Sourcing & Compliance · EU

Since August 2025, radio equipment sold in the EU has had to meet cybersecurity requirements under the Radio Equipment Directive. Most summaries describe these as rules for internet-connected devices — which is true of two of the three requirements, and misleading about the third. For baby monitors specifically, the third is the one that matters.

True Bond Engineering Team · Shenzhen · 12 min read

Quick answer

Delegated Regulation (EU) 2022/30 activated three cybersecurity requirements under the Radio Equipment Directive, applicable from 1 August 2025, with the EN 18031 series as the harmonised standards for demonstrating conformity. Article 3(3)(d), network protection, applies to internet-connected radio equipment — including equipment that reaches the internet indirectly through another device. Article 3(3)(f), fraud protection, applies to internet-connected equipment involved in transferring money or value. But Article 3(3)(e), protection of personal data and privacy, applies to several categories including radio equipment designed or intended exclusively for childcare, where the equipment is capable of processing personal data — and the regulation’s recitals name child monitors as the example. That category is not conditional on internet connectivity. The practical consequence: a baby monitor with no WiFi and no app sits outside the network and fraud requirements and has a far smaller attack surface, but “no WiFi” alone does not take it out of scope of the privacy requirement. Whether and how each requirement applies to a specific model is established in its conformity assessment — which is where any claim about it should be checked.

Not legal advice. This summarises the published structure of Delegated Regulation (EU) 2022/30 and the EN 18031 series for general understanding. Applicability to any specific product depends on its design and is determined through conformity assessment. Importers and manufacturers should work from the regulation’s text and qualified compliance advice.

§01What became mandatory

The Radio Equipment Directive has always contained three essential requirements in Article 3(3)(d), (e) and (f) that could be “switched on” for particular categories of equipment. Delegated Regulation 2022/30 switched them on, and they have applied since 1 August 2025.

The EN 18031 series — part 1 for network protection, part 2 for privacy and personal data, part 3 for fraud — was published as harmonised standards, meaning a product that correctly applies them benefits from a presumption of conformity with the corresponding requirement. Certain clauses carry restrictions, and where a product relies on those, assessment by a notified body is required rather than self-declaration.

The headline version is “cybersecurity rules for connected devices.” The accurate version is three requirements with three different scopes — and one of them names child monitors directly.

§02The scope rule most summaries get wrong

RequirementWhat it protectsApplies toConnectivity needed?
ART. 3(3)(d)
EN 18031-1
Networks — the device mustn’t harm networks or misuse network resources Internet-connected radio equipment, directly or via another device Yes
ART. 3(3)(e)
EN 18031-2
Personal data and privacy of users Where capable of processing personal data: internet-connected equipment; equipment designed or intended exclusively for childcare; toys with radio function; wearables Not for the childcare category
ART. 3(3)(f)
EN 18031-3
Protection from fraud Internet-connected equipment enabling transfer of money or value Yes

TABLE.01 — Three requirements, three scopes. The middle row is the one that matters for baby monitors, because the childcare category is defined by purpose rather than by connectivity. Summarised from Delegated Regulation (EU) 2022/30; the regulation’s text governs.

The sentence worth reading in the original

The regulation’s recitals explain why these categories were chosen, and in describing equipment designed or intended exclusively for childcare, they give child monitors as the example.

That’s unusually direct for a regulation. It means there’s no interpretive question about whether baby monitors were in the drafters’ minds: they were named. The remaining question for any specific product is whether it is capable of processing personal data — and a device whose purpose is to capture and transmit video and audio of a child is a strong candidate for that description.

The full text is on EUR-Lex, and it’s short enough to read in full.

§03What removing the internet connection does — and doesn’t — change

This is the honest core of the matter, and it’s worth being precise rather than convenient.

What “no internet” genuinely changes Two requirements, and most of the attack surface
  • The network-protection requirement doesn’t arise, because it applies to equipment that can communicate over the internet.
  • The fraud requirement doesn’t arise, for the same reason and because no payment function exists.
  • Remote attack paths disappear. With no internet connection, no cloud account and no app, there is no route for someone elsewhere in the world to reach the device, and no stored credentials to leak from a server.
  • The data stays local. Video and audio travel between the camera and the parent unit and nowhere else.
What “no internet” doesn’t change The privacy requirement, and the local link still matters
  • The childcare category under Article 3(3)(e) isn’t conditional on connectivity. A dedicated local link doesn’t by itself remove a child monitor from that scope.
  • A radio link is still a radio link. Personal data still travels through the air between two units, and what safeguards protect that link is a legitimate question.
  • Frequency hopping is a transmission technique, not encryption. It makes casual interception considerably harder than a fixed-channel transmission, and it improves resilience to interference — but whether a link’s safeguards satisfy a privacy requirement is something established in assessment, not assumed from the modulation scheme.
  • Pairing and physical access still count. How units pair, and what prevents an unauthorised receiver from joining, are part of the same picture.
3(3)(d) NETWORK internet-connected only no WiFi → doesn’t arise 3(3)(e) PRIVACY includes childcare equipment no WiFi → still in scope 3(3)(f) FRAUD internet-connected only no WiFi → doesn’t arise “NO WIFI” REMOVES TWO OF THREE — NOT ALL THREE for a child monitor, the privacy requirement is defined by purpose, not connectivity

FIG.01 — A no-WiFi architecture has a real regulatory and security advantage, and it’s specific: two of three requirements fall away along with most of the attack surface. The third remains, because it’s defined by what the device is for.

§04The indirect-connection clause

A second detail that catches buyers out, in the opposite direction. “Internet-connected” in the regulation includes equipment that communicates over the internet via another device, not just equipment with its own internet connection.

