Wireless and Radio Compliance
Wireless and radio compliance encompasses the regulatory requirements that govern the design, testing, and certification of devices that emit radio frequency (RF) energy. These regulations exist to ensure that wireless devices operate within allocated spectrum bands, do not cause harmful interference to other radio services, and protect human health from excessive RF exposure. Compliance is mandatory in virtually every country, and products cannot be legally sold or operated without appropriate certification.
The regulatory landscape for wireless devices is complex and varies significantly by region. In the United States, the Federal Communications Commission (FCC) regulates radio equipment. In Europe, the Radio Equipment Directive (RED) establishes requirements enforced through CE marking. Other major markets including Japan, China, South Korea, and Australia maintain their own certification regimes. Despite these regional differences, the underlying technical requirements share common foundations based on international standards from organizations such as the International Telecommunication Union (ITU) and the International Commission on Non-Ionizing Radiation Protection (ICNIRP).
Human Exposure Limits
Protecting human health from RF exposure is a primary concern of wireless regulations. Exposure limits rest on a well-established thermal rationale: at radio frequencies the dominant established hazard is tissue heating, so the basic restrictions are set at a fraction of the exposure that produces a measurable temperature rise. Two derived metrics implement those restrictions in practice, and which one applies depends on the operating frequency and the typical separation between the device and the user.
Almost every national limit traces back to one of two source frameworks: the guidelines of the International Commission on Non-Ionizing Radiation Protection (ICNIRP), revised in 2020 to replace the 1998 edition, or the IEEE C95.1 standard. The two frameworks have converged substantially, though regional rules still lag behind the source documents by several years because adopting a revision requires a rulemaking in each jurisdiction.
Specific Absorption Rate (SAR)
Specific Absorption Rate measures the rate at which RF energy is absorbed by body tissue when a device operates in close proximity to the body. SAR is expressed in watts per kilogram (W/kg) and is the governing metric for devices used within 20 centimeters of the body, such as mobile phones, tablets, smartwatches, and other portable wireless devices.
SAR limits are stated separately for whole-body average exposure and for localized peak spatial-average exposure, and each has a general-population value and a less restrictive occupational value. In the United States, the FCC applies a general-population localized limit of 1.6 W/kg averaged over 1 gram of tissue, a whole-body average limit of 0.08 W/kg, and a 4 W/kg limit averaged over 10 grams for the hands, wrists, feet, and ankles. ICNIRP and the European regulations that follow it specify 2.0 W/kg averaged over 10 grams for the head and torso, 4 W/kg over 10 grams for the limbs, and the same 0.08 W/kg whole-body average. The localized values differ mainly because of the different averaging masses: a 1-gram average captures sharper spatial peaks than a 10-gram average, so a numerically lower limit is required to express a comparable degree of protection.
The 2020 ICNIRP revision extended the whole-body SAR restriction across the full 100 kHz to 300 GHz range, where the 1998 edition had applied it only up to 10 GHz. It also added restrictions on absorbed power density for frequencies above 6 GHz, where energy deposits in the outermost few millimeters of tissue and SAR ceases to be a meaningful predictor of temperature rise, and it added a restriction on brief exposures shorter than the six-minute averaging window so that transient heating cannot reach painful levels. These additions were motivated directly by millimeter-wave 5G deployments.
SAR testing requires specialized equipment including anthropomorphic phantoms filled with tissue-simulating liquid, robotic positioning systems, and calibrated electric field probes. The consolidated procedure is IEC/IEEE 62209-1528:2020, which covers 4 MHz to 10 GHz for hand-held and body-worn devices operated with their radiating structures up to 200 millimeters from the head or body. That edition replaced the earlier split between IEC 62209-1 for head exposure, IEC 62209-2 for body-worn exposure, and IEEE Std 1528. Above roughly 6 GHz, separate measurement and computational standards address power density rather than SAR. The highest SAR value recorded across the specified test conditions must be reported and must remain below the applicable limit with the device transmitting at maximum power.
Design techniques to reduce SAR include placing antennas away from likely body contact points, adding proximity or grip sensors that back off transmit power when the device is close to the body, and shaping the ground plane and radiation pattern to direct energy away from the user. Multi-antenna and multi-radio products face an additional burden, since simultaneous transmission requires either a summed SAR assessment or a demonstration that the radios cannot transmit together at full power. These considerations must be addressed early, because SAR is dominated by device geometry and antenna placement and cannot easily be corrected once the mechanical design is frozen.
