Without formal compliance, a wireless device cannot be sold legally — working firmware and a stable cloud are not enough. IoT device certification covers radio testing, electromagnetic compatibility (EMC), product safety, and — since 2025 — cybersecurity, and its scope differs between the European Union (the CE mark) and the USA (FCC). This guide organizes the requirements, standards, costs, and timeline.

In short: IoT device certification is the process of confirming compliance with the RED directive 2014/53/EU (the CE mark) in the EU and with the FCC Part 15 rules in the USA; typical testing covers standards from the EN 300, EN 301 489, EN IEC 62368-1, and EN 18031 (cybersecurity) series, and a full cycle usually takes 4 to 12 weeks and costs from a few to a dozen or so thousand euros per region.
What is IoT device certification?
IoT device certification is a set of mandatory conformity assessments confirming that a wireless product meets the target country's legal requirements for radio spectrum, EMC, safety, and data protection. In practice it is a condition for legally placing the product on the market, not a quality mark.
For a device with a radio (Wi-Fi, Bluetooth Low Energy, LoRa, NB-IoT, or Wi-Fi HaLow), the scope of testing is broader than for a wired product, and the entire path must be documented in the technical documentation and the declaration of conformity.
What do the RED directive and the CE marking cover?
The RED directive (Radio Equipment Directive 2014/53/EU) is the fundamental legal act for radio equipment in the EU, and the CE mark denotes the manufacturer's self-declaration that it has met its requirements. RED defines three main groups of requirements: safety and health (Art. 3.1a), electromagnetic compatibility (Art. 3.1b), and the efficient use of spectrum (Art. 3.2).
Since 1 August 2025, the cybersecurity requirements of Art. 3.3 (d, e, f) have become mandatory, confirmed by the EN 18031-1/2/3 standards — every IoT device connecting to a network must meet minimum standards for protecting the network, data, and privacy.
Using harmonized standards, the manufacturer can often assess conformity on its own (module A); when they do not cover all radio functions, a Notified Body is required. Data protection is worth planning together with the IoT security and compliance architecture.
What requirements does FCC Part 15 impose in the USA?
FCC Part 15 is the US regulation for devices emitting radio waves, dividing equipment into unintentional radiators (subpart B) and intentional radiators (subpart C). Wi-Fi and BLE modules operating in the 2.4 GHz band usually fall under section 15.247.
Unlike the CE self-declaration, most intentional radiators in the USA require certification by an accredited TCB (Telecommunication Certification Body) and the assignment of an FCC ID. Canada uses ISED RSS standards (e.g., RSS-247) and an IC number, and the UK market after Brexit — the UKCA marking.
What standards and tests must an IoT device pass?
IoT device certification relies on several parallel families of standards that test different aspects of the product. The list below shows a typical scope for a device with a 2.4 GHz radio and mains power:
- Radio (spectrum): EN 300 328 for the 2.4 GHz ISM band, EN 300 220 for sub-GHz (863–870 MHz).
- EMC: the EN 301 489 series (immunity and emission of electromagnetic disturbances).
- Safety: EN IEC 62368-1 for electronic and IT equipment.
- RF exposure: EN 62311 or EN 62479 (electromagnetic field assessment, SAR for wearables).
- Cybersecurity: EN 18031-1/2/3 in line with RED Art. 3.3.
A well-designed IoT PCB — with proper grounding, filtering, and shielding — can significantly reduce costly rework after failed EMC tests.
How much does IoT device certification cost and how long does it take?
The cost of IoT device certification depends on the number of markets, the radio bands, and whether the device uses a ready-made radio module. In practice, for a single region and a single radio, the budget usually falls in the 5,000–20,000 EUR range, and the testing cycle takes 4 to 12 weeks.
The most effective way to cut costs is to use a pre-certified radio module (e.g., ESP32 modules with ready FCC and CE IDs). Thanks to so-called modular approval, the end device inherits part of the module's certification and undergoes only a limited scope of testing (mainly host EMC and unintentional emissions).
- Pre-scan (EMC/radio): early lab testing catches problems before the design is frozen.
- Formal testing: full testing in an accredited laboratory against the relevant standards.
- Documentation and declaration: compiling the reports, the EU declaration of conformity, and applying the CE mark or FCC ID.
How to design a device for certification?
Design for compliance is an approach in which certification requirements are considered from the first schematic, not after a prototype is built. Accounting for EMC, access to the radio's test mode, and security updates at an early stage eliminates the most expensive iterations.
It is worth planning the mechanisms required by EN 18031 from the start: secure boot, encrypted storage, and signed firmware updates — ideally in parallel with the transition from prototype to production, so that scaling does not require a hardware redesign.
Frequently asked questions (FAQ)
Can the CE mark for IoT be applied by yourself?
Yes, in many cases the manufacturer applies the CE mark based on its own declaration of conformity, if it has used harmonized standards covering all radio functions. When the standards do not cover a given function or band, a Notified Body is required to assess the technical documentation.
Is an FCC certificate valid in the European Union?
No. FCC Part 15 applies only to the US market, and the EU requires the CE marking compliant with the RED directive. These are separate regimes with different standards and procedures, which is why a global product requires parallel certification paths for each target region.
Does a pre-certified radio module exempt you from testing?
Not entirely. Modular approval transfers the radio's certification to the end device, but the host still has to pass EMC and unintentional-emission testing. It is, however, a significantly cheaper and faster route than certifying your own radio circuit from scratch.
Summary and key takeaways
IoT device certification is a mandatory stage of commercialization, not a formality at the end of the project. The CE mark (the RED directive, including EN 18031 cybersecurity from 2025) opens the EU market, FCC Part 15 the US market, and the cheapest route is usually to use a pre-certified radio module and design with EMC in mind from the first schematic.
FSS designs IoT hardware, firmware, and cloud with compliance built into the process — from custom IoT device design to industrial and hospitality integrations. If you plan to bring a wireless product to the EU or US market, contact us and explore our IoT integration capabilities to plan certification without costly delays.