Skip to content

Compliance and economics

What Actually Stops You Shipping: A 2026 Certification Map for Connected Hardware

What certification costs for connected hardware in the EU and US in 2026, and which deadlines are already live.

By Aike Müller14 min read

There is a particular kind of silence that falls over a startup when the first production run is sitting in a warehouse and someone finally asks whether the product is legal to sell. We have been in that room. The units are beautiful, the firmware is stable, the packaging has a lovely die-cut window, and nobody can produce a Declaration of Conformity, because nobody owned that job.

Certification is a set of design constraints that arrive eighteen months before you notice them, and in 2026 they reach deeper into the product than before. Anything with a radio now has to meet a cybersecurity requirement before it can carry the CE mark. In the US, the identity of your radio module’s grantee has turned into a legal question rather than a procurement one. Neither is something a test lab can fix for you in week 40.

Where it costs money, the figures below come from labs and published fee schedules rather than folklore.

The baseline: two markets, two mechanisms

The EU and the US are the two gates almost everyone walks through first, and they work differently in a way that trips up founders coming from software.

The EU has no certification authority for ordinary electronics. You declare conformity yourself: assemble a technical file, test against harmonised standards, sign an EU Declaration of Conformity, affix the CE mark. Nobody blesses it. That sounds liberating until you realise the liability sits entirely with you, and market surveillance authorities can demand the file at any point.

For a mains-powered device with Wi-Fi or Bluetooth, four pieces of EU law apply at once: the Radio Equipment Directive (2014/53/EU) for anything that transmits, the Low Voltage Directive for mains safety, EMC for interference, and RoHS for restricted substances. RED absorbs the EMC and safety essential requirements for radio products, so the practical work is one coordinated test campaign, not four.

The US splits along a different seam. The FCC cares about spectrum, and Part 15 divides the world into unintentional radiators (anything with a clock above 9 kHz, which is everything) and intentional radiators. Unintentional radiators go through Supplier’s Declaration of Conformity: you test, you keep records, no filing. Intentional radiators need Certification through a Telecommunications Certification Body, with a public grant and an FCC ID. Safety is not the FCC’s problem at all, which surprises people: in the US it is handled by OSHA for workplace equipment, by the National Electrical Code for installations, and, for consumer goods, by retailers, insurers and the plaintiff’s bar.

The 2026 curveball: cybersecurity now gates the CE mark

If your team last shipped hardware in 2023, this is the change most likely to blindside you. Since 1 August 2025, Delegated Regulation (EU) 2022/30 has activated Articles 3(3)(d), (e) and (f) of the RED. Internet-connected radio equipment must not harm the network, equipment that processes personal, traffic or location data (wearables, baby monitors, connected toys) has to protect it, and equipment enabling money or virtual currency transfers has to resist fraud. There was no grace period and no transition window for products already in design.

The harmonised standards are EN 18031-1, -2 and -3, listed in the Official Journal on 30 January 2025 via Implementing Decision (EU) 2025/138. Commercially, the restrictions attached to that listing are the part that matters. Where a restriction applies to your design, you lose presumption of conformity by self-assessment and the conformity assessment requires a notified body.

The restrictions land on ordinary product decisions. Let a user skip setting a password during onboarding and you are in restricted territory. Same if children may use the device and there is no parental control mechanism. These are choices a UX designer makes on a Tuesday, without knowing they have just moved the project from a €5,000 to €15,000 self-assessment into a notified body engagement that starts at €60,000. Designing out of the restrictions, with mandatory credential setup, a defensible secure update mechanism and documented secure storage, is cheaper than buying the certificate.

The Cyber Resilience Act, and the repeal nobody told you about

The Cyber Resilience Act entered into force on 10 December 2024, and its main product obligations apply from 11 December 2027. Most founders have filed that as a 2027 problem. Two things make that wrong.

First, the reporting obligations start on 11 September 2026. From that date, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA’s single reporting platform: early warning within 24 hours, notification within 72 hours, final report within 14 days for a vulnerability or one month for a severe incident. The clock starts when you have “a reasonable degree of certainty.” In practice you need a monitored security contact, a triage process, and someone who can write a report for a regulator over a weekend. Penalties run to €15 million or 2.5% of global turnover.

Second, on 16 February 2026 the Commission adopted a delegated regulation repealing 2022/30 with effect from 11 December 2027. The RED cybersecurity requirements therefore apply to radio equipment placed on the market up to and including 10 December 2027, and the CRA takes over the day after. If you are certifying in 2026, you do EN 18031 now and you will redo the exercise against CRA Annex I before end-2027. The overlap is real: secure-by-default behaviour, vulnerability handling and update mechanisms all map across, so build the evidence once, in a form you can re-cut.

The CRA also asks for things a hardware startup rarely has: a declared support period during which you ship free security updates (five years is the Commission’s reference point, adjustable to the product’s realistic life), a machine-readable SBOM, and a documented risk assessment. The support period is a business decision with a cost attached. Make it deliberately.

