Category
  • Industry

European Union: CE RED updates harmonized standards


On September 4, 2026, the European Commission issued Resolution (EU) 2026/2003, which revised the harmonized standards for several Radio Directives (RED). The main changes include:

  • Updated versions of the original harmonized standards: Electromagnetic Radiation Standard EN 50566:2017/A1:2023 and EN 50566:2017/A2:2025 (should be used together with EN 50566:2017), point-to-point fixed wireless link RF standard EN 302 217-2 V3.4.1, UWB Tank Level Probing Radar standard EN 302 372 V3.1.1, oastal Surveillance, Vessel Traffic Services and Harbour Radars Standard EN 303 135 V2.2.1, Broadcast Television Receiver Amplifier and Active Antenna Standard EN 303 354 V1.2.1;
  • New harmonized standards: short-range radio standard EN 300 440-2 V3.1.1 and EN 305 550-5 V1.1.1, PMR/TETRA EMC standard EN 301 489-5 V2.3.1, CB equipment EMC standard EN 301 489-13 V2.1.1, cellular base station EMC standard EN 301 489-50 V2.4.1, UWB standard EN 302 065-3-3 V3.1.0 and EN 302 065-4-4 V2.1.1, primary radar standard EN 303 364-1-1 V1.1.1.

Click this link to view the original text of the (EU) 2026/2003 resolution, whose mandatory implementation date is March 7, 2028.

EU: ETSI publicly solicited comments on the draft EU CRA companion standard and updated the vulnerability reporting guidelines


On August 13, 2026, the European Telecommunications Standards Institute (ETSI) issued a notice announcing the official launch of a public consultation process for the EU Cybersecurity Act (CRA) supporting standards, releasing 17 technical specification drafts covering key digital products such as wearable devices, smart toys, internet routers, operating systems, smart homes, password managers, antivirus software, and virtual private networks (VPNs). These EN 304 XXX standards aim to provide a compliance framework for CRA, such as the antivirus software draft specifying the configuration path for "default security." According to the CRA timeline, starting September 11, 2026, relevant manufacturers must promptly report exploited vulnerabilities or serious security incidents through the European Union Agency for Cybersecurity (ENISA)'s unified reporting platform, with comprehensive compliance requirements set to take effect by the end of 2027.

Click this link to view the original text of ETSI's announcement. Click this link which allows you to view the operation guide for designated agents who have completed "EU Registration" registration on the ENISA reporting platform.

EU: Commission issues the Harmonized Digital Product Passport standards for the Ecodesign for Sustainable Products Regulation (ESPR)


On July 14, 2026, the European Commission adopted Implementation Resolution (EU) 2026/1763, issuing six unified standards for digital product passports (DPPs) supporting the Eco-Design for Sustainable Products Regulation (ESPR, EU 2024/1781). The resolution was published in the Official Journal of the EU and took effect immediately. According to the resolution, digital product passports that meet these unified standards can be presumed to meet the requirements of Articles 10 and 11 of the regulations, providing companies with a clear path to compliance.

The six standards include:

  • EN 18216:2026 "Digital Product Passport – Data Interchange Protocol";
  • EN 18219:2026 "Digital Product Passport - Unique Identifier";
  • EN 18220:2026 "Digital Product Passport – Data Carrier";
  • EN 18221:2026 "Digital Product Passport – Data Storage, Archiving and Data Persistence";
  • EN 18222:2026 "Digital Product Passport – Application Programming Interface (API) for Product Passport Lifecycle Management and Searchability";
  • EN 18223:2026 "Digital Product Passport – System Interoperability".

For mobile devices, ESPR replaces the Native Eco-Design Directive (2009/125/EC), and thus serves as the superior regulation to the Eco-Design Regulation (EU) 2023/1670. Currently, ESPR's requirements for digital passports will first apply to products such as steel, and automobile/industrial batteries, but the mandatory implementation date for mobile terminals has yet to be determined. The main compliance consideration for ESPR for mobile devices is to implement the relevant eco-design requirements according to (EU) 2023/1670.

Click this link to view the original text of Implementing Resolution (EU) 2026/1763.

EU: The EU delays certain aspects of the AI Act


On May 7, 2026, the European Parliament and the Council of the European Union reached a provisional agreement on AI Omnibus (Omnibus VII), aiming to simplify and optimize parts of the EU AI Act implementation arrangements. For manufacturers, this does not mean the AI Act is being fully postponed, but rather that compliance obligations for some high-risk AI systems are being reclassified and implemented in phases, with major changes including:

  • Postponed from August 2, 2026 to December 2, 2026: Transparency obligations such as labeling and watermarks for AI-generated content are expected to apply; Newly prohibits AI-generated child sexual abuse material or involuntary intimacy/sexually explicit content that identifies individuals;
  • Postponed from August 2, 2026 to December 2, 2027: Some Annex III high-risk AI system obligations are expected to apply, such as biometrics, critical infrastructure, education, employment, law enforcement, border management, and other scenarios;
  • Postponed from August 2, 2027 to August 2, 2028: High-risk AI systems embedded in products and used as security components, especially those regulated by EU industry safety regulations, are expected to be subject to relevant obligations.

