Before Adding Wi-Fi, Bluetooth, App Control or Cloud Access

EU Smart Appliance Radio Equipment, RED Cybersecurity and Software Handoff

Adding a Wi-Fi or Bluetooth function can change an ordinary electrical appliance into radio equipment under Directive 2014/53/EU. The importer then needs a product-level route covering safety objectives, electromagnetic compatibility, effective radio-spectrum use, applicable cybersecurity requirements and every other relevant EU act. A CE-marked radio module is useful evidence, but it does not automatically make the finished appliance compliant.

This guide is for EU importers and private-label buyers developing connected air fryers, ovens, fans, pumps and other wholesale appliances. It separates the physical appliance, radio module, antenna, firmware, mobile app, cloud service, user account and update process before quotation and sample approval. It is general B2B information, not legal, radio-engineering, cybersecurity, laboratory, data-protection or market-access advice. MOQ starts from 1000 PCS. Wholesale only.

Smart appliance production requiring controlled radio module firmware app and EU RED evidence

Direct Answer for EU Smart-Appliance Importers

Does a CE-marked Wi-Fi or Bluetooth module cover the finished appliance?

No. Module documentation can support the finished-product assessment, but the integration can change radio performance, antenna conditions, exposure, EMC, safety, software, cybersecurity, instructions and intended use. The responsible manufacturer must assess and document the complete radio equipment as marketed, not only the purchased module.

A buyer should therefore freeze the wireless architecture before relying on a quotation or prior report. The antenna, enclosure, power supply, PCB layout, radio settings, firmware, app, cloud endpoint and user-account design form one controlled project. If any of them changes, the impact decision must be recorded before production release.

Feature-to-Scope Decision

Commercial words do not define the legal route

Product claim or functionScope questionEvidence to request before quotationCommon mistake
Wi-Fi app controlDoes the appliance intentionally transmit or receive radio waves, connect to the internet directly or through other equipment, and process user or device data?Radio-module model, frequency bands, power, antenna, firmware, app owner, cloud path, account functions and intended countries.Calling the product "smart" without identifying who controls the software and security lifecycle.
Bluetooth setup or local controlIs Bluetooth used only locally, or does the app or phone bridge the appliance to an internet service?Pairing flow, supported profiles, radio parameters, authentication, permissions, data map and update method.Assuming Bluetooth never creates internet-connected or personal-data questions.
Third-party radio moduleAre the module's tested conditions preserved in the finished product?Module identity, reports, declaration, antenna limitations, integration guide, host conditions, software revision and change notices.Copying the module declaration as the finished-appliance declaration.
Buyer-owned app and cloudWhich party controls accounts, credentials, servers, updates, vulnerability response and customer support?Written responsibility matrix, API boundary, security contacts, service period, data locations, deletion route and exit plan.Leaving the factory responsible for a service it cannot access or update.
Factory or platform appCan the buyer retain lawful operational control if the software provider changes or disappears?Tenant ownership, administrator access, source or escrow position where agreed, export rights, domain and certificate ownership, update authority and termination process.Approving packaging and production before confirming long-term service ownership.
No wireless functionHas the exact production model actually removed the radio module, antenna and wireless firmware?Separate BOM, PCB, software, rating label, manual, packaging and model identity for the non-radio variant.Using one model number and one technical file for radio and non-radio versions.

RED Essential-Requirement Layers

A radio appliance is more than an EMC test plus a module report

Article 3(1)(a)

Health and safety objectives

Radio equipment follows the safety objectives associated with the Low Voltage Directive without the LVD voltage limit, together with relevant health considerations for the complete product.

Article 3(1)(b)

Electromagnetic compatibility

The integrated appliance must provide an adequate level of EMC. Host electronics, motors, heaters, switching supplies, displays and radio operation can interact.

Article 3(2)

Effective radio-spectrum use

Frequency bands, output, modulation, antenna, receiver behavior and country restrictions must match the final equipment and current EU requirements.

Article 3(3)

Applicable additional requirements

Determine whether network protection, personal-data and privacy protection, fraud protection or another activated requirement applies to the actual category and function.

Other EU Acts

One product, several legal routes

RoHS, ecodesign, energy labelling, batteries, GPSR, WEEE, packaging, food-contact or other requirements remain separate scope decisions.

Conformity Route

Standards coverage matters

Current harmonised standards, their restrictions and how they are applied affect the available conformity-assessment route. A qualified EU professional should confirm the route for the exact model.