Maximum Permissible Exposure (MPE)
Maximum Permissible Exposure limits apply to devices that operate at greater distances from the body, typically fixed or mobile transmitters where users are not in direct contact with the radiating antenna. MPE is expressed as power density in milliwatts per square centimeter (mW/cm2) or, at lower frequencies where the far-field relationship between the fields does not hold, as separate electric and magnetic field strengths.
MPE limits are frequency-dependent, with different values for controlled environments (occupational exposure) and uncontrolled environments (general public exposure). In the FCC limits, the general-population power density is 0.2 mW/cm2 across 30 to 300 MHz, rises linearly as frequency divided by 1,500 between 300 and 1,500 MHz, and is 1.0 mW/cm2 from 1,500 MHz to 100 GHz. The corresponding occupational values are five times higher, reaching 5.0 mW/cm2 above 1,500 MHz. The most restrictive region, roughly 30 to 300 MHz, corresponds to whole-body resonance, where a standing adult absorbs energy most efficiently.
Averaging time matters as much as the limit itself. Occupational exposure is averaged over any six-minute period, while general-population exposure is averaged over thirty minutes. A transmitter may therefore exceed the instantaneous limit provided the time-averaged exposure over the applicable window remains compliant, which is how duty-cycled and beam-scanning systems demonstrate conformity.
Compliance with MPE requirements can be demonstrated through measurement or calculation. For fixed installations, site surveys measure field strengths at accessible locations, and the results define compliance boundaries, signage, and access restrictions. For portable and mobile equipment, MPE evaluation determines the minimum separation distance at which exposure falls below the limit. That distance must be communicated to users through product labeling and documentation, which is the origin of the familiar instruction to keep a device a specified distance from the body.
The FCC restructured its exposure procedures in a 2019 Report and Order, replacing the former list of categorical exclusions with a general set of exemption criteria in 47 CFR 1.1307(b) that apply uniformly across services. The amended rules took effect in May 2021, with a transition period for existing installations and previously authorized devices. An exemption relieves an operator only of the duty to perform a routine exposure evaluation; the underlying exposure limits, and the obligation to obtain equipment authorization, continue to apply.
Products that operate at higher power levels or place antennas near occupied areas require careful MPE analysis. Base stations, outdoor access points, and industrial RF equipment typically need detailed assessments that consider every operating mode, antenna configuration, and plausible exposure scenario. Massive MIMO and beamforming arrays complicate this analysis further, because the worst-case instantaneous beam is far stronger than the time-averaged field, and realistic assessments depend on statistical models of beam usage rather than on peak radiated power alone.
Transmitter Certification
Before a wireless device can be legally marketed and operated, it must receive authorization from the relevant regulatory authority. The certification process verifies that the device meets all applicable technical requirements including spectrum usage, emissions limits, and RF exposure compliance.
FCC Equipment Authorization
The FCC operates two authorization paths. Supplier's Declaration of Conformity is a self-declaration route that covers unintentional radiators such as digital devices, and it consolidated the older Verification and Declaration of Conformity procedures. Certification, the stricter path, is required for essentially all intentional radiators, including Wi-Fi and Bluetooth devices, cellular handsets, and short-range transmitters. Certification involves testing at a laboratory accredited and recognized for the applicable rules, followed by submission of an application to an FCC-recognized Telecommunication Certification Body (TCB). TCBs, rather than the Commission itself, issue the grant in nearly all routine cases.
Required testing includes occupied and emission bandwidth, conducted and radiated output power, power spectral density, band-edge compliance, spurious and out-of-band emissions, frequency stability, and RF exposure. Devices must demonstrate compliance with the specific rule parts that govern their operation. Part 15 covers unlicensed operation, with Subpart C rules such as 15.247 applying to frequency-hopping and digitally modulated systems in the ISM bands and Subpart E rules such as 15.407 applying to the 5 GHz and 6 GHz U-NII bands. Licensed services fall under their own parts, including Part 22 for cellular, Part 24 for personal communications services, Part 27 for miscellaneous wireless communications services, and Part 90 for private land mobile radio.
Certified devices must bear an FCC ID composed of a grantee code and a product code, and the grant and exhibits become publicly searchable in the Commission's equipment authorization database. Detailed interpretations of the test rules are published as Knowledge Database (KDB) guidance, which laboratories and TCBs treat as binding in practice even though it is not codified. Any change that could affect RF characteristics must be evaluated to determine whether it can proceed as a permissive change or requires a new application.
