RED-DA complicance modules
-
Antonio2025
- Posts: 3
- Joined: Mon Oct 27, 2025 11:03 am
RED-DA complicance modules
Hi. New on RED-DA compliance. Is it possible to full full the RED-DA directive with module ESP32-WROOM-32 (ESP32 Series) ? If not what should be the closer module that shall be used instead?. Thanks
Re: RED-DA complicance modules
Short answer: RED-DA compliance is assessed on the final radio equipment (the product you place on the EU market), not on the module. So no module choice can make your product "RED-DA compliant" by itself , and conversely, the WROOM-32 doesn't prevent compliance either. No need to switch to a newer module for RED-DA reasons alone.
The applicable standards (EN 18031-1/-2/-3, harmonised since Aug 2025) evaluate the equipment as a whole: your network protection, your update mechanism, how your firmware handles credentials and personal data, etc. What the module does give you is the security building blocks the assessment will ask about: secure boot, flash encryption, a maintained Wi-Fi/BT stack with published security advisories, and esp-idf-sbom for the software inventory. Same model as RF certification: a pre-certified module shortens the path, it doesn't replace it.
Worth knowing: RED-DA is the rule today, but from Dec 2027 the EU CRA (Cyber Resilience Act) takes over with similar-but-broader requirements (vulnerability handling, SBOM, technical file), and its reporting obligations start already in Sep 2026. So whatever you build for EN 18031 now, build it to carry over.
If you share what the product does (does it handle personal data? payments?), I can point you to which parts of EN 18031 actually apply.
The applicable standards (EN 18031-1/-2/-3, harmonised since Aug 2025) evaluate the equipment as a whole: your network protection, your update mechanism, how your firmware handles credentials and personal data, etc. What the module does give you is the security building blocks the assessment will ask about: secure boot, flash encryption, a maintained Wi-Fi/BT stack with published security advisories, and esp-idf-sbom for the software inventory. Same model as RF certification: a pre-certified module shortens the path, it doesn't replace it.
Worth knowing: RED-DA is the rule today, but from Dec 2027 the EU CRA (Cyber Resilience Act) takes over with similar-but-broader requirements (vulnerability handling, SBOM, technical file), and its reporting obligations start already in Sep 2026. So whatever you build for EN 18031 now, build it to carry over.
If you share what the product does (does it handle personal data? payments?), I can point you to which parts of EN 18031 actually apply.
Who is online
Users browsing this forum: Amazon [Bot], Applebot, Bing [Bot] and 2 guests