
For EU-bound consumer IoT, a useful China-side control is a configuration-to-unit handoff. It compares the approved model, radio module, firmware build, app or cloud pairing reference, label artwork, and export lot with selected physical units. It does not perform a cybersecurity assessment, validate a technical file, certify conformity, or decide whether a product may be placed on the market.
That boundary prevents a common release error. A factory may show a declaration, a standards reference, and a retail carton, yet the selected device can carry a different firmware build or module reference from the controlled configuration. The inspection record should preserve that difference for the accountable technical or regulatory owner before the buyer releases a shipment.
Commission Delegated Regulation (EU) 2022/30 made the RED Article 3(3)(d), (e), and (f) cybersecurity-related essential requirements applicable from 1 August 2025 to specified radio-equipment categories or classes. The delegated regulation identifies the requirement areas and covered equipment classes.
RED is the EU Radio Equipment Directive framework for radio equipment. For a product team, the first decision is not “does it look like a smart device?” but whether the specific equipment, radio function, and intended market position bring the relevant requirements into scope. A factory visit can work only from the controlled product decision supplied by the responsible owner; it cannot create that scope decision.
A configuration card should link the approved IoT model, radio module, firmware build, app or cloud pairing reference, label artwork, declaration revision, and physical lot without claiming that the card itself proves conformity.
Use one row for each controlled configuration that can reach a shipment. At minimum, include the model code, hardware or PCB revision where relevant, radio-module supplier and reference, firmware-build identifier and display path, companion-app or cloud-environment reference, approved label revision, EU declaration of conformity reference, applicable standards reference, pack-artwork revision, supplier lot, and carton range. Add a named owner for each technical decision and a date or revision for every supplied reference.
The card is a release-control record, not an evidence substitute. A missing field should remain open rather than being filled with a visual similarity judgement. When an early sample and its visible references need a physical comparison before production spreads a change, a Pre-Production Inspection service can record the selected facts against the buyer’s controlled card.
Under the RED, manufacturers must perform conformity assessment, draw up the EU declaration of conformity, and ensure radio equipment bears a type, batch, serial number, or other identification element; the declaration identifies the radio equipment type. Articles 10 and Annex VI of Directive 2014/53/EU set out those manufacturer and declaration requirements.
For inspection planning, those fields are retrieval points. Ask whether the selected unit, label, pack, and factory lot record can be connected to the controlled model and declaration reference. Do not ask an inspector to decide whether the declaration is complete or whether the conformity assessment route was correct.
Commission Implementing Decision (EU) 2025/138 lists EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 in support of different RED Article 3(3) cybersecurity requirements, with stated limitations to the presumption of conformity. The implementing decision gives the standard references and limitations.
EN 18031 is therefore not a generic device label or a factory checkbox. The responsible technical owner needs to identify the relevant standard part, product scope, version, and any limitation. When the release decision needs a cybersecurity method and result rather than a physical correspondence check, use appropriate product testing services and retain the issued evidence reference in the configuration card.
An on-site inspection can record configuration identifiers and visible product or packing facts against a buyer-controlled evidence pack, but it cannot execute a cybersecurity assessment, validate a test method, or certify RED or CRA conformity. An EU consumer IoT RED EN 18031 CRA inspection should preserve an observable match or mismatch for the owner who can make the next decision.
Give the inspector a controlled copy of the configuration card, with the selected product codes and the exact locations where evidence can be seen: device settings screen, printed label, module label or supplier record, carton mark, packing list, and lot sheet. State whether a different radio module, firmware build, cloud endpoint, label language, or accessory version creates a separate configuration line. TradeAider can scope and report those selected observable facts; the report should say which items were available, compared, and not retrievable.
| Evidence lane | Factory comparison | What it cannot determine | Accountable owner |
|---|---|---|---|
| RED file | Declaration reference, model identity, unit or pack identifier | Conformity assessment adequacy or legal scope | Manufacturer or regulatory owner |
| EN 18031 evidence | Declared part, version, and controlled reference | Standard applicability, limitation, or cybersecurity result | Technical owner and laboratory |
| Selected configuration | Model, module, firmware display, app reference, and label revision | Security behaviour or software-test conclusion | Technical product owner |
| Shipment record | Carton range, pack state, supplier lot, and photo record | EU market-release approval | Buyer release owner |
The comparison shows why documents and physical facts should not be collapsed into one “compliant” label. A retrievable match can support the buyer’s release record. A missing or conflicting link should be logged as an evidence hold, with the affected configuration and accountable owner named.
RED manufacturers must have procedures for series production to remain in conformity and take changes in design, characteristics, standards, or specifications adequately into account. Directive 2014/53/EU sets that production-change requirement.
A firmware change should therefore trigger a controlled version decision before the affected units enter a final release population. Preserve the build shown on the selected device, the linked module and label revision, the factory lot range, and the reference supplied by the technical owner. If the factory cannot retrieve the link, the inspection result is a configuration gap—not a cybersecurity failure finding.
The Cyber Resilience Act entered into force on 10 December 2024, reporting obligations apply from 11 September 2026, and its main obligations apply from 11 December 2027. The European Commission’s CRA policy page states those dates.
CRA means the EU Cyber Resilience Act for products with digital elements. Its timeline matters for product governance, vulnerability and incident processes, and the supporting evidence a manufacturer may need to manage. It does not make an on-site visual check a CRA assessment. The Commission’s CRA reporting guidance explains the reporting route, including an early warning within 24 hours and notification requirements for the specified events.