The US side, where the trap is in your BOM

FCC Part 15 itself is well trodden. Use a pre-certified radio module and you are testing the host: roughly $3,000 to $10,000 and three to six weeks. Design your own RF front end and you are at $8,000 to $20,000 and six to twelve weeks, more if SAR applies. Cellular pushes you into carrier certification territory: $15,000 to well past $200,000, six to nine months. A grantee code costs about $40, the only genuinely cheap thing in this article.

What has changed is the Covered List. It began in 2021 as a list of companies: Huawei, ZTE, Hytera, Hikvision, Dahua, later Kaspersky. Through 2025 and 2026 it became something structurally different.

In its October 2025 Second Report and Order the FCC clarified that covered equipment includes modular transmitters, and prohibited authorisation of any device incorporating one, regardless of whether that module holds its own valid grant. On 23 July 2026 it extended the prohibition to devices containing logic-bearing hardware components from Covered List entities, broadly anything generating or using timing signals above 9,000 pulses per second using digital techniques. And on 16 July 2026, previously authorised covered equipment listed in 2024 or earlier lost the right to be imported or marketed at all, breaking the old assumption that an FCC grant was permanent.

The FCC has also started adding country-neutral categories based on where a product is produced rather than who makes it: uncrewed aircraft systems and their critical components (22 December 2025), consumer-grade internet routers (23 March 2026), and foreign-produced power inverters and advanced robotic devices (28 July 2026). “Foreign-produced” turns on a domestic component-cost threshold, not the nationality of the brand.

The consequence for a startup is specific and uncomfortable. For every radio module and every significant logic-bearing part, you need to know which company holds the FCC grant. Your distributor’s name does not answer that, and neither does the logo printed on the reel. Answer it before you commit to tooling, then re-check, because the list moves.

The U.S. Cyber Trust Mark is the friendlier US story and remains voluntary. It has had a rocky administration: UL Solutions withdrew as lead administrator in December 2025 and the FCC selected the ioXt Alliance in April 2026. Treat it as a retail differentiator to watch, not a gate.

The safety mark no law requires and every retailer demands

No US federal law requires an NRTL mark on a consumer gadget sold direct. There is also, in practice, no way onto the shelves at Amazon, Best Buy or Walmart without one, and your product liability insurer will ask.

For most connected electronics the standard is UL 62368-1, which replaced the old IT and AV safety standards. Budget $15,000 to $50,000+ for initial certification and 12 to 20 weeks with a round or two of findings, plus $15,000 to $30,000 a year for the quarterly factory inspections that keep the listing alive. Founders routinely leave that recurring cost out of the model. Lithium cells add UL 1642 or UL 2054 testing on top. ETL from Intertek carries identical legal standing at 25 to 50% less.

The paperwork layer, which is where small companies actually get caught

Enforcement against startups tends to show up as a marketplace takedown or a customs hold rather than a failed EMC test. The cause is usually administrative.

Since 16 July 2021, Article 4 of Regulation (EU) 2019/1020 has required an economic operator established in the EU for CE-marked products including radio equipment, EMC, LVD and RoHS scope, with that operator’s name and postal address on the product, packaging or accompanying documents. The GPSR (Regulation (EU) 2023/988), applicable since 13 December 2024, layers a parallel responsible-person duty for consumer products plus recall machinery: affected consumers must be notified directly, offered at least two of repair, replacement or refund, and serious incidents reported through the Safety Business Gateway. If you are a US or Asian company selling into Europe without an entity there, this is a real appointment you have to make and pay for.

Then there is producer responsibility, which is national rather than European. WEEE, batteries and packaging registrations are per member state. The Batteries Regulation added producer registration duties from 18 August 2025, and packaging registration under the PPWR follows from 12 August 2026. Selling into eight countries means eight registrations. Chemicals sit alongside: RoHS restricts ten substances in homogeneous materials, while REACH’s Candidate List reached 253 SVHCs on 4 February 2026, and anything above 0.1% by weight in an article triggers information duties down the chain and an SCIP notification to ECHA.

Batteries, passports, and what is not yet your problem

From 18 February 2027, the EU Batteries Regulation requires portable batteries in consumer products to be removable and replaceable by the end user, using commonly available tools, with spare batteries available for five years after the last unit is sold and no software parts-pairing lock. Narrow derogations exist for wet-environment and safety-critical designs. If your industrial-design language depends on a glued-in pouch cell, this is a mechanical architecture decision you need to make in 2026, not 2027.

The battery passport, also from 18 February 2027, applies to LMT, industrial batteries above 2 kWh and EV batteries, not to the 500 mAh cell in a wearable. Similarly, the ESPR working plan’s first wave of Digital Product Passports targets steel, aluminium, textiles, tyres, furniture and mattresses; consumer electronics has no dedicated delegated act, with phones and tablets indicated around 2030 and a horizontal EEE recyclability requirement around 2029. The direction of travel is clear enough, but the deadline pressure is not there yet.

