Directive 2014/53/EU · Del. Reg. 2022/30Generate my documentation — €99
ACTIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

Art. 12 of Directive 2014/53/EU makes it clear: before you place radio equipment on the EU market, you must verify that the manufacturer has drawn up cybersecurity technical documentation. If the documentation does not exist, you cannot legally import the product.

You are an EU importer. Your Chinese, Indian or Turkish supplier has CE marking for EMC and safety — but not for cybersecurity. From 1 August 2025, Delegated Regulation (EU) 2022/30 requires cybersecurity documentation under Art. 3(3)(d) and (e). Art. 12(2) requires YOU to verify the documentation exists before placing the product on the market. Art. 12(1): importers shall place only compliant radio equipment on the market. If your supplier cannot provide the documentation, YOU bear the liability. REDCheck generates the 5 PDF documents for each product model. Send your supplier the link: 30 minutes, €99 per product, 100% in their browser.

Generate RED documentation — €99Free: does this product need RED cybersecurity documentation?

€99 one-time payment · 5 PDF documents in ZIP · 30 minutes · 100% in your browser

Directive 2014/53/EU · Art. 3(3)(d)(e)(f) · Art. 21 + Annex V · Art. 18 + Annex VI · Art. 10(9) + Annex VII · Delegated Reg. (EU) 2022/30 · EN 18031-1, -2, -3

Art. 12 obligations for importers: the numbers

Directive 2014/53/EU assigns specific obligations to importers. The cybersecurity requirements of Art. 3(3)(d) and (e) — activated by Delegated Regulation (EU) 2022/30 — make these obligations concrete and urgent.

Art. 12(1)
Importers shall place ONLY compliant radio equipment on the market. No exceptions.
Art. 12(2)
Before placing on market: verify manufacturer has carried out conformity assessment, drawn up technical documentation, product bears CE marking, accompanied by required documents.
10 years
Art. 12(8): importer must keep a copy of the EU declaration of conformity at the disposal of market surveillance authorities for 10 years.

How REDCheck helps you as importer

The documentation obligation is the manufacturer's (Art. 10). But if your supplier cannot produce it, your products are blocked. REDCheck is a tool you can send to your supplier.

1
Send the link to your supplier
Your manufacturer enters their company and product data into REDCheck. The tool runs in their browser — their data never leaves their computer.
2
Supplier completes product classification
Determines which essential requirements apply: Art. 3(3)(d), Art. 3(3)(e), or both.
3
Supplier completes cybersecurity assessment
Requirement-by-requirement review mapped to EN 18031-1 and EN 18031-2 categories.
4
Supplier generates ZIP with 5 PDFs
Product classification, technical documentation, risk assessment, EU declaration of conformity, simplified declaration + label.
5
You verify and file
Art. 12(2): verify that documentation exists. Art. 12(8): keep a copy of the EU declaration of conformity for 10 years.
6
Place on market
Your product is legally compliant. You have fulfilled Art. 12(1) and 12(2).

Three mistakes importers make about RED cybersecurity

COMMON ERROR

"My supplier has CE marking — that means everything is covered"

CE marking applied BEFORE 1 August 2025 covers EMC (Art. 3(1)(b)) and safety (Art. 3(1)(a)). It does NOT cover the cybersecurity requirements of Art. 3(3)(d) and (e) activated by Delegated Regulation (EU) 2022/30. You must verify that the technical documentation now INCLUDES cybersecurity (Art. 12(2)).

COMMON ERROR

"It's the manufacturer's problem — I just import"

Art. 12(1) is unambiguous: importers shall place ONLY compliant radio equipment on the market. Art. 12(2) requires you to verify documentation BEFORE placing the product. If you place non-compliant equipment, Art. 12(7) requires you to take corrective action — withdraw, recall, inform authorities. The obligation to produce the documentation is the manufacturer's. The obligation to verify it is YOURS.

COMMON ERROR

"I can wait and see — enforcement won't start immediately"

Market surveillance authorities can act from 1 August 2025. Art. 40(1) of Directive 2014/53/EU empowers authorities to require withdrawal, prohibit sale or order recall. Art. 43 addresses formal non-compliance — including missing technical documentation (Art. 43(1)(f)). Amazon and EU marketplaces can suspend listings independently of authority action.

What's in the ZIP

5 PDF documents generated from the manufacturer's product data. Each cites the exact article of Directive 2014/53/EU that it covers.

1

Product Classification

Art. 1, Del. Reg. (EU) 2022/30 + Art. 3(3), Dir. 2014/53/EU.

2

Cybersecurity Technical Documentation

Art. 21 + Annex V. Requirement-by-requirement documentation.

3

Risk Assessment

Arts. 3(3)(d) and (e). Structured risk table.

4

EU Declaration of Conformity

Art. 18 + Annex VI.

5

Simplified Declaration + Label

Art. 10(9) + Annex VII.

Look before you buy — Download sample dossier (PDF, fictitious product) — Real structure, real articles, real format. Fictitious data.

The manufacturer generates the documents. You verify and file them. Art. 12(8): retain for 10 years.

What your supplier pays

🧾 NOTIFIED BODY / CONSULTANCY
€5,000–10,000
Per product model. 3–6 months. 23 models = €115,000–230,000. Will your supplier pay that?
✓ REDCHECK
€99
5 documents. 30 minutes per model. 23 models = €2,277. Send your supplier the link.

Technical documentation and third-party testing: two layers

● LAYER 1

Cybersecurity technical documentation (Annex V)

5 PDF documents. 30 min. €99 per product. The documentation that Art. 21 requires BEFORE your product can bear CE marking.

