Delegated Regulation (EU) 2022/30 will be repealed from 11 December 2027, when the Cyber Resilience Act applies in full. Until then, its RED cybersecurity requirements and related compliance controls remain relevant for covered radio equipment.
What has been decided
The European Commission adopted Delegated Regulation (EU) 2026/339 on 16 February 2026. Published in the Official Journal on 29 April 2026, it enters into force on the twentieth day following publication, while its repeal of Delegated Regulation (EU) 2022/30 takes effect on 11 December 2027.
Why the repeal is taking place
The essential cybersecurity requirements in Annex I to the Cyber Resilience Act include the elements covered by the relevant RED requirements in Article 3(3)(d), (e) and (f).
The repeal is intended to provide legal certainty and prevent covered radio equipment from being subject simultaneously to overlapping cybersecurity requirements under both frameworks. It does not mean that every RED obligation moves into the Cyber Resilience Act.
What applies until 10 December 2027
Delegated Regulation (EU) 2022/30 remains applicable until the day before the Cyber Resilience Act applies in full. For covered radio equipment, the relevant RED cybersecurity requirements address three distinct areas:
- protection of networks and network services;
- protection of personal data and privacy; and
- protection from fraud.
The repeal does not remove Union market-surveillance and conformity controls for covered radio equipment placed on the Union market between 1 August 2025 and 10 December 2027 where those RED requirements applied.
What changes from 11 December 2027
From 11 December 2027, Delegated Regulation (EU) 2022/30 is repealed and the Cyber Resilience Act applies in full. Manufacturers should therefore distinguish their product and conformity planning according to when a product is placed on the market and which legal framework applies.
What manufacturers should consider
The repeal is not an immediate exemption from the RED cybersecurity requirements. RED work remains relevant for products placed on the market before the changeover date, while manufacturers should prepare for the broader Cyber Resilience Act requirements in parallel.
Technical evidence, product documentation and compliance decisions should identify the applicable period clearly. Where products are changed or placed on the market again after the changeover date, the applicable Cyber Resilience Act position should be assessed against the legislation and the product's status. Earlier technical evidence should not be assumed automatically to demonstrate Cyber Resilience Act conformity.