Welcome to WZHL ! 28-30 May, 2027 Wenzhou, China 中文(简体)

Home / Press & Links /

What's New

EU Cybersecurity Mandate for Wireless Smart Locks Takes Effect Under CE-RED Framework

BRUSSELS, Belgium — Starting August 1, 2025, all smart door locks fitted with wireless communication modules including Wi‑Fi, Bluetooth, Zigbee, Thread and NFC for the European market shall satisfy requirements laid down in the Radio‑Equipment Directive (RED, 2014/53/EU). Mandatory cybersecurity benchmarks are defined by harmonised standard ETSI EN 303 645 (baseline cybersecurity for consumer‑grade IoT hardware) alongside the industry‑specific technical specification ETSI TS 103 815 created exclusively for residential smart‑locking equipment.

Under the CE‑RED compliance regime, manufacturers are obligated to complete rigorous laboratory assessments carried out by EU‑authorised Notified Bodies to demonstrate full‑scale product compliance. Key evaluation items are listed below:

1. Multi‑radio coexistence test
Engineers verify stable operation and minimal signal interference when multiple wireless protocols (Bluetooth, Wi‑Fi, NFC) run concurrently. The smart lock is mounted onto a representative metal plate simulating real‑world entrance‑door installation so that radio‑frequency performance under actual operating circumstances can be assessed.

2. Cybersecurity clauses
Products need to meet advanced security criteria specified within ETSI EN 303 645 V3.1.3 (September 2024). Major requirements cover the prohibition of universal default passwords, public vulnerability‑reporting workflows and reliable over‑the‑air secure firmware‑update mechanisms.

3. Electromechanical safety assessment
Battery safety testing follows Annex M of EN 62368‑1. Lock‑motor stall testing is implemented to rule out overheating risk when the deadbolt gets physically jammed.

4. RF‑performance measurement on metallic door panels
All radio‑frequency measurements shall be conducted while the hardware is fixed to a standard security‑door steel sheet. The 2.4‑GHz radio tests comply with ETSI EN 300 328 and NFC assessments follow EN 300 330. Metallic mounting surfaces greatly alter antenna radiation patterns and resonant properties.

Any smart‑lock unit failing radio‑frequency or cybersecurity evaluation cannot obtain CE certification and is legally prohibited from being placed on the EU marketplace.

Customs‑enforcement measures have been activated since August 1, 2025. Wireless smart‑lock consignments lacking complete RED technical documentation and a valid EU Declaration of Conformity referencing applicable harmonised standards will be detained by European customs authorities.

Industry compliance analysts note that the Matter protocol Version 1.2, published October 2023, now provides dedicated support for European‑market lock functions that separate “unlock” and “door‑release” commands. Even so, interoperability and cybersecurity are assessed under the broader CE‑RED regulatory framework, rather than standalone Matter‑focused stress‑test procedures.

“The updated regulatory priority shifts evaluation focus from elementary radio‑hardware compliance toward real‑world multi‑device stability and cybersecurity resilience,” stated an anonymous industry‑compliance analyst. “With widespread uptake of smart‑home ecosystems, cross‑brand interoperability and dependable offline unlocking capacity have transformed into legally‑binding compliance requirements.”

This new regulation poses substantial challenges for overseas OEM and ODM hardware producers. Factories are advised to schedule notified‑body laboratory testing well ahead of shipment cycles, embed mandatory security features from ETSI EN 303 645 and ETSI TS 103 815 into device firmware, optimise antenna performance for metal‑door installation conditions, and maintain comprehensive technical files ready for customs inspection.

In addition, draft harmonised‑standard prEN 304 632 is presently under formulation to deliver detailed compliance benchmarks for security‑oriented smart‑home hardware under the EU Cyber‑Resilience Act (CRA, Regulation (EU) 2024/2847). Full legal obligations of the CRA will enter into force on December 11, 2027.

 Source Statement:


All technical specifications, effective‑date information and enforcement‑related rules in this press release derive from publicly‑accessible official resources as listed below:

1. ETSI TS 103 815 V1.1.1 (January 2024) — Cyber‑security for Consumer Internet of Things; Requirements for Residential Smart Door Locking Devices

2. ETSI EN 303 645 V3.1.3 (September 2024) — Baseline cybersecurity requirements for consumer IoT‑devices

3. CE‑RED certification guidance documents issued by EU‑designated notified‑body laboratories

4. Official Matter protocol release notes and ecosystem documentation (Version 1.2, October 2023)

5. Ongoing draft‑standard prEN 304 632 developed in response to the EU Cyber‑Resilience‑Act (EU 2024/2847)