The transition also needs care. The Commission notes that RED cybersecurity requirements transition to the CRA, while software updates and uploads remain within RED. Its RED overview is useful for separating those frameworks. Put dates and responsible owners on the configuration card, but do not backfill a future-process conclusion into a current inspection report.
A pre-shipment inspection can record selected finished-goods, packaging, and configuration evidence against the approved release card, while conformity assessment, cybersecurity testing, and regulatory reporting remain outside the inspection result.

Use the branch to separate a retrievable physical configuration match from a configuration evidence hold; it is not a RED, EN 18031, or CRA conformity decision.
A PSI, or pre-shipment inspection, is a finished-goods check before export. TradeAider scopes a PSI when 100% of the order quantity is completed and at least 80% is packed for export. For connected products, add the controlled configuration line, selected settings-screen checks, visible labels, carton range, supplier lot record, and the technical-owner escalation contact to that scope.
Release is a buyer decision, so define the hold before sampling starts. Hold the identifiable carton range when the selected firmware build, radio module, model code, label revision, or lot record does not match the controlled card. If the supplier cannot isolate the affected configuration, expand the hold to the wider unseparated range. TradeAider’s Pre-Shipment Inspection service can document those selected physical findings against the agreed scope.
A mismatch between the selected unit’s firmware-build evidence and the controlled release card should be treated as an evidence hold, not as proof of cybersecurity failure or conformity.
This composite example uses a private-label Wi-Fi consumer gateway. It shows the value of a retrievable configuration record without presenting a client case, test result, legal conclusion, or market-approval outcome.
The illustrative scenario preserves a configuration mismatch and targeted recheck path without making a RED, EN 18031, CRA, or cybersecurity conclusion.
Situation. A private-label importer is preparing a Wi-Fi consumer gateway for EU distribution.
Order context. Two retail-pack language versions cover 180 export cartons, with one controlled model and firmware-release card.
Readiness state. Finished goods are complete and export-packed for the buyer’s shipment-release decision.
Observation one. The selected unit’s settings screen shows firmware build FW-1.6, while the factory lot sheet retrieves the relevant carton range.
Observation two. The supplied release card and label artwork identify FW-1.5, and the factory cannot provide a controlled technical-owner approval connecting FW-1.6 to the declared configuration.
Problem. The inspector can preserve the build display, unit identifiers, label, carton range, and missing approval link. The inspector cannot infer security performance, RED conformity, EN 18031 coverage, or CRA status.
Action. The buyer holds the identifiable 54-carton FW-1.6 subset. If the supplier cannot separate it from the remaining shipment, the hold expands to all 180 cartons.
The responsible manufacturer or technical owner supplies a controlled configuration decision, and the factory segregates the identified carton range before a targeted recheck.
Result. The recheck compares the model code, radio-module reference, firmware-build display, label revision, carton range, supplier-lot record, and approved release card. It yields a bounded physical evidence record only.
Illustrative only. This is not a client case, cybersecurity test result, RED or CRA conformity conclusion, regulatory report, or market-approval outcome.
A useful China-side IoT inspection scope names the controlled product configuration, selected visible checks, evidence references, sample basis, and hold conditions before the visit.
Attach the approved configuration card; product model and radio-module identifiers; device path for showing the firmware build; app, cloud, and label references; declaration and standards references; carton and supplier-lot plan; sampling instructions; required photos; and named escalation contacts. Use inspection standard guidance to make the physical acceptance points observable. For a China-side configuration-to-unit comparison, request an IoT configuration inspection quote.
TradeAider is a quality inspection, testing, and certification service provider in China, with coverage across Guangdong, Zhejiang, Jiangsu, Shandong, and Fujian. Its nationwide network of quality control specialists provides real-time reporting for scoped quality-control work.
Inspection & QA Services are offered at an all-inclusive rate of $199/man-day. The company reports an 18% Amazon inspection fee discount and a 23% re-inspection rate reduction as client-reported outcomes. TradeAider is an Amazon Service Provider Network (SPN) partner.
The FAQ keeps RED duties, EN 18031 standard references, CRA timing, and physical inspection in separate accountable lanes.
No, the relevant EN 18031 part depends on the RED essential requirement, the equipment category, and the scope described in the applicable standard reference. The three listed parts support different Article 3(3) requirement areas and the implementing decision states limitations to presumption of conformity. A product owner should confirm the actual device scope and version with the responsible technical or regulatory function; a visible device mark or factory record does not resolve that question.
No, an inspection can document selected configuration and lot facts but cannot perform a cybersecurity assessment, validate a test method, or certify legal conformity. A well-scoped visit can compare model, module, firmware display, label, pack, carton range, and lot record with a controlled evidence card. It should report a missing link or mismatch for owner review rather than translate it into a passing or failing cybersecurity conclusion.
CRA reporting obligations apply from 11 September 2026, while the Act’s main obligations apply from 11 December 2027. The dates are important for manufacturer governance and reporting preparation, but they do not change the boundary of a current factory inspection. Keep the CRA timeline, responsible owner, and relevant configuration references in a controlled record, then obtain technical, regulatory, or legal advice for the particular product and obligations.
An IoT PSI should compare selected unit identifiers, module and firmware evidence, label artwork, packing, carton range, and supplier-lot records with the controlled configuration card. It should also state the sample basis, exact visible check points, required photos, and hold trigger. The report can show whether selected physical evidence corresponds with the supplied configuration; it cannot replace testing, conformity assessment, CRA reporting, or an EU market-release decision.
Нажмите кнопку ниже, чтобы войти непосредственно в систему услуг TradeAider. Простые шаги от бронирования и оплаты до получения отчетов легко выполнить.