5G Industrial Routers – EU Compliance at a Glance

Government Regulations, Standards, and Certifications – Organized by Level of Mandatory Compliance

What government regulations and certifications for 5G industrial routers are important in the EU?

Government Regulations, Standards, and Certifications – Organized by Level of Mandatory Compliance

Government regulations, standards & certifications – structured by binding nature

As of: July 2026 · Without guarantee, no legal advice

Contact 1ST-embedded experts

Last updated: 21.07.2026

In the EU, the following essentially apply to an industrial 5G router:

1 EU law (RED, RoHS, WEEE, REACH, possibly ATEX)

2 Harmonized standards and additional certifications

1. Government regulations for 5G industrial routers in the EU

1.1 Radio Equipment Directive (RED) 2014/53/EU for every router with radio

- Applies to placing on the market in the EU (manufacturer/importer) and indirectly also for operators.

- Covers three central areas:

  • Health & safety (including electrical safety) – Art. 3(1)(a)

  • EMC (emission/immunity) – Art. 3(1)(b)

  • Efficient and interference-free use of the radio spectrum – Art. 3(2)

- Obligations include:

  • CE marking on the device

  • EU Declaration of Conformity (DoC)

  • Technical documentation (risk analysis, test reports according to standards)

  • Labeling of type/batch and manufacturer/importer address

For a 5G router, the RED is the central legal basis.

1.2 Cybersecurity according to RED (Delegated Regulation (EU) 2022/30)

The RED has been supplemented with specific cybersecurity requirements:

- Delegated Regulation (EU) 2022/30 activates Art. 3(3)(d),(e),(f) RED for, among other things, internet-enabled radio devices 

- Application after postponement by (EU) 2023/2444 from 1.08.2025

- Manufacturers must then demonstrate that the device:

  • Protects networks from damage (e.g., no easily exploitable router as a gateway),

  • Protects personal data and privacy,

  • Makes abuse for fraud more difficult (e.g., authentication, protection against manipulation).

From 2025/2026, 5G industrial routers Security-by-Design and defined protective measures must be technically verifiable implemented.

1.3 Substance and environmental protection

- RoHS Directive 2011/65/EU + (EU) 2015/863

  • Limitation of lead, mercury, cadmium, certain flame retardants, etc.

- WEEE Directive 2012/19/EU

  • Manufacturer responsibility for old devices (registration in the WEEE system, labeling "crossed-out trash can").

- REACH Regulation (EG) 1907/2006

  • Obligation to provide information on substances of very high concern (SVHC) in components.

These are not "certificates", but legally binding requirements.

1.4 Special operating environments

- ATEX Directive 2014/34/EU

  • when the router is used in explosion-prone areas.

- Sector regulations:

  • Rail: e.g., EN 50155/EN 50121,

  • Energy substations: IEC 61850-3 / IEEE 1613,

  • Maritime applications: Marine Equipment Rules.

These are not always mandatory, but often effectively required by tenders or safety regulations.

1.5 Frequency usage / national regulators

- The router must only use approved bands and permissible transmission powers (BNetzA, ARCEP, AGCOM, etc.).

-In campus/private 5G networks (e.g., 3.7–3.8 GHz in Germany), your company may need a radio license from the national regulator.

However, this is a question of operator certification, not device certification.

2. Important harmonized standards for 5G industrial routers

To comply with the RED and other directives, manufacturers rely on harmonized standards. An industrial 5G router should typically be tested according to the following standards:

2.1 Safety

- EN/IEC 62368-1 – Audio/Video, Information and Communication Technology – Safety

Considered a modern safety standard for IT/communication devices and listed as a harmonized safety standard under the RED.

2.2 EMV (Electromagnetic Compatibility)

- ETSI EN 301 489-1 – EMC basic standard for radio equipment   

- plus the relevant technical part of the EN-301-489 series (e.g., for mobile devices).

2.3 Radio spectrum / 5G interface

- ETSI EN 301 908-25 – IMT cellular networks; Harmonized Standard for access to radio spectrum; Part 25: New Radio (NR) User Equipment (UE) Release 15

  • De facto mandatory standard for 5G devices.

- Additional parts of the EN-301-908 series for 4G/3G fallback, if the router supports this.
- If applicable, additionally:

  • EN 62311 (Human exposure to EM fields),

  • ETSI EN 303 413 for GNSS, if GPS/GLONASS is integrated.

If these standards are met, the presumption of conformity with the corresponding RED requirements applies.

3. Cybersecurity beyond the RED: CRA & Standards

3.1 Cyber Resilience Act (CRA) – Looking ahead

- Regulation (EU) 2024/2847 (Cyber Resilience Act) establishes horizontal cybersecurity requirements for all "products with digital elements" starting from December 11, 2027 – this clearly includes industrial 5G routers.  

- Obligations include:

  • Security-by-Design (risk assessment, secure development process),

  • Vulnerability management and update provision,

  • Documentation of security functions.

If you are specifying or developing new industrial routers today, you should already pay attention to CRA compatibility, even if the application only becomes mandatory in 2027.

3.2 ETSI EN 303 645 (IoT Cybersecurity)

- ETSI EN 303 645 defines basic security requirements for connected consumer IoT devices and is widely used as a reference for device security.

- It is primarily designed for consumer devices but can also serve as a baseline checklist for routers (password policy, update concept, logging, hardening, etc.) and is expected to play a role in the implementation of RED/CRA.

4.Important certifications for industrial 5G routers

4.1 Mandatory for the EU market

Certification / Proof

Mandatory?

Significance

CE marking (incl. RED)

Yes

Legal requirements for placing on the market in the EU. The basis is RED, RoHS, possibly ATEX, etc.

EU Declaration of Conformity (DoC)

Yes

The manufacturer formally declares compliance with all relevant directives/regulations. Must be presented upon request.


4.2 Very relevant, but formally voluntary certifications

These certifications are not legally mandatory, but are often expected in the industrial environment and can be very helpful for CRA/RED-Cyber in the future:

a). IEC 62443 certification (industrial IT security)

- Series of standards for "Industrial communication networks

- Network and system security", including:

  • IEC 62443-4-1(secure development process),

  • IEC 62443-4-2 (security requirements for components such as routers/firewalls).

- There are specific certification programs for devices according to 62443-4-2; the first industrial routers have already been certified accordingly.

- Recommendation: For OT networks (production facilities, critical infrastructures), an IEC-62443-4-2 certification is a strong quality feature.

b) GCF / PTCRB and network operator approvals (mobile communication)

- GCF (Global Certification Forum)or PTCRB (mainly USA) check conformity with the 3GPP specification and the radio interface – many network operators require such certification for devices in their networks.

- Additionally, operators (Vodafone, Deutsche Telekom, Orange, etc.) often grant their own "Device Approval" approvals.

c) CB-Scheme / national security certificates

- CB certificates based on IEC 62368-1 facilitate global market access (UL/CSA/CCC, etc.).

d) ETSI/IoT security certificates (EN 303 645, national labels)

- Certificates according to ETSI EN 303 645 or national markings (e.g., BSI IT security marking in Germany) demonstrate a minimum level of cybersecurity; while they are not standard in the industrial context, they are an additional advantage.

e) Manufacturer management systems

- ISO/IEC 27001 (Information Security Management),

- ISO 9001(Quality Management).

These certificates pertain to the organization, not the individual device, but are often a knockout criterion in tenders.

f) Special certifications depending on industry/environment

- ATEX/IECEx for explosive atmospheres,

- EN 50155/50121 (Railway),

- IEC 61850-3 / IEEE 1613 (Energy substations).

5. Practical checklist for your specification

When selecting or specifying industrial 5G routers, you may require:

5.1 Legal minimum basis

- CE marking with reference to RED 2014/53/EU (including cybersecurity from 1.8.2025),

- Compliance with RoHS, WEEE, REACH,

- Provision of the EU declaration of conformity and list of applicable standards
(e.g., EN 301 908-25, EN 301 489-x, EN IEC 62368-1, EN 62311).

5.2 Cybersecurity

- Evidence of a secure development process (e.g., IEC 62443-4-1),

- GDevice certification according to IEC 62443-4-2 or a comparable scheme,

- Security features: Hardening, role/permission model, encrypted management interfaces, update concept, logging.

5.3 Network operator/radio compatibility

- GCF/PTCRB certification (when using public mobile networks),

- if applicable, specific network operator approvals.

5.4 Future-proofing (CRA readiness)

- Manufacturer's declaration that the product and development process are designed to meet the requirements of the Cyber Resilience Act (risk management, patch policy, vulnerability disclosure process, etc.).

We have researched this information for the products we offer and recommend this valuable information to you.
This blog post makes no claim to completeness and we exclude any liability for the information listed herein and its use.

~~

Sources

Cyber Resilience Act
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Cyber_Resilience_Act/cyber_resilience_act_node.html

Public 5G telecommunications networks
https://www.bsi.bund.de/dok/5G

The Cyber Resilience Act & FAQ
https://digital-strategy.ec.europa.eu/en/policies/cra-summary

SGS - Testing, Inspection and Certification company
https://www.sgs.com/en/news/2025/07/sgs-awards-robustels-industrial-router-with-red-cybersecurity-certification

Cyber Resilience Act Requirements, Standards Mapping, 4/2024
https://www.enisa.europa.eu/sites/default/files/2024-11/Cyber%20Resilience%20Act%20Requirements%20Standards%20Mapping%20-%20final_with_identifiers_0.pdf

Guide to the Radio Equipment Directive (RED)
https://www.nabto.com/radio-equipment-directive-red/

~~

Robustel industrial mobile routers

Get informed and equip your business with efficient 5G connectivity.

Consult your expert: Sven Trommer, Tel. +49407003550

We look forward to hearing from you!

Jelena Dronowa, Head of Digital Media, Dipl.-Ing in Systems Engineering

Detailed Infographic: 5G Industrial Routers – EU Compliance at a Glance

Detailed Infographic: 5G Industrial Routers – EU Compliance at a Glance

As of: July 2026 · Without guarantee, no legal advice.