A Wi-Fi digital photo frame sold in the EU can sit inside an unusual compliance window. Cybersecurity requirements activated under the Radio Equipment Directive have applied to covered radio equipment since 1 August 2025. A 2026 repeal does not switch them off immediately: it takes effect on 11 December 2027, when the Cyber Resilience Act's main obligations begin to apply.
For importers, private-label brands and OEM project teams, the question is therefore not “Was RED cybersecurity repealed?” It is “Which rules apply to this exact model on the date it is placed on the EU market, and what evidence supports that conclusion?” This guide turns that question into a procurement handover. It is not legal advice, a conformity assessment or a substitute for an EU authorised representative, notified body, laboratory or qualified regulatory adviser.
What changed in 2026—and what did not?
Commission Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027. The European Commission explains that the timing avoids overlap with the Cyber Resilience Act. Until then, the RED cybersecurity requirements continue to matter for covered radio equipment placed on the market during the period beginning 1 August 2025 and ending 10 December 2027.
This distinction is commercially important. A buyer cannot treat a future repeal date as permission to remove security evidence from a 2026 or 2027 launch file. Nor should a team build a one-time RED folder and ignore CRA readiness. Record the planned placing-on-the-market date, the affected model configuration and the legal basis used by the responsible EU economic operator.
Why can a digital photo frame fall within the RED cybersecurity scope?
A digital frame with Wi-Fi or Bluetooth is radio equipment, but that fact alone does not answer every requirement. Delegated Regulation (EU) 2022/30 applies particular RED Article 3(3) requirements to defined categories. Article 3(3)(d) concerns protection of the network and its functioning and misuse of network resources. Article 3(3)(e) concerns safeguards for personal data and privacy in specified radio equipment. Article 3(3)(f) concerns fraud protection for internet-connected radio equipment that enables transfers of money or monetary value.
A typical connected photo frame may communicate over the internet and process account identifiers, uploaded images, device identifiers or usage data. Those facts deserve a documented assessment. Payment capability is a separate question; do not assume Article 3(3)(f) applies merely because a retail transaction bought the device. Map what the shipped product and its related app or cloud service actually do, then have the responsible specialist determine scope.
Start with a model-and-service map
List the exact hardware model, wireless module, firmware build, mobile app version, cloud platform, update service, account model and EU brand. Add every route by which the product connects: Wi-Fi bands, Bluetooth pairing, local USB or memory card, application programming interfaces and remote administration. Mark which features are enabled in the EU configuration rather than copied from a global datasheet.
This map prevents two common errors. The first is testing a radio module while ignoring the finished product's account and update behaviour. The second is using an earlier report after changing firmware, module, antenna, app provider or cloud endpoint. A shared enclosure does not make two connected-product configurations identical. Give each approved combination a versioned identity in the purchase order and technical file.

Which buyer questions reveal the real search intent?
Commercial search intent usually appears as operational questions: Does EN 18031 apply to my Wi-Fi frame? Is self-assessment available? Do I need a notified body? What changed after the 2026 repeal? Can an old test report cover a new model? Which documents should the OEM provide? These are not requests for a broad cybersecurity definition. They are attempts to unblock a launch, a marketplace listing, a technical-file review or a purchase-order decision.
A useful article must therefore distinguish legal scope, conformity route, laboratory evidence and supplier handover. Google Search Central recommends helpful, people-first content that adds first-hand value rather than producing pages for every query variation. The value here is the decision sequence: define the product, identify the applicable date, validate the evidence path, lock the configuration and preserve an auditable change record.
How should buyers use the EN 18031 standards?
Commission Implementing Decision (EU) 2025/138 listed harmonised standards in the EN 18031 series in support of RED cybersecurity requirements, with restrictions described in the decision. A harmonised standard can provide a route to presumption of conformity only within its cited scope and conditions. It is not a decorative certificate and it should not be named in marketing merely because a laboratory recognises the number.
Ask the responsible conformity specialist which part or parts relate to the product and which clauses are applicable. Request a standards matrix showing requirement, product feature, evidence, result, report reference and any non-applicable rationale. If a restriction in the Official Journal affects a feature, obtain a documented route rather than assuming the standard automatically gives full presumption of conformity.
Does the buyer need a notified body?
The answer depends on the conformity assessment route, the standards applied and whether the applicable harmonised standards are used fully and correctly. A buyer should not infer the answer from a supplier's statement that the module is “CE approved.” CE marking applies to the finished radio equipment under the manufacturer's responsibility, and a radio-module report is only one input to the complete product assessment.
Before approving the order, ask an EU regulatory professional to confirm the route for the exact configuration. Record whether assessment is based on internal production control, an EU-type examination route or another permitted module, and why. Where a notified body participates, keep its role and documents clear. Do not portray voluntary laboratory review as notified-body involvement.
Build cybersecurity requirements into the product brief
Translate the legal and standards assessment into engineering requirements that can be checked. Typical topics may include secure communications, authentication, protection of stored credentials, least-privilege access, update authenticity, vulnerability handling, protection of personal data and resistance to misuse of network resources. The applicable list must come from the assessment of the real product, not from this article.
For every requirement, name an owner and evidence. The owner may be the OEM, firmware developer, app provider, cloud operator or private-label brand. Evidence might be a design description, configuration record, test report, code or dependency record, access-control demonstration, update workflow or support procedure. A statement that the product uses “bank-grade encryption” is neither a controlled requirement nor useful evidence.
Control default settings and first-use behaviour
A sample review should begin before the user adds photographs. Observe pairing, account creation, password or authentication behaviour, network setup, permission prompts, update handling and factory reset. Confirm whether unnecessary services are enabled, whether the same credentials appear across units and whether sensitive information remains after reset or account transfer.
Use production-intent hardware and a clean account. Record firmware, app and backend versions during the review. Test ordinary failures such as interrupted setup, expired authorisation, lost connectivity and a refused update. The purpose is not to invent a penetration test; it is to prove that the agreed user journey and controls exist in the version the buyer plans to ship.
Ask for evidence across the whole service chain
A connected frame can depend on more than the factory. The mobile app may be maintained by one developer, device messaging by a platform provider and image storage by another service. Ask who controls each component, who receives vulnerability notices, who can issue an update and what happens if a vendor relationship ends. The EU manufacturer or importer needs facts that remain available after the first shipment.
The handover can include architecture and data-flow diagrams, software and firmware version records, wireless module documentation, applicable test reports, risk assessment, standards matrix, update policy, vulnerability contact, dependency inventory where appropriate and evidence supporting the EU declaration of conformity. The exact technical documentation is a regulatory decision, but the commercial contract should make delivery and maintenance responsibilities explicit.
Separate a test report from a market-ready technical file
A laboratory report answers defined questions about a tested sample. It does not prove that production units use the same components, code and settings; it does not assign importer responsibilities; and it does not automatically keep the product compliant after a cloud change. Buyers should connect the report to a configuration list, approved sample, declaration, labelling, instructions and production-control record.
Check names and model identifiers across all documents. Confirm the applicant, manufacturer, brand, model family, hardware revision, module, firmware and report sample. Resolve small differences before mass production. A marketplace reviewer or authority should not have to guess that two similar model strings refer to the same device.
Make change control part of the purchase order
Require written notice before changes to the wireless module, antenna, processor, memory, firmware, bootloader, cryptographic library, app, cloud provider, data flow, update server or security settings. State that shipment approval depends on reviewing the effect of the change. Keep a decision showing whether the existing assessment remains valid, needs an addendum or requires new testing.
Apply the same discipline to component substitutions made during shortages. “Equivalent” in price or footprint does not prove equivalent radio or security behaviour. The golden sample should be paired with a digital configuration record because visual inspection cannot identify every connected-product change.

Prepare now for the CRA transition
The 2026 repeal creates a handover point, not a cybersecurity holiday. The Commission states that the RED delegated regulation will be repealed when the CRA's main obligations apply on 11 December 2027. A product roadmap that spans that date needs specialist review of CRA scope, obligations, support period, vulnerability handling, reporting dates and conformity evidence.
Keep RED and CRA workstreams distinguishable while reusing sound engineering evidence where appropriate. Do not rename a RED folder “CRA compliant.” Ask which requirements, documents and processes need expansion. Procurement should especially identify software support, update ownership and vulnerability response commitments that must survive after the supplier has delivered the hardware.
Buyer approval checklist
- EU model, brand and placing-on-the-market date recorded
- Hardware, module, antenna, firmware, app and cloud versions mapped
- RED Article 3(3)(d), (e) and (f) scope reviewed for actual features
- Applicable harmonised standards and restrictions assessed
- Conformity route and notified-body need confirmed by a responsible specialist
- Cybersecurity requirements assigned to named owners
- Production-intent first-use and reset flows reviewed
- Laboratory evidence tied to exact identifiers and configuration
- Technical-file deliverables and retention responsibilities contracted
- Change-notice triggers written into the purchase order
- Update and vulnerability contacts tested
- CRA transition plan dated and assigned
Questions to send the OEM
Ask: Which exact hardware and software configuration was assessed? Which RED cybersecurity requirements are considered applicable and why? Which EN 18031 parts and clauses were used? Are there restrictions or gaps in the harmonised-standard route? Who controls the app, backend and signing keys? How are production credentials created? How long are security updates supported? What changes trigger reassessment?
Then ask the EU responsible party: Who is the manufacturer for RED purposes? Which conformity route is used? Are the declaration, CE marking, traceability and instructions aligned? Is notified-body involvement required? What evidence must remain accessible in the EU, and who handles authority or marketplace questions during the 2025–2027 window?
Experience scope and project limits
Editorial review: Jessica, Founder & Project Advisor at DOREMI Display. Updated 3 October 2026. Jessica's practical scope is B2B display-frame project briefing, supplier coordination, sample review, packaging handover and production change control. DOREMI does not present this article as a legal opinion, laboratory report, notified-body assessment, cybersecurity audit or guarantee of market acceptance.
Use the workflow to make the product facts and supplier evidence reviewable. The current legislation, Official Journal citations, exact configuration, conformity route and advice of responsible EU specialists control the final decision.
Public sources used for this guide
- Google Search Central: optimizing for generative AI features
- European Commission: Radio Equipment Directive and 2026 cybersecurity transition update
- EUR-Lex: Delegated Regulation (EU) 2022/30
- EUR-Lex: Delegated Regulation (EU) 2026/339
- EUR-Lex: Implementing Decision (EU) 2025/138 on harmonised standards