Cybersecurity Transition as of July 2026

Keep the current RED file while preparing for the Cyber Resilience Act

PeriodCurrent control pointImporter action
From 1 August 2025Delegated Regulation (EU) 2022/30 makes RED Article 3(3)(d), (e) and (f) requirements applicable to specified categories or classes of radio equipment.Classify the finished equipment against each activated requirement and retain the applicable conformity evidence.
Current 2026 projectsEN 18031-1, -2 and -3 references are published with restrictions. A standards title alone is not proof that every clause and restriction has been addressed.Record the selected standard, applicable part, edition, OJ restrictions, product functions, assessment basis and unresolved gaps.
Until 10 December 2027Covered radio equipment placed on the Union market remains subject to the applicable RED cybersecurity requirements under the current delegated regulation.Do not remove RED cybersecurity evidence merely because a later repeal has already been published.
From 11 December 2027Delegated Regulation (EU) 2026/339 repeals Regulation 2022/30 when the Cyber Resilience Act applies in full.Prepare a dated transition plan with qualified EU advisers; do not assume existing evidence automatically satisfies the future route.
Products placed during the transition windowThe 2026 repeal states that market surveillance remains able to control RED Article 3(3)(d), (e) and (f) compliance for covered products placed from 1 August 2025 through 10 December 2027.Retain the dated model, software, cybersecurity and market-release evidence for those units.

The Cyber Resilience Act has provisions that apply before full application, including certain reporting and conformity-assessment-body provisions. The exact project timeline, economic-operator role, product scope and transition must be confirmed from current official texts. This page does not replace a legal or cybersecurity assessment.

Smart-Appliance RED Scope Master

Freeze fourteen records before the connected sample is approved

Control fieldRecord for the actual wholesale SKUWhy it protects the project
Product identityBrand, marketed model, factory model, variant, intended use, images and approved sample revision.Keeps radio, software and production evidence attached to the same product.
Radio architectureModule, chipset, protocols, frequency bands, maximum power, antenna type, gain, cable and placement.Defines the radio configuration assessed in the finished appliance.
Host constructionPCB, enclosure, shielding, power supply, motors, heaters, displays, cables and grounding.Host integration can alter safety, EMC and radio performance.
Country configurationEU countries, enabled channels, regional firmware, restrictions and user information.Prevents a non-EU radio configuration from entering EU production.
Firmware identityVersion, build hash or controlled identifier, radio settings, libraries, signing route and release owner.Connects test results and cybersecurity decisions to executable software.
Mobile applicationOwner, store account, package identifier, supported operating systems, permissions, SDKs and release process.Shows who can maintain the customer-facing control interface.
Cloud and APIService owner, tenant, regions, endpoints, certificates, data flow, logs, backup and termination route.Connected-product continuity cannot depend on an undocumented account.
Identity and accessPairing, onboarding, credentials, password policy, roles, recovery, reset and device transfer.Authentication choices directly affect network and data risks.
Data mapDevice, user, traffic, location, diagnostic and third-party data; purposes, recipients, retention and deletion.Supports privacy and cybersecurity classification without inventing a generic claim.
Update processUpdate authority, signing, delivery, rollback, end-of-support date, emergency patch route and user communication.A compliant sample still needs a controlled software lifecycle.
Vulnerability processContact, intake, triage, remediation, disclosure, incident records and buyer notification.Establishes who acts when a security issue appears after shipment.
Conformity mapApplicable RED requirements, other EU acts, standards and restrictions, reports, risk assessment, declaration and notified-body decision where relevant.Prevents the module file from being mistaken for the complete product file.
Production controlsApproved BOM, module and antenna labels, firmware programming, credentials, inspection, traceability and substitution authority.Keeps series production aligned with the assessed construction.
Commercial continuityApp, cloud, domain, certificate, administrator, source access where agreed, service fees, exit rights and evidence retention.Protects the importer if a platform, employee or supplier relationship changes.

Radio-Module Evidence Handoff

Use module records as inputs, not as a substitute for finished-product control

Module Identity

Match the exact production module

Record manufacturer, model, hardware revision, label, chipset, firmware baseline and approved supplier. Similar names are not traceability.

Integration Conditions

Preserve tested limitations

Keep antenna type, gain, separation, enclosure, supply, layout, operating mode and host conditions within the documented integration route.

Finished-Product Testing

Assess host interactions

Determine what product-level safety, EMC, radio, exposure and cybersecurity evaluation remains after integration.

Instructions and Label

Use the finished product identity

Country restrictions, bands, accessories, installation, safety, conformity and responsible-party information must match the marketed appliance.

Change Notice

Control supplier revisions

Require notification before module, chipset, antenna, firmware, security library or manufacturing-site changes affect production.

End of Life

Plan the replacement route

Define last-buy, substitute assessment, firmware support, evidence retention and buyer approval before the module becomes unavailable.