∅ LAYER 2

Conformity assessment by a Notified Body

If you fully apply EN 18031, you can self-declare via Module A (Annex II) without a Notified Body. If you partially apply or don't apply the harmonised standards, Art. 17(4) requires third-party involvement. REDCheck does not replace a Notified Body — it generates the documentation that is a prerequisite for any conformity route.

As importer, your role is to VERIFY Layer 1 documentation exists. The manufacturer produces it.

What happens to importers without verified cybersecurity documentation

Art. 46 of Directive 2014/53/EU requires Member States to establish penalties. As importer, YOU are liable — not just the manufacturer.

🇪🇺
Market withdrawal — at importer's expense
Immediate

Art. 40(4): market surveillance authorities can prohibit sale, require withdrawal or order recall. Art. 12(7): the importer must take corrective action on all affected products throughout the EU.

🇩🇪
Germany — Produktsicherheitsgesetz
€3,000–€30,000

Administrative fines under §19. Up to 1 year of imprisonment for serious offences under §20. The importer — not the manufacturer — faces German enforcement.

⚖️
Formal non-compliance — Art. 43
Listing of deficiencies

Art. 43(1)(f): if technical documentation is not available or not complete, the Member State shall require the economic operator to put an end to the non-compliance. Incomplete documentation = non-compliance.

Options for your supplier

OptionCostWhat your supplier gets
Notified Body / lab in China€5,000–10,000 per model3–6 months. Full third-party assessment.
EU-based cybersecurity consultancy€5,000–15,000 per modelCustom report. Weeks of wait.
Supplier assembles documentation€0 (their time)EN 18031 has 600+ pages. No guidance.
REDCheck — send them the link€995 documents, 30 min, per model

Importing more than ten product models?

If your suppliers document 10 or more product models, we offer the Professional Pack: €999 for 70 generations with a single license key. You can purchase the Pack and distribute the license key to your suppliers.

Request volume pricing
Reply within one business day.

What REDCheck guarantees and what it does not

REDCheck generates a document structured under Art. 21 and Annex V of Directive 2014/53/EU based on the information you enter. The truthfulness, accuracy and completeness of that information is your responsibility as manufacturer of the radio equipment.

We guarantee that the document structure follows Art. 21 and Annex V of Directive 2014/53/EU and that the legal references cited are correct as of the latest verification date. We do not guarantee that a specific document will be accepted by a market surveillance authority in a specific case, nor by a commercial buyer in a procurement process.

REDCheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.

Frequently asked questions — importer obligations RED cybersecurity

Am I liable if my supplier's documentation is incomplete?
Art. 12(2) requires you to ensure that the manufacturer has drawn up technical documentation. If the documentation is incomplete and the product is placed on the market, Art. 43(1)(f) applies — technical documentation not complete. The Member State will require you, as the economic operator who placed the product, to put an end to the non-compliance. You are liable as importer.
Can I produce the cybersecurity documentation on behalf of my supplier?
Art. 10(1) and 10(3) place the documentation obligation on the manufacturer. However, Art. 14 provides that if an importer places radio equipment under their own name or trade mark, they assume manufacturer obligations. In that case, you CAN and MUST produce the documentation. REDCheck can be used by either party.
How do I verify my supplier's documentation is correct?
Art. 12(2) requires you to verify that the conformity assessment has been carried out, the technical documentation exists, CE marking is applied, and required documents accompany the product. You are not required to audit the content — but you must confirm the documentation exists and covers the applicable requirements.
What happens when the CRA replaces the RED cybersecurity requirements?
The Cyber Resilience Act (Regulation (EU) 2024/2847) will gradually replace the cybersecurity requirements of Art. 3(3)(d), (e) and (f) of Directive 2014/53/EU. The transition is expected by 2027–2028. Until the CRA fully applies, the RED cybersecurity requirements remain in force. Documentation generated now remains valid for products placed on the market during the RED regime.
Can I use Module A (self-declaration) instead of a Notified Body?
If you fully apply the harmonised standards EN 18031-1, EN 18031-2 and, where applicable, EN 18031-3, you can use Module A (self-declaration, Annex II) under Art. 17(3)(a) of Directive 2014/53/EU. No Notified Body required. If you partially apply or do not apply the standards, Art. 17(4) requires a Notified Body (Module B+C or Module H). REDCheck generates the documentation for both routes.
Is it a subscription?
No. One-time payment. Each license includes a 30-day editing window and up to 10 regenerations. The 5 PDF documents you download are yours permanently.
Can I request a refund?
Under Art. 16(m) of Directive (EU) 2011/83 on consumer rights, by activating the license you give express consent to the immediate generation of the digital content, waiving the 14-day right of withdrawal. Refunds are accepted only for reproducible technical failures reported to hello@solidwaretools.com within 14 days of purchase.
What if the regulation changes?
If Directive 2014/53/EU, Delegated Regulation (EU) 2022/30 or the EN 18031 standards change during your license validity period, you can regenerate the documents with the updated version of the generator at no additional cost.
⚠️ Important notice: REDCheck is a documentary self-assessment tool, not legal advice or a third-party audit. The document is generated from the data you enter. The accuracy of the data is your responsibility under Art. 10(1) of Directive 2014/53/EU. REDCheck does not replace a conformity assessment by a Notified Body where required under Art. 17(4) of the Directive.

Your suppliers need cybersecurity documentation. Send them the link. €99 per product. 30 minutes.

Five PDF documents per model. Art. 21 and Annex V fully structured. Directive 2014/53/EU. Data stays in the manufacturer's browser. You verify and file.

€99 per product
One-time payment · No subscription · 30 minutes · 10 regenerations · 30-day editing window · Professional Pack: €999
Generate RED documentation — €99
✓ Last regulatory check: 6 May 2026 · No substantive changes detected · View history