surface, resilience, telemetry, personal data, and more.

EU Radio Equipment Directive, cybersecurity delegated act

Network protection, personal-data and privacy protection, fraud protection, via harmonised standard EN 18031.

GDPR

Data minimisation, lawful basis and consent, right to erasure, data protection by design, stricter rules for health and biometric data (Article 9).

EU NIS2 Directive

Risk management, supply-chain security, incident reporting within 24 hours (early warning) and 72 hours (notification) for operators.

Comparisons

Check your own product

The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.

← All jurisdictions

© 2026 Yoel Frischoff / TheRoad. All rights reserved. · About the Book · Press · Teaching · Glossary · References · Privacy · Terms · Accessibility