Factory-to-Importer Release Workflow

Nine gates before a connected appliance enters production

01

Define the connected use case

Describe what the customer can do, which data moves, whether internet access exists and which countries will receive the product.

02

Freeze commercial and technical identity

Separate radio and non-radio variants and assign controlled model, hardware, software, app and cloud identifiers.

03

Map RED and other EU scope

Identify essential requirements, activated cybersecurity duties, other applicable acts, standards and transition dates.

04

Approve the architecture and ownership matrix

Assign module, antenna, firmware, app, cloud, account, update, vulnerability and data responsibilities in writing.

05

Approve assessment and evidence plans

Use competent laboratories and qualified advisers to decide product-level tests, risk assessments, standards and conformity routes.

06

Verify the complete sample

Assess the integrated appliance with production-representative hardware, antenna, firmware, app, cloud and settings.

07

Align the technical and customer files

Match reports, risk assessment, declaration, labels, manual, app listing, privacy information and support statements.

08

Lock production and provisioning

Control approved components, firmware loading, credentials, regional configuration, inspection, records and release authority.

09

Operate the post-market process

Maintain updates, vulnerability handling, incidents, complaints, changes, support period and evidence for shipped lots.

Reassessment Triggers

Connected-product changes must reopen the affected evidence

ChangePotential effectRequired project response
Module, antenna or layoutRadio, exposure, EMC, integration conditions and declarations can change.Block substitution until a documented technical and conformity impact review is approved.
Firmware or radio settingsFrequencies, power, protocols, security controls or test identity can change.Compare controlled builds and repeat affected assessment or testing before release.
App SDK or permissionData access, authentication, third-party transfer and privacy statements can change.Update the data map, risk review, app records and customer information.
Cloud endpoint or providerCertificates, data location, service continuity, subprocessors and incident response can change.Approve the migration and update ownership, security and support evidence.
Account or password designAuthentication and unauthorized-access risk can change.Reassess the applicable cybersecurity requirements and standards restrictions.
New market or placing dateRadio restrictions, languages, transition law and responsible-party duties can change.Run a current destination-and-date review before shipment.
Software support endsThe product may remain in use while vulnerabilities can no longer be corrected.Execute the agreed end-of-support, customer notice, service and market-action plan.

Factory and Importer Boundary

What Yaoyuan can coordinate and what responsible EU parties must determine

Factory Hardware

Controlled appliance construction

We can coordinate available specifications, BOM, radio module, antenna, PCB, enclosure, power architecture, sample and production revision for the selected order.

Software Coordination

Known firmware and platform records

We can organize available legitimate firmware, app, cloud and supplier information for the actual project. Ownership and access must be agreed, not assumed.

Production Execution

Approved configuration and traceability

We can execute buyer-approved programming, regional settings, labels, packing, inspection and change controls within the agreed manufacturing scope.

EU Responsibility

Scope and conformity decisions

The responsible manufacturer, importer and qualified EU professionals determine legal scope, standards, testing, conformity route, declaration, languages and market actions.

No Module Shortcut

Evidence stays product-specific

We do not claim that a radio-module certificate automatically covers the finished appliance or every antenna, enclosure, firmware and market version.

No Cybersecurity Fiction

Only authentic controls and records

We do not invent penetration tests, risk assessments, update commitments, security contacts, app ownership, cloud access, standards coverage or incident records.

Current Official Starting Points

Use the applicable texts and Official Journal references for the exact launch date

This page is general B2B information, not legal, radio-engineering, RF-exposure, EMC, electrical-safety, cybersecurity, penetration-testing, software, cloud, privacy, standards, laboratory, notified-body or market-access advice. The applicable scope, essential requirements, standards, restrictions, assessment route, technical documentation, declaration, instructions, labels, languages, data duties, reporting, support period, retention and transition depend on the exact product, radio function, user, data flow, destination, economic-operator role and placing-on-market date. Use current official texts, competent laboratories and qualified EU professionals. Never falsify or alter a product identity, module, antenna, firmware, app, cloud account, risk assessment, report, certificate, declaration, standard, security control, test result, update record or market date.

EU Smart-Appliance Project Review

Send the complete connected-product profile before sample approval

Send the buyer company, EU countries, responsible EU entity, brand, product and model, quantity, intended use, voltage, frequency, plug, radio module, protocols, frequency bands, antenna, firmware owner and version, app owner, cloud owner, account design, data flow, update route, support period, available reports, target launch date, destination port and appointed EU adviser or laboratory. Yaoyuan can review available factory-side data and manufacturing controls for the actual wholesale project. MOQ starts from 1000 PCS. Wholesale only. No retail orders.