Directive 2014/53/EU · Del. Reg. 2022/30Generate my documentation — €99
ACTIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

You manufacture WiFi smart thermostats in the United States and sell them in Europe. Your thermostat communicates over the internet and may process personal data via its companion app. Both Art. 3(3)(d) and Art. 3(3)(e) of Directive 2014/53/EU apply from 1 August 2025.

Your WiFi smart thermostat connects to the internet via the home router. It runs a companion app that collects room temperature schedules, occupancy patterns and user preferences. Art. 3(3)(d) applies because the device communicates over the internet. Art. 3(3)(e) may apply if the app collects user-identifiable data — occupancy patterns linked to an email address are personal data under GDPR Art. 4(1). A European consultancy quotes $12,000 per model. REDCheck generates the 5 PDF documents. 30 minutes. €99.

Generate my RED documentation — €99Free: does my thermostat need RED cybersecurity documentation?

€99 one-time payment · 5 PDF documents in ZIP · 30 minutes · 100% in your browser

Directive 2014/53/EU · Art. 3(3)(d)(e)(f) · Art. 21 + Annex V · Art. 18 + Annex VI · Art. 10(9) + Annex VII · Delegated Reg. (EU) 2022/30 · EN 18031-1, -2, -3

EU cybersecurity documentation for smart thermostats: the numbers

A WiFi smart thermostat is a textbook example of internet-connected radio equipment under Delegated Regulation (EU) 2022/30.

1 Aug 2025
Mandatory application date — no grace period
Art. 3(3)(d) + (e)
Network protection (always for WiFi) + personal data (if app collects user data)
$12,000 vs €99
EU consultancy vs REDCheck per thermostat model

What REDCheck does with your product data

You enter your product specifications. REDCheck structures the cybersecurity documentation requirement by requirement, following the EN 18031 categories.

1
Company details
Legal name, role under Directive 2014/53/EU, country, EU contact.
2
Product classification
Determines applicable requirements: Art. 3(3)(d), (e) and/or (f).
3
Cybersecurity assessment
EN 18031 categories: access control, authentication, secure comms, updates, vulnerability management.
4
Risk assessment
Structured risk table per applicable requirement.
5
EU Declaration of Conformity
Art. 18 + Annex VI. Basis for CE marking.
6
Download ZIP
5 PDFs. Add to technical file. Retain 10 years (Art. 10(4)).

Three mistakes smart thermostat manufacturers make about RED cybersecurity

COMMON ERROR

"A thermostat is a simple device — cybersecurity doesn't apply"

Art. 1(1) applies Art. 3(3)(d) to ANY radio equipment that communicates over the internet. Complexity is irrelevant. A €30 thermostat has the same obligation as a €300 gateway.

COMMON ERROR

"Temperature data is not personal data"

Temperature alone may not be personal data. But occupancy schedules, heating patterns linked to a user account with email, and geofencing data ARE personal data under GDPR Art. 4(1).

COMMON ERROR

"We comply with the EU Energy Labelling Directive — that covers us"

Energy labelling (Regulation (EU) 2017/1369) and the Radio Equipment Directive (2014/53/EU) are separate regulations. They are complementary, not overlapping.

What's in the ZIP

5 PDF documents per product model. Each cites the exact article of Directive 2014/53/EU that it covers.

1

Product Classification

Art. 1, Del. Reg. (EU) 2022/30 + Art. 3(3), Dir. 2014/53/EU.

2

Cybersecurity Technical Documentation

Art. 21 + Annex V.

3

Risk Assessment

Arts. 3(3)(d) and (e).

4

EU Declaration of Conformity

Art. 18 + Annex VI.

5

Simplified Declaration + Label

Art. 10(9) + Annex VII.

Look before you buy — Download sample dossier (PDF, fictitious product)

Generated from your data, in your browser. No product data leaves your computer.

What you pay

🧾 EU CONSULTANCY
$12,000
Per model. Months.
✓ REDCHECK
€99
5 documents. 30 minutes.

