What Ezurio products are impacted by RED Cyber?

Answer

As of the applicability date of RED Article 3.3 (d), (e), and (f) — effective August 1, 2025 — Ezurio products that ship with software and a default configuration enabling direct or indirect Internet connectivity are impacted and must comply with RED Cybersecurity requirements in a stand-alone basis. These articles cover:

  • Article 3.3 (d): Safeguarding of network functions
  • Article 3.3 (e): Protection of personal data and privacy
  • Article 3.3 (f): Protection against fraud

Ezurio’s position, in alignment with expert guidance, is that radio modules, SOMs, and USB dongles which are subcomponents or development platforms and do not ship with integrated Internet-capable applications are not subject to RED Cyber in a standalone basis.

The following table captures RED Cybersecurity applicability across different product lines and products. It should be noted that Ezurio does not plan to take through a standalone assessment is in no way a statement that RED Cybersecurity does not apply when integrated into a Final Radio Product. It is up to the integrator to ensure full conformity with RED and any other applicable regulatory requirements for the end product. 

Product LineRed Cyber StatusFuture Actions
Radio Modules, SOMs, SBCs, and USB DonglesNot applicable in DoC - subcomponents of a final Radio ProductCVE Reporting & SBOM
IoT DevicesMG100, BT510 - Not Applicable in DoC - products will be delivered without application software as development platformsCVE Reporting & SBOM
IG60 - Assessment Planned for Article 3.3 (d)CVE Reporting & SBOM
RS1xx - Assessment Planned for Article 3.3 (d)CVE Reporting & SBOM
RG1xx - Assessment Planned for Article 3.3 (d)CVE Reporting & SBOM
RS2xx - Assessment Planned for Article 3.3 (d)CVE Reporting & SBOM