The above changes were approved by the European Parliament on June 16, 2026, and after adoption by the Council of the European Union, they are expected to be officially published to the OJ by August 2, 2026.

Click this link to view the European Parliament's press release on the approval of the revision of the AI Act.

EU: The Commission issues (EU) 2026/339, replacing the Cybersecurity Delegated Regulation (EU) 2022/30


On February 16, 2026, the European Commission adopted the initiative to adopt the Cyber Resilience Act (CRA) as an alternative to the Cybersecurity Authorization Regulation (EU) 2022/30. On April 29, 2026, the Commission officially issued the new Delegated Regulation (EU) 2026/339, which replaces Regulation (EU) 2022/30 effective December 11, 2027.

Click this link to view the original delegated regulation.

European Union: Commission launches public consultation on draft guidelines for the implementation of the Cyber Resilience Act (CRA).


On March 3, 2026, the European Commission launched a public consultation on the draft implementation guidelines for the Cyber Resilience Act (CRA).

Click this link for the original public consultation, and the call for comments is until March 31, 2026.

EU: Commission to repeal the Cybersecurity Delegation Regulation (EU) 2022/30


Following the European Commission's public consultation on the initiative to repeal the Cybersecurity Delegation Regulation (EU) 2022/30 on December 10, 2025, the Commission officially adopted the initiative on February 16, 2026, and the Delegation Regulation (EU) 2022/30 will expire from December 11, 2027. The Cyber Resilience Act (EU) 2024/2847 will replace the Delegated Regulation (EU) 2022/30. At present, the relevant initiative has not completed the legislative process and has not been published on the Official Journal (OJ) website.

Click this link to see the content of the initiative and the status of resolution.

European Union: Commission adopts Regulation 2025/2392 amending the Cyber Resilience Act


On December 1, 2025, the European Commission published Commission Implementing Regulation (EU) 2025/2392, which provides a technical description of important and critical product categories that contain digital elements, in accordance with Regulation 2024/2847. The regulations will come into effect on December 21, 2025.

Click this link to view the original text of (EU) 2025/2392.

EU: ETSI publishes draft cybersecurity standards under the framework of the Cyber Resilience Act (CRA).


On January 15, 2026, the European Telecommunications Standards Institute (ETSI) published the following draft standards for the Cyber Resilience Act:

  • EN 304 617 – Cybersecurity requirements for Browsers
  • EN 304 618 – Cybersecurity requirements for password managers
  • EN 304 619 – Cybersecurity requirements for software that searches for, removes, or quarantines malicious software
  • EN 304 620 – Cybersecurity requirements for Virtual Private Networks (VPNs)
  • EN 304 621 – Cybersecurity requirements for Network Management Systems (NMSs)
  • EN 304 622 – Cybersecurity requirements for Security Information and event management (SIEM)
  • EN 304 623 – Cybersecurity requirements for boot managers
  • EN 304 624 – Essential cybersecurity requirements for Public Key Infrastructure and digital certificate issuance software
  • EN 304 625 – Cybersecurity requirements for physical and virtual network interfaces
  • EN 304 626 – Cybersecurity requirements for Operating Systems (OS)
  • EN 304 627 – Essential cybersecurity requirements for routers, modems intended for the connection to the internet, and switches
  • EN 304 635 – Cybersecurity requirements for Virtualisation Execution Stack (VES) and Container Execution Stack (CES), including hypervisors and container runtime systems
  • EN 304 636 – Cybersecurity requirements for firewalls, intrusion detection and/or prevention systems

Click on this link to view the above draft standards. The link also includes a public consultation guide and a feedback form.

European Union: Commission revises RED harmonized standards for short-range equipment and airborne mobile communication systems


On December 11, 2025, the European Commission issued Commission Implementation Decision (EU) 2025/2499, which revises the harmonized standards for short-range devices (SRDs) and airborne mobile communication systems.

The main changes are as follows:

  • Removal of the old version of the standard: EN 300 220-2 V3.1.1 for short-range devices (SRDs) in the frequency band from 25 MHz to 1 000 MHz, EN 302 480 V2.2.1 for airborne mobile communication systems (MCOBA) and EN 302 729 V2.1.1 for short-range devices using ultra-wideband (UWB) technology. The effective date of standard deletion is June 11, 2027;
  • The following harmonized standards have been added: EN 300 220-2 V3.3.1, EN 302 480 V3.1.1, EN 302 729-1 V3.1.1, EN 303 659 V1.1.1 short-range devices in data networks, EN 305 550-6 V1.2.1 specific wireless measurement equipment (e.g. detection radar) in the frequency band from 40 GHz to 260 GHz.

Click on this link to view the original text of (EU) 2025/2499.

  • 40 records in 4 pages
  • «
  • 1
  • 2
  • 3
  • 4