Technical documentation and third-party testing: two layers

● LAYER 1

Cybersecurity technical documentation (Annex V)

5 PDF documents. 30 min. €99. Art. 21 prerequisite for any conformity route.

∅ LAYER 2

Conformity assessment by a Notified Body

If you fully apply EN 18031, self-declare via Module A (Annex II). If not, Art. 17(4) requires third-party involvement.

We do not sell testing. We do not sell consulting. We sell the tool that structures your cybersecurity documentation.

What happens without cybersecurity documentation

Art. 46 of Directive 2014/53/EU requires effective, proportionate and dissuasive penalties.

🇪🇺
Market withdrawal
Immediate

Arts. 40(1), 40(4) and 43.

🇩🇪
Germany — BNetzA
€3,000–€30,000

BNetzA has already contacted startups selling smart thermostats without cybersecurity documentation.

🛒
Amazon EU listing removal
Revenue loss

Amazon requires conformity documentation.

Alternatives

AlternativeCostWhat you get
EU consultancy$12,000/modelMonths. Custom report.
Hire EU specialist$80,000+/yearIf available.
Assemble yourself$0 (your time)EN 18031 has 600+ pages.
REDCheck€995 documents, 30 min, per model

Selling more than one smart home product in the EU?

Professional Pack: €999 for 70 generations.

Request volume pricing
Reply within one business day.

What REDCheck guarantees and what it does not

REDCheck generates a document structured under Art. 21 and Annex V of Directive 2014/53/EU based on the information you enter. The truthfulness, accuracy and completeness of that information is your responsibility as manufacturer of the radio equipment.

We guarantee that the document structure follows Art. 21 and Annex V of Directive 2014/53/EU and that the legal references cited are correct as of the latest verification date.

REDCheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.

Frequently asked questions

Our thermostat uses Zigbee for local control and WiFi for cloud. Which triggers cybersecurity?
The WiFi connection triggers Art. 3(3)(d) directly. The Zigbee radio communicates indirectly via WiFi. Recital 8: all aspects must comply. The entire device is in scope.
Our app uses geofencing. Does that make occupancy data 'personal data'?
Yes. Geofencing requires GPS location, which is personal data under GDPR Art. 4(1). Art. 1(2)(a) applies Art. 3(3)(e).
Can we use Module A (self-declaration)?
Yes, if you fully apply EN 18031. Art. 17(3)(a) allows Module A.
What happens when the CRA replaces RED?
Delegated Regulation (EU) 2022/30 will be repealed from 11 December 2027.
Is it a subscription?
No. One-time payment. Each license includes a 30-day editing window and up to 10 regenerations. The 5 PDF documents you download are yours permanently.
Can I request a refund?
Under Art. 16(m) of Directive (EU) 2011/83 on consumer rights, by activating the license you give express consent to the immediate generation of the digital content, waiving the 14-day right of withdrawal. Refunds are accepted only for reproducible technical failures reported to hello@solidwaretools.com within 14 days of purchase.
What if the regulation changes?
If Directive 2014/53/EU, Delegated Regulation (EU) 2022/30 or the EN 18031 standards change during your license validity period, you can regenerate the documents with the updated version of the generator at no additional cost.
⚠️ Important notice: REDCheck is a documentary self-assessment tool, not legal advice or a third-party audit. The document is generated from the data you enter. The accuracy of the data is your responsibility under Art. 10(1) of Directive 2014/53/EU. REDCheck does not replace a conformity assessment by a Notified Body where required under Art. 17(4) of the Directive.

Your thermostat is on the EU market. The cybersecurity documentation must be too. Generate it in 30 minutes.

Five PDF documents. Art. 21 and Annex V fully structured. Directive 2014/53/EU. Your product data never leaves your computer.

€99 per product
One-time payment · No subscription · 30 minutes · 10 regenerations · 30-day editing window · Professional Pack: €999
Generate my RED documentation — €99
✓ Last regulatory check: 6 May 2026 · No substantive changes detected · View history