For baby monitors this matters with hybrid designs. A camera described as using a dedicated radio link, whose parent unit or base station then bridges to an app over WiFi, is part of an internet-connected system — and the network-protection requirement comes back into view. The question isn’t whether the camera has WiFi; it’s whether any path from the camera’s data reaches the internet. That’s the same question behind verifying a no-WiFi claim in the first place.

§05A connection to the rest of this series

One more line in the regulation ties back to the medical device discussion earlier in this series. Radio equipment to which the EU medical device regulations apply is excluded from these three requirements — it’s governed through that framework instead.

It’s a small illustration of the theme running through the hub article: which rules apply to a device depends on what the device is declared to be. A monitor positioned as a medical device in the EU sits in one framework; the same hardware positioned as consumer childcare equipment sits in another, with these cybersecurity requirements attached.

§06What importers and buyers should ask

Questions for any baby monitor entering the EU
  • Does the Declaration of Conformity address the RED cybersecurity requirements, and which of Articles 3(3)(d), (e) and (f) does it treat as applicable?
  • If a requirement is treated as not applicable, what’s the stated reasoning? For a child monitor, “no internet connection” is an argument about (d) and (f), not about (e).
  • Which parts of EN 18031 were applied, and did any restricted clause mean a notified body was involved?
  • Does any path from the device’s data reach the internet — including through a base station, hub, or companion app?
  • What safeguards protect the radio link and the pairing process, stated specifically rather than as “secure transmission”?
  • When was this batch placed on the EU market? The requirements apply to products placed on the market from 1 August 2025.

These fit into the broader document discipline covered in the verification checklist and the ongoing obligations in the maintenance calendar — a firmware or radio change that affects the link can reopen the assessment just as a hardware change can. For the wider EU import picture, see the EU import guide.

§07Where True Bond sits

Stated without the convenient version

Our monitors have no WiFi, no app and no cloud account — a dedicated FHSS link between camera and parent unit, and nothing that reaches the internet directly or indirectly. That places them outside the internet-connected conditions behind the network and fraud requirements, and removes the remote attack surface that connected monitors have to defend.

It doesn’t make the privacy question disappear, and we won’t claim it does. Our products are childcare radio equipment that carries video and audio of a child between two units, which is exactly the category Article 3(3)(e) names. How that requirement applies to a given model, and what the conformity documentation for it says, is specific to the model and the market — and it’s something we’d rather show an importer than summarise in a blog post.

If you’re assessing one of our products for the EU, ask us for the current conformity documentation for that specific model. The honest answer to “is it in scope?” is a document, not a slogan.

§08Frequently asked questions

Does EN 18031 apply to baby monitors?

It can, and for child monitors specifically, connectivity isn’t the only route in. Delegated Regulation (EU) 2022/30 applies the privacy and personal data requirement of Article 3(3)(e) to several categories where the equipment can process personal data — including radio equipment designed or intended exclusively for childcare, which the regulation’s recitals illustrate with child monitors. EN 18031-2 is the harmonised standard for that requirement. The network-protection and fraud requirements, covered by EN 18031-1 and -3, apply to internet-connected equipment.

Is a no-WiFi baby monitor exempt from the EU cybersecurity requirements?

Not entirely. Having no internet connection takes a monitor outside the network-protection and fraud requirements, which apply to internet-connected radio equipment, and it removes the remote attack surface that connected devices must defend. But the privacy requirement applies to childcare radio equipment capable of processing personal data regardless of connectivity. So “no WiFi” removes two of the three requirements, not all three. How the remaining one applies to a specific model is established in its conformity assessment.

When did the RED cybersecurity requirements become mandatory?

They apply to radio equipment placed on the EU market from 1 August 2025. Delegated Regulation (EU) 2022/30 was published in January 2022, and the EN 18031 series was subsequently published in the Official Journal as harmonised standards, giving a presumption of conformity to products that correctly apply them. The separate EU Cyber Resilience Act brings broader cybersecurity obligations with its main requirements applying later, from December 2027.

Does frequency hopping count as encryption?

No. Frequency hopping spread spectrum is a transmission technique: the signal moves rapidly across many channels in a pattern shared by the paired units. It makes casual interception considerably harder than a fixed-channel transmission and improves resilience to interference, but it isn’t cryptographic encryption. Whether a particular link’s safeguards satisfy a privacy requirement is determined in conformity assessment rather than assumed from the modulation scheme alone.

Does a monitor count as internet-connected if only the base station has WiFi?

Generally yes, in the regulation’s sense. Internet-connected radio equipment includes equipment that communicates over the internet via another device, not only equipment with its own connection. A camera using a local radio link to a base station or parent unit that then bridges to an app over WiFi is part of an internet-connected system. The useful question is whether any path from the device’s data reaches the internet, not whether the camera itself has WiFi.

How do True Bond monitors relate to EN 18031?

They have no WiFi, no app and no cloud account, using a dedicated FHSS link with no direct or indirect internet path, which places them outside the internet-connected conditions behind the network and fraud requirements. As childcare radio equipment carrying video and audio of a child, the privacy requirement is a question we don’t dismiss. How it applies to a specific model is set out in that model’s conformity documentation, which we provide to importers on request rather than summarising in general terms.

Ask for the document, not the slogan

“No WiFi” is a real advantage, and a specific one. For an EU import, the question worth asking is what the conformity documentation for the exact model says — and we’ll provide it.

Request conformity documentation → info@truebondtech.com · WhatsApp +86 189 2846 4489 · View products

Leave a Reply

Your email address will not be published. Required fields are marked *