You manufacture NFC payment devices — terminals, smart cards, mobile payment accessories. Art. 1(3) applies Art. 3(3)(f). Since the device is internet-connected, Art. 3(3)(d) applies. Since it processes cardholder data, Art. 3(3)(e) applies too. Triple requirement. REDCheck generates the 5 PDF documents covering all three. 30 minutes. €99 per product.
€99 one-time payment · 5 PDF documents in ZIP · 30 minutes · 100% in your browser
NFC payment devices trigger ALL THREE cybersecurity requirements: (d) network, (e) personal data, (f) fraud. The broadest scope in the Regulation.
You enter your product specifications. REDCheck structures the cybersecurity documentation requirement by requirement.
PCI-DSS is a payment industry standard. It is NOT a harmonised standard under Directive 2014/53/EU. The cybersecurity requirements require documentation referencing EN 18031. PCI-DSS does not satisfy the legal obligation.
Art. 1(3) applies Art. 3(3)(f) to any internet-connected radio equipment enabling transfer of money, monetary value OR virtual currency. Standard NFC card payments transfer monetary value. Art. 3(3)(f) applies.
Art. 10(1) and 10(3): obligation is on the manufacturer.
5 PDF documents per product model.
Art. 1, Del. Reg. (EU) 2022/30 + Art. 3(3), Dir. 2014/53/EU.
Art. 21 + Annex V.
Arts. 3(3)(d) and (e).
Art. 18 + Annex VI.
Art. 10(9) + Annex VII.
Look before you buy — Download sample dossier (PDF, fictitious product)
Generated from your data, in your browser. No product data leaves your computer.
5 PDF documents. 30 min. €99. Art. 21 prerequisite for any conformity route.
If you fully apply EN 18031, self-declare via Module A (Annex II). If not, Art. 17(4) requires third-party involvement.
We do not sell testing. We do not sell consulting. We sell the tool that structures your cybersecurity documentation.
Art. 46 of Directive 2014/53/EU requires effective, proportionate and dissuasive penalties.
Arts. 40(1), 40(4) and 43.
Acquirers may suspend terminal certification if EU compliance is not demonstrated.
Missing documentation = no market.
| Alternative | Cost | What you get |
|---|---|---|
| Consultancy / lab | €5,000–15,000/model | Triple scope. Months. |
| Rely on PCI-DSS | €0 | PCI-DSS is not a harmonised standard. Does not satisfy Art. 21. |
| Assemble yourself | €0 | EN 18031: 600+ pages × 3 parts. |
| REDCheck | €99 | 5 documents, 30 min, per model |
Professional Pack: €999 for 70 generations.
Request volume pricingREDCheck generates a document structured under Art. 21 and Annex V of Directive 2014/53/EU based on the information you enter. The truthfulness, accuracy and completeness of that information is your responsibility as manufacturer of the radio equipment.
We guarantee that the document structure follows Art. 21 and Annex V of Directive 2014/53/EU and that the legal references cited are correct as of the latest verification date.
REDCheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.
Five PDF documents. Art. 21 and Annex V fully structured. Directive 2014/53/EU. Your product data never leaves your computer.