Equipment authorization also serves non-technical policy objectives. Following the Secure Equipment Act of 2021, the Commission adopted rules barring authorization of communications equipment identified on its Covered List as posing an unacceptable national security risk. Manufacturers must therefore confirm that neither the product nor its identified components fall within that prohibition before applying.
European Radio Equipment Directive
The Radio Equipment Directive (RED) 2014/53/EU establishes requirements for radio equipment placed on the European market. Article 3 sets out the essential requirements in three tiers: Article 3(1) covers health and safety and electromagnetic compatibility, Article 3(2) covers the effective and efficient use of radio spectrum, and Article 3(3) contains additional requirements that the Commission may activate for specific equipment categories through delegated acts. A manufacturer must satisfy all applicable tiers, draw up an EU Declaration of Conformity, and affix the CE mark before placing the product on the market.
Conformity assessment follows one of three routes. Internal production control, Module A, is available only when harmonized standards have been applied in full to every applicable essential requirement; the manufacturer then performs or commissions the necessary assessment itself, and third-party testing, though customary, is not legally compulsory. Where no harmonized standard exists, where one has been applied only in part, or where its reference has been withdrawn or restricted, the manufacturer must instead use EU-type examination by a Notified Body combined with conformity to type, or full quality assurance. Radio equipment operating on non-harmonized frequencies carries a further obligation to notify the relevant member states before market placement.
RED compliance requires a technical file containing test reports, a design and construction description, a risk assessment, and user instructions, retained for ten years after the last unit is placed on the market. The EU Declaration of Conformity must identify the harmonized standards applied, by reference and dated version, or otherwise describe how the essential requirements were met. Article 10 sets out the general obligations of manufacturers, including the duty to ensure that equipment is designed and manufactured to the essential requirements and is accompanied by instructions and safety information in a language readily understood by end users, together with information on the frequency bands and maximum transmitted power.
Compliance with a harmonized standard confers a presumption of conformity, but only for the clauses covered by the reference published in the Official Journal of the European Union. References are sometimes published with restrictions that exclude specific clauses, in which case those aspects must be justified separately in the technical file. Tracking the status of harmonized standard references is therefore an ongoing compliance activity, not a one-time lookup.
International Certification
Global market access requires authorization in each target market. Mutual recognition agreements reduce duplicated testing in some cases, but most countries maintain independent certification regimes. Key markets include Japan, where the Ministry of Internal Affairs and Communications sets the rules and bodies such as TELEC issue the giteki mark; China, where the State Radio Regulation of China administers radio type approval and the CCC scheme covers product safety; South Korea and its KC mark; Australia and New Zealand and the RCM mark; and India, where the Wireless Planning and Coordination wing issues equipment type approval. Great Britain has operated its own regime since leaving the European Union, with the UKCA mark applied under the Radio Equipment Regulations 2017, while Northern Ireland continues to follow the EU rules.
International certification strategy should weigh the reuse of existing test data, in-country testing mandates, local representative requirements, frequency-band differences, and labeling obligations. Some regimes accept reports from laboratories accredited to ISO/IEC 17025 under a recognition arrangement, which substantially reduces the testing burden; others require testing at a locally designated laboratory or add market-specific measurements. Frequency planning is often the binding constraint, since a band edge or power level permitted in one market may be unusable in another, and a single hardware variant that satisfies every target market may not exist.
Industry and Operator Certification
Regulatory authorization establishes only that a device may lawfully be sold and operated. Devices that attach to a mobile network or use a licensed trademark face a second, entirely separate layer of approval imposed by industry bodies and network operators. The Global Certification Forum and the PTCRB program certify cellular device conformance to 3GPP specifications and to operator-specific requirements, and many carriers add their own acceptance testing before a device may be activated on the network.
Trademark licensing programs work the same way. Use of the Wi-Fi, Bluetooth, or USB logos requires qualification through the respective member organization, including interoperability testing and declaration of the product in a member database. These programs are contractual rather than statutory, but missing them can block a product as effectively as a failed regulatory test. Certification schedules for cellular and interoperability programs are frequently longer than regulatory testing, so they belong in the program plan from the outset.