The UK, briefly

Do not overthink it. The UK announced on 1 August 2023 that it would indefinitely extend recognition of the CE mark across 18 regulations administered by the Department for Business and Trade, covering electrical equipment and radio. That still holds in 2026: a valid CE mark gets you into Great Britain, and Northern Ireland requires CE regardless. Medical devices and construction products run on separate clocks.

Ecosystem certifications, which are membership fees wearing a lab coat

Bluetooth branding requires SIG qualification. The SIG raised all member fees effective 1 March 2026; on the current schedule an Adopter pays $0 dues and $12,000 per product qualification, while a Contributing Adopter pays $3,500 in dues and $8,000 for its first qualification of the year. Do the arithmetic on your product cadence before choosing a tier.

Matter runs through the Connectivity Standards Alliance: Associate membership is free, Adopter $7,000 a year, Participant $20,000, with per-product certification of $2,000 to $3,000. Cellular means PTCRB: roughly $16,000 to $20,000 for a data-only device with an external antenna, $40,000 to $50,000 for a multi-band device with voice and an internal antenna, though building on an already-approved module can bring a device through in two to three weeks. Individual carriers may still want their own approval on top.

What it costs, and the order to do it in

Requirement Applies when Bites
RED + EMC + LVD + RoHS (CE) Any radio product sold in EU Before first EU sale
EN 18031 / RED Art. 3(3) Any connected radio product, EU Since 1 Aug 2025
CRA reporting Products with digital elements, EU 11 Sep 2026
CRA product requirements Products with digital elements, EU 11 Dec 2027
FCC Part 15 + Covered List check Any US sale Before first US sale
NRTL (UL/ETL) US retail, workplace, insurance Before retail listing
Art. 4 / GPSR responsible person Non-EU seller into EU Before first EU sale
Battery removability Portable batteries, EU 18 Feb 2027

For a typical connected consumer device with a pre-certified radio, a realistic 2026 budget for EU plus US market access is somewhere between €60,000 and €120,000 all-in, with a nine-month runway from design freeze to launch. Published lab ranges put CE EMC and LVD work at €10,000 to €20,000, RED Articles 3.1 and 3.2 at €20,000 to €40,000, RED 3.3 self-assessment at €5,000 to €15,000, and US FCC certification at $12,000 to $30,000, before safety listing, ecosystem fees and the two rounds of retesting that almost always happen.

The order matters more than the total. Resolve your BOM against the FCC Covered List before committing to a radio module, and design out the EN 18031 restrictions while you are still writing firmware architecture rather than when you are in test. Your EU responsible person needs appointing early, because their name and address have to be on the labelling artwork. Book lab slots three months ahead; capacity for RED cybersecurity work has been tight since 2025. On the first EVT build, $3,000 to $8,000 of pre-compliance scanning routinely prevents a five-figure retest cycle. The ecosystem certifications can wait until last: they are fees and paperwork, not physics.

The founders who ship on time treat regulation as a specification and write it into the requirements document alongside battery life and enclosure tolerance. At RMBG the compliance constraints live in the same document as the electrical spec, because late in the programme none of it is negotiable, and early on all of it is cheap.

Sources

Frequently asked

How much does it cost to certify a connected hardware product for the EU and US?

A realistic 2026 budget for a typical connected consumer device with a pre-certified radio is €60,000 to €120,000 all-in, over a nine-month runway from design freeze to launch. Published lab ranges put CE EMC and LVD work at €10,000 to €20,000, RED Articles 3.1 and 3.2 at €20,000 to €40,000, RED 3.3 self-assessment at €5,000 to €15,000, and US FCC certification at $12,000 to $30,000, before safety listing and ecosystem fees.

Do I need a notified body for the RED cybersecurity requirements?

Only where a restriction attached to the EN 18031 listing applies to your design, at which point you lose presumption of conformity by self-assessment. The restrictions land on ordinary product decisions: letting a user skip setting a password during onboarding, or a device children may use with no parental control mechanism. Designing out of the restrictions is cheaper than buying the certificate.

Is a UL mark legally required to sell electronics in the US?

No US federal law requires an NRTL mark on a consumer gadget sold direct. In practice there is no way onto the shelves at Amazon, Best Buy or Walmart without one, and your product liability insurer will ask. For most connected electronics the standard is UL 62368-1, at $15,000 to $50,000 plus and 12 to 20 weeks, with $15,000 to $30,000 a year for the factory inspections that keep the listing alive.

Does a CE mark still get me into the UK?

Yes. The UK announced on 1 August 2023 that it would indefinitely extend recognition of the CE mark across 18 regulations covering electrical equipment and radio, and that still holds in 2026. Northern Ireland requires CE regardless. Medical devices and construction products run on separate clocks.

The Device Is a Third of the Company

The app, the returns desk, the channel, the packaging register and the liability all outlive your launch. Budget for the two thirds nobody demos.

Work with us

Building something physical?

We take hardware and connected products from requirements to production, with the security and compliance work built into the schedule rather than bolted on at the end.

Start a project