Back to blog
    28 July 2026Michael Devid10 min read

    CE and FCC in Plain Words: When You Can Sign It Yourself

    Nobody hands you a CE certificate — you sign it. The rule that decides whether you can sign alone or need a notified body, worked through on an LTE-M tracker.

    certificationCEFCCcomplianceREDCRAIoT

    Nobody gives you a CE certificate. There is no exam and no inspector at the door.

    You write a file about your product. You sign a paper that says it follows the rules. You print the CE logo on it. Done.

    That's the normal path, and it's called self-certification. It works for most products.

    Sometimes you're not allowed to sign alone. Then you have to pay an outside company — called a notified body — to check your file and sign first. That adds a substantial cost and two to six months to the schedule.

    So the only question that really matters on any project is: can we sign this ourselves, or do we have to pay someone?

    Self-certification is not the same as "free"

    One thing to be clear about, because it trips up nearly every startup.

    Self-certification does not mean you skip testing, and it is not free. You still put the product through a lab, and the lab work is the real budget line on a connected product.

    Self-certification only decides who signs at the end. A notified body's fee comes on top of the testing, not instead of it.

    The one rule that decides it

    • Europe: you need an outside body when there's no standard that fits your product.
    • America: you need an outside body when your product transmits at all.

    That's the whole difference, and everything else follows from it.

    Europe's logic is worth understanding, because it isn't obvious. A standard is a public agreement on what "safe" and "well-behaved" mean for a type of product. Europe treats the standard itself as the expert. Follow it exactly and you can sign alone. Step outside it and you have to go buy an expert opinion instead.

    Note what this means: it has nothing to do with how dangerous your product is. A harmless little sensor in an unusual radio band needs an outside body. A 2000-watt mains heater doesn't.

    Boring radio — Bluetooth, Wi-Fi, LTE. Cheap in Europe: sign it yourself. Expensive in America: you must use a certification body, no exceptions.

    Unusual radio — a new band, a new modulation. The other way round. America charges roughly the same flat fee. Europe's cost explodes into a notified body.

    Put simply: Europe punishes doing something new with radio. America punishes using radio at all.

    When can you sign it yourself?

    Always yours to sign

    Safety and electromagnetic interference (EMC). You can never be forced to use an outside body for these two. Not even if no standard exists. If a standard is missing, you just have to write a good explanation in your file instead.

    This surprises people, and it saves real money. RED Art 17(2) is the reason.

    Depends on the standard

    Radio behaviour (does it use the airwaves properly) and cybersecurity.

    You can sign these yourself, but only if a fitting standard exists, is officially listed, covers your product, and you follow it completely. Fail any one of those and you need an outside body. RED Art 17(4).

    Always an outside body

    Medical devices above the lowest risk class. Machine safety parts that use machine learning. Anything that moves money. And in America, anything that transmits.

    Here it's the product type that triggers it, not the standards. No amount of standards work gets you out.

    The five ways people trip on the middle one

    1. No standard exists for your band and your use.
    2. A standard exists, but it's not on the official EU list right now. Published is not the same as listed.
    3. Your product falls outside what the standard says it covers. Then, for you, the standard may as well not exist.
    4. You followed most of it. "Partly" counts as "not at all" here. One skipped test is enough.
    5. The standard is listed, but with a warning note attached to the exact part you relied on.

    That fourth one catches good engineers. A lab report that says "tested to EN 300 xxx except clause 5.3.2" has quietly moved you from a free signature to a paid one.

    The cybersecurity part

    This is the bit that changed, and it confuses everyone because there are two rules doing the same job at different times.

    Now: the RED cybersecurity rules

    Since 1 August 2025, any radio product that can reach the internet has to meet three security requirements. People call this "RED+".

    • Don't harm the network. Applies to anything that can reach the internet, directly or through something else.
    • Protect personal data. Applies if the product handles personal, traffic or location data. Also applies to wearables, toys and childcare products even with no internet.
    • Protect against fraud. Only applies if the product itself can move money.

    You prove this with a standard called EN 18031. You can sign it yourself, with one catch.

    Design rule that saves you a notified body Never let a user skip setting a password. If your product offers a "no password" option, you lose the right to sign alone.

    And no, having no login at all isn't a clever way around it. That reads as "the user is allowed not to set a password" too.

    The money one is different: if your product can move money or virtual currency, an outside body is basically unavoidable. Budget it from day one.

    Later: the Cyber Resilience Act (CRA)

    The CRA is the bigger, permanent version. It replaces the RED cybersecurity rules on 11 December 2027, same day, no gap.

    So the answer to "do I do EN 18031 now or wait for the CRA?" is: both, one after the other. You can't wait. The current rules have been binding for a year already.

    Two things about the CRA that people get wrong:

    • It covers everything with digital bits, not just radio. Wired products too.
    • Most ordinary sensors and trackers are in the lowest tier, where you can always sign yourself. The scary "must use an outside body" tiers are for things like firewalls, hypervisors and secure chips.

    Three dates worth putting in the calendar

    Date What happens
    11 Sep 2026 CRA incident reporting starts. If a vulnerability in your product is being actively exploited, you have 24 hours to raise a flag and 72 hours to report properly. This applies to products already out in the field, not just new ones.
    12 Sep 2026 Data Act. Connected products sold after this date must be built so the user can get at their own data. This is a firmware and architecture job, not paperwork, and the one most people haven't heard of.
    11 Dec 2027 CRA takes over fully and the RED cybersecurity rules are switched off the same day.

    The check that saves you the most money

    Before you quote any job, spend twenty minutes confirming that the standards your lab plans to use are actually on the EU's current list, in the version they plan to use.

    This sounds like admin. It isn't. It's the single thing that decides whether a project runs at its normal cost or roughly double it, and lists change every few months.

    Three traps to check for:

    • Old version still listed. For several radar standards, the EU still points at a pre-2016 version. Your lab will default to the newer one, which counts for nothing.
    • Warning notes. A standard can be listed but carry a note saying it doesn't cover part of the requirement. That part is then your problem.
    • Delayed removals. Modern EU decisions hide the "this version dies on date X" bit in Article 2 of the decision, not in the table. Read Article 2.

    Worked case: an LTE-M / NB-IoT tracker with GPS

    The everyday job. Battery-powered asset tracker, cellular back to a server, GPS for position.

    Verdict: no outside body needed. Standards exist for every part of this product, they're on the current EU list, and they fit. So you sign the declaration yourself, as long as you don't trip one of the four gotchas below.

    Timeline is roughly 16–22 weeks from design freeze to CE and FCC in hand, and nearly all of it is lab time rather than paperwork.

    What actually applies

    Area Standard
    Safety EN IEC 62368-1 — the normal electronics safety standard. Battery charging is what makes this get expensive.
    Interference EN 301 489-52 for the cellular side, EN 301 489-19 for the GPS side. Both listed. Both carry a note about their clause 6. Your lab knows what to do, but check the report says so.
    Cellular radio EN 301 908-13, version V13.2.1 or V13.3.1, both listed. LTE-M and NB-IoT are both LTE, so this is the right one.
    GPS receiver EN 303 413 V1.2.1 — clean, no warning notes at all. Rare, and worth knowing.
    Cybersecurity EN 18031-1 and -2. See gotcha 1 — most people only do the first.
    Paperwork Technical file, declaration of conformity, RoHS, WEEE registration, battery rules.

    1. A tracker handles location data, so you need both security parts

    The cybersecurity rules have three parts. Most people building a connected device do part 1 — "don't harm the network" — and stop.

    But a tracker's whole job is producing location data. That triggers the privacy requirement too, which is EN 18031-2. It's a separate document with separate requirements, and you can't copy your part-1 answers into it: even the shared requirements have different wording, and the pass/fail logic genuinely differs between them.

    This is the most common miss on tracker projects.

    Design rule Never ship a "skip password" option in the setup flow or the config app. If a user can decline to set credentials, you lose self-certification.

    2. Use a pre-approved cellular module, but understand what you inherit

    Building your own cellular radio is the expensive path. Using a ready-made module — Nordic, Quectel, u-blox — is much cheaper and faster.

    The catch differs by continent:

    • America — real inheritance. There's a proper legal mechanism. If you use the module exactly as it was approved — same antenna, same conditions — you inherit its approval and just mark your product "Contains FCC ID…". Change the antenna and you're filing again.
    • Europe — no such thing. There is no module approval scheme. The module's CE does not discharge you. You become the manufacturer of the finished product and owe a fresh assessment. What you inherit is evidence — the module's test reports save you real testing money, but you still sign for the whole thing.

    So: buy the module for the test-cost saving, not because you think it makes the paperwork disappear in Europe. It doesn't.

    3. Standards versions get retired, quietly

    A live example from this exact product: the GPS receiver standard EN 303 413 V1.1.1 was withdrawn on 10 May 2024. If your file still cites it, that file is defective, even though the document still exists and still downloads fine.

    The current one is V1.2.1. The same thing happened to EN 301 908-13 V13.1.1 on the same date.

    Check the list before every quote. Citing a dead version is a formal failure on its own, regardless of how good your testing was.

    4. The battery brings its own rulebook

    Nothing painful yet, but two dates:

    • 18 February 2027 — the user has to be able to replace the battery. There is an exemption shaped for IoT devices (wet environments, needing continuous power), but you have to actually qualify for it, and that's a mechanical design decision.
    • The recycling symbol is already required.

    Good news: for a small embedded battery there's no carbon footprint declaration and no battery passport. Those hit big batteries.

    Two dates that apply even to trackers you already shipped

    • 11 Sep 2026 — incident reporting. If someone is actively exploiting a hole in your tracker, you have 24 hours to flag it. This covers your installed base, not just new units. You need a process and a named person, not a document.
    • 12 Sep 2026 — data access. Trackers sold after this date have to let the customer get at their own data. For a tracker this is very much on-point — position history is exactly what the rule is about. Firmware and API work, so start early.

    Where the effort actually goes

    Almost all of it is lab time. None of it is the signature. Roughly in order of weight:

    1. Interference testing. The biggest single line, and more again if the product runs off mains.
    2. Safety. Modest for a simple DC board; several times that once lithium charging is involved.
    3. Cellular and GPS radio testing. Straightforward for a standard module.
    4. Cybersecurity file. Nearly all of it goes on listing your software components and checking each for known vulnerabilities. Routinely underestimated. A normal device throws up thousands of hits to triage.
    5. Technical file and declaration. Engineering time, and it can overlap with the testing.
    6. Pre-compliance scan before design freeze. The cheapest money you will ever spend. Catches interference problems while they're still a PCB revision instead of a re-spin.
    7. America, if you integrate an approved module. Designing your own cellular radio instead multiplies this several times over.

    Rolling your own radio rather than buying a module pushes the total up sharply. That's the real argument for buying a module.

    For comparison: needing an outside body would add its own fee and several months on top of all of the above. That's what the four gotchas are protecting.

    Book the lab early. Chamber slots run two to six weeks out. That's usually the longest single delay in the whole project, and it's the easiest to fix. Book it at design freeze, not when the boards arrive.

    One more shortcut

    Pick a lab that is a European notified body and a US certification body and a Canadian one. Then one set of measurements feeds all three markets. It saves a whole repeat campaign.


    Checked against EU and US primary sources on 28 July 2026. Rules move, so re-check the standards list before you rely on this for a quote.