Spectrum Allocation Compliance
Wireless devices must operate within spectrum allocations established by national regulators following the ITU Radio Regulations. The ITU divides the world into three regions, and allocations differ between them, which is why a band available in one continent may be assigned to an entirely different service in another. Understanding spectrum allocation is fundamental to wireless product development, since it determines which frequencies may be used, under what conditions, and with what technical parameters.
Licensed and Unlicensed Spectrum
Licensed spectrum is assigned to specific users or services through a licensing process, often by auction. Cellular networks, broadcast services, and many professional radio systems operate in licensed bands with exclusive or coordinated access rights. Devices operating in licensed bands still require equipment authorization, and they may generally be operated only by the license holder or by subscribers of the licensed service.
Unlicensed, or license-exempt, spectrum allows operation without an individual user license, subject to technical rules limiting power, bandwidth, out-of-band emissions, and in some regions duty cycle. Unlicensed operation is frequently described as taking place in the ISM bands, but the two terms are not synonymous. The ITU designates a specific set of industrial, scientific, and medical bands, including 902 to 928 MHz in ITU Region 2, 2.400 to 2.500 GHz, and 5.725 to 5.875 GHz, in which equipment radiating for non-communication purposes has priority and communication services must accept the resulting interference. Much modern unlicensed operation lies outside those designations: the 5 GHz U-NII bands at 5.15 to 5.35 GHz and 5.47 to 5.725 GHz and the 6 GHz band at 5.925 to 7.125 GHz are license-exempt but are not ISM bands.
Typical unlicensed bands include 2.400 to 2.4835 GHz for Wi-Fi, Bluetooth, and Zigbee; the 5 GHz U-NII bands; the 6 GHz band, opened for unlicensed use in the United States in 2020; and sub-GHz short-range bands such as 902 to 928 MHz in North America and 863 to 870 MHz in Europe. Sub-GHz bands are widely used for metering, sensor networks, and other long-range, low-rate applications because of their favorable propagation. No user license is required in any of these bands, but devices must still be certified against the applicable technical rules.
Allocations differ between regions, and a frequency permitted in one country may be unavailable, restricted to indoor use, or subject to different power limits elsewhere. Multi-region products must either operate within the intersection of all permitted parameters, which sacrifices performance in the more permissive markets, or implement region-specific configurations. The second approach carries its own regulatory obligation: the mechanism that selects the regional configuration must not be alterable by the end user, since a user-selectable country setting would allow the device to be operated outside its authorization.
Coordinated Access in the 6 GHz Band
The 6 GHz band illustrates a middle path between licensed and unlicensed access. Because incumbent fixed microwave links, satellite uplinks, and broadcast auxiliary services already occupy the band, unlicensed devices are separated into power classes with correspondingly different obligations. Low-power indoor devices may operate across the band at reduced power without coordination, provided they are restricted to indoor use with an integrated antenna, and very low power devices are permitted a limited portable allowance.
Standard-power access points and fixed client devices, by contrast, must consult an Automated Frequency Coordination system before transmitting. The AFC service holds a database of protected incumbent links and returns the channels and power levels available at the requesting device's geographic location, obliging the device to report its position accurately and to re-query periodically. The FCC approved the first group of AFC system operators in February 2024 to coordinate access to the U-NII-5 band at 5.925 to 6.425 GHz and the U-NII-7 band at 6.525 to 6.875 GHz, with additional approvals following. For product designers, AFC introduces requirements with no precedent in earlier unlicensed rules: verified geolocation, a network path to the coordination service, and defined behavior when that service is unreachable.
Band Edge and Channelization Requirements
Regulators specify exact frequency ranges for radio services and require devices to contain their emissions within the allocated band. Band edge requirements limit out-of-band emissions that could interfere with adjacent services, and devices must show that emissions fall rapidly outside the authorized band, meeting specified attenuation levels at defined frequency offsets. Band edge performance is one of the most common causes of certification failure, because it depends on filter selectivity, transmitter linearity, and modulation spectral regrowth simultaneously, and the outermost channels of a band are almost always the worst case.
Many bands specify channelization plans that define center frequencies and channel bandwidths, and devices must operate on authorized channels and support the applicable numbering scheme. Channel plans are not globally uniform: the 2.4 GHz band supports channels 1 through 11 in the United States and 1 through 13 across most of Europe, so a product sold in both markets must constrain its channel set by region. ETSI harmonized standards and the corresponding national regulations document the channel arrangements for European markets, and the equivalent information for the United States appears in the relevant Part 15 subpart together with the associated KDB guidance.
Interference Mitigation
Wireless regulations aim to prevent harmful interference between radio services. Devices must be designed to minimize interference potential through power control, spectrum efficiency, and coexistence mechanisms.
Emission Limits
Intentional radiators must meet limits on both in-band and out-of-band emissions. In-band limits are expressed either as maximum effective isotropic radiated power (EIRP) or as conducted power combined with an antenna gain allowance, and many rules add a power spectral density limit so that a narrowband signal cannot concentrate the full permitted power into a small bandwidth. These limits balance adequate coverage against interference potential to other users of the same band. Rules that specify conducted power plus antenna gain have a practical consequence: substituting a higher-gain antenna changes the EIRP and therefore the compliance status, which is why antenna type and gain are recorded explicitly in the grant.
Out-of-band and spurious emission limits protect services on nearby frequencies. Harmonics, intermodulation products, local oscillator leakage, and broadband noise must all remain below specified levels. Testing spans a wide frequency range, conventionally from well below the operating frequency to the tenth harmonic, and restricted bands set aside for radio astronomy, aeronautical navigation, and safety services carry particularly stringent limits.
Regulators differ in how they require spectrum to be shared. The FCC rules for unlicensed bands rely principally on power, bandwidth, and emission limits, whereas the ETSI harmonized standards add explicit access mechanisms. Wideband equipment in the European 2.4 GHz and 5 GHz bands must implement adaptivity, commonly realized as listen-before-talk, in which the transmitter senses the channel and defers if it is occupied. Short-range devices in the European sub-GHz bands are further constrained by duty cycle limits that cap the fraction of any hour a device may transmit. A product designed only against the FCC rules may therefore fail European testing even though its radiated power is well within the limit, and vice versa.
Coexistence Testing
Coexistence differs from emissions compliance. A device may satisfy every emission limit and still degrade a neighboring system, because the limits govern how much energy is radiated rather than how the shared medium is used. Coexistence assessment therefore examines functional performance: whether the device continues to meet its own requirements in the presence of other transmitters, and whether its transmissions impair systems sharing the band. ANSI C63.27 provides a general method for evaluating wireless coexistence, defining intended and unintended signal environments, tiers of assessment rigor, and pass criteria based on the device's own functional wireless performance rather than on radiated power.
Coexistence is treated as a safety matter in some domains. Medical devices with wireless functions are expected to include a coexistence evaluation in their risk file, because a dropped link in an infusion pump or patient monitor has consequences that a dropped file transfer does not. Industrial and automotive applications apply similar reasoning where wireless links carry control or diagnostic traffic.
Bluetooth, Wi-Fi, and cellular standards each define their own coexistence mechanisms, and the IEEE 802.19 working group develops methods for coexistence between IEEE 802 wireless standards, including the 802.19.1 framework originally developed for unlicensed operation in TV white space. Devices combining several radios face the hardest case, since a co-located transmitter can be tens of decibels stronger at the victim receiver than any external interferer. Solutions include frequency planning that keeps harmonics and intermodulation products away from the other receiver's band, time-domain arbitration signals between chipsets, front-end filtering, and antenna isolation.
Laboratories perform these evaluations using controlled interference environments, either radiated in a chamber or conducted through a combining network. Beyond demonstrating conformity, the results guide practical tuning: adjusting arbitration priorities, scan schedules, and channel selection policies in firmware usually yields more improvement than changes to the radio hardware.
Dynamic Frequency Selection
Dynamic Frequency Selection (DFS) is required for unlicensed devices operating in the portions of the 5 GHz band shared with radar systems, principally 5.25 to 5.35 GHz and 5.47 to 5.725 GHz. DFS obliges the unlicensed device to detect radar signals and vacate the channel, protecting military, aeronautical, and weather radar operations that hold priority in the band.
DFS Requirements and Testing
DFS-capable devices must implement radar detection algorithms that recognize specified radar waveforms above a defined interference threshold and within a required detection probability. Under the FCC rules, once radar is detected all transmissions on the operating channel must cease within ten seconds, of which no more than roughly 200 milliseconds may carry normal traffic; the remainder is reserved for management frames that move associated clients off the channel. The vacated channel is then subject to a non-occupancy period of at least thirty minutes before the device may return to it.
Before transmitting on a DFS channel, a device must perform a Channel Availability Check by monitoring the channel and confirming that no radar is present. The check period is sixty seconds for most channels, but channels overlapping 5600 to 5650 MHz, which is used by terminal Doppler weather radar at airports, require an extended check of ten minutes. That difference explains the long startup delay users observe when an access point is configured onto certain 5 GHz channels. Once operating, the device must continue in-service monitoring so that radar appearing after the initial check is still detected.
DFS testing requires radar simulators that generate the specified pulse patterns, chirps, and hopping waveforms at precisely controlled levels. Testing verifies detection probability across the required waveform set, channel move time, non-occupancy behavior, and correct handling of the extended check on weather radar channels. Master devices such as access points carry the full obligation. Client devices generally have reduced requirements because they transmit only under the control of a master that has already validated the channel, though a client that can initiate a network on its own must meet the master requirements.
Regional DFS Variations
DFS requirements vary significantly between regulatory domains. The FCC, ETSI, and other regulators specify different radar waveforms, detection thresholds, and timing parameters. Multi-region products must implement DFS algorithms that satisfy the requirements of all target markets or support region-specific configurations.
Some regulatory domains are introducing updated DFS requirements that mandate detection of additional radar waveforms or modify timing parameters. Products must track regulatory changes and update DFS implementations through firmware to maintain compliance in all markets.
Transmit Power Control
Transmit Power Control (TPC) requirements mandate that devices reduce transmit power when full power is not needed for reliable communication. TPC reduces average interference levels and enables more efficient spectrum sharing.
TPC Implementation
The requirement is stated as a capability rather than as a specific operating behavior. In the 5.25 to 5.35 GHz and 5.47 to 5.725 GHz bands, the FCC requires a U-NII device to be capable of operating at least 6 dB below the mean EIRP value of 30 dBm, and it exempts systems whose EIRP is below 500 mW from the TPC requirement entirely. The 6 GHz rules apply a comparable 6 dB capability to the power classes that need it. European rules use a similar structure with their own mitigation factor. Certification testing therefore demonstrates that the required reduction can be commanded and achieved, and the device is expected to apply it when the link does not need full power.
For Wi-Fi devices, TPC is implemented alongside link adaptation, which selects modulation and coding based on measured signal quality. IEEE 802.11h added the TPC and DFS procedures that make 5 GHz operation acceptable to European and other regulators, including the exchange of link margin and power capability information between the access point and its clients. An implementation must ensure that commanded reductions take effect across all supported modulation modes, since a power amplifier calibrated at one data rate may not deliver the same backoff at another.
Power Limits by Device Type
Regulations often specify different power limits for different device categories. Fixed point-to-point links may be permitted higher EIRP than mobile devices. Indoor-only devices may have different limits than devices approved for outdoor operation. Client devices operating under infrastructure control may have different limits than master devices.
Understanding device classification is essential for determining applicable power limits. A device certified as portable may be subject to SAR requirements and lower power limits, while the same device classified as mobile might have different constraints. Manufacturers must carefully consider intended use cases when selecting device classifications during the certification process.
Modular Approval
Modular approval allows wireless modules to be certified independently and then integrated into host products without requiring full recertification of the wireless portion. This approach significantly reduces time-to-market and certification costs for products incorporating standard wireless modules.
Module Certification Requirements
To qualify for single modular approval, a module must satisfy a defined set of criteria published in FCC guidance. The radio elements must be enclosed in their own RF shielding; the module must provide its own modulation and data buffering so that host signals cannot alter the transmitted spectrum; it must include its own power supply regulation; it must be tested standalone in a representative configuration; it must use only antennas that are permanently attached or fitted with a unique coupling; and it must carry its own label and demonstrate RF exposure compliance for the intended installation. The animating principle is that the module's compliance must not depend on anything the host provides.
Limited modular approval covers modules that do not meet every criterion but whose host dependencies can be characterized and controlled. A module lacking its own shielding or regulation, for example, may still be approved subject to conditions that the host must satisfy, such as a specified enclosure, supply arrangement, or trace layout. The grant then names those conditions, and the integrator must meet them and may need supplementary testing in the finished product.
Host Integration Considerations
Host products using certified modules must maintain the module's certified configuration. Antenna specifications, including type, gain, and cable loss, must remain within certified parameters. Host manufacturers must follow module integration guidelines and may need to perform limited testing to verify that integration does not affect module compliance.
Labeling requirements for host products depend on module visibility. If the module's certification label is visible after installation, no additional host labeling may be required. If the label is not visible, the host must display the module's certification identifier or its own identifier if certified as a composite device.
Class II permissive changes allow host manufacturers to add or change antennas within specified parameters without module recertification. Understanding permissive change rules enables flexibility in product design while maintaining compliance.
Software Defined Radio
Software Defined Radio (SDR) technology enables radio parameters to be modified through software changes, raising regulatory concerns about devices being modified to operate outside certified parameters. Regulations have evolved to address SDR while enabling legitimate software flexibility.
SDR Security Requirements
Regulators require that SDR devices implement security features to prevent unauthorized modification of RF parameters. The FCC requires manufacturers to describe the measures that prevent third-party software from driving the radio beyond its certified limits, and those descriptions are submitted confidentially with the certification application. The issue became concrete for consumer Wi-Fi equipment when regulators pressed manufacturers to lock the RF parameters of routers, a step that many vendors initially implemented by blocking all firmware replacement. The workable resolution separates the RF control layer, which must remain locked, from the general-purpose software above it, which may remain open.
The EU Radio Equipment Directive Article 3(3)(i) requires that radio equipment support features ensuring that software can only be loaded when the compliance of the combination of equipment and software has been demonstrated. A related set of provisions, Article 3(3)(d), (e), and (f), addresses network protection, the safeguarding of personal data and privacy, and protection against fraud. Delegated Regulation (EU) 2022/30 activated these cybersecurity requirements for categories including internet-connected radio equipment, childcare and toy devices, and wearables; the original date of application of 1 August 2024 was deferred by twelve months, so the requirements have applied since 1 August 2025.
The harmonized standards series EN 18031-1, EN 18031-2, and EN 18031-3 supports these three provisions, and their references were published in the Official Journal of the European Union in January 2025. The publication carried restrictions, so the presumption of conformity does not extend to every clause, and manufacturers relying on the series must confirm which parts remain excluded and justify those aspects separately. The Cyber Resilience Act, Regulation (EU) 2024/2847, will take over this ground when it becomes fully applicable on 11 December 2027, with the RED delegated regulation expected to be repealed at that point. Products designed today should anticipate the transition rather than treat the current delegated act as a stable endpoint.
Security measures may include cryptographic verification of software updates, secure boot mechanisms, hardware-enforced parameter limits, or access controls that prevent unauthorized configuration changes. The specific measures required depend on the device type, software architecture, and regulatory interpretation.
Reconfigurable Radio Systems
ETSI has developed standards for Reconfigurable Radio Systems (RRS) that enable authorized reconfiguration while maintaining compliance. These standards define architecture, interfaces, and security requirements for software-reconfigurable devices.
Reconfigurable radio equipment may support multiple radio access technologies, frequency bands, or power configurations that can be activated through software. Compliance requires that all possible configurations meet applicable requirements and that the device cannot be configured to operate outside approved parameters.
Compliance Testing Process
Successful wireless certification requires comprehensive testing at accredited laboratories followed by proper documentation and application procedures.
Pre-Compliance and Design Verification
Pre-compliance testing during development identifies potential issues before formal certification testing. Evaluating prototype devices against expected requirements allows design modifications while changes are still practical. Many accredited laboratories offer pre-compliance services, and some design teams invest in in-house test equipment for early screening.
Design verification testing covers all operating modes, channels, and power levels to ensure the device meets requirements across its full operating envelope. This comprehensive evaluation often reveals edge cases or specific configurations that require optimization before certification.
Certification Testing
Formal certification testing must be performed at laboratories accredited for the specific test methods and regulatory requirements. In the United States, laboratories must be accredited to ISO/IEC 17025 and recognized by the FCC for the applicable rule parts. European testing requires accreditation by a national accreditation body and, for certain product categories, designation as a Notified Body.
Testing covers RF parameters (frequency, power, bandwidth, emissions), SAR or MPE evaluation, and any technology-specific requirements such as DFS. Test reports must follow prescribed formats and include all information required by the certification authority.
Documentation and Application
Certification applications require comprehensive documentation including test reports, device descriptions, block diagrams, schematics (often submitted under confidentiality), user manuals, and labeling artwork. Applications must be complete and accurate to avoid delays or rejection.
Response to certification body questions and resolution of any issues identified during application review require technical expertise and may involve additional testing or documentation. Maintaining good relationships with certification bodies and understanding their requirements facilitates efficient processing.
Maintaining Compliance
Compliance is not a one-time achievement but an ongoing obligation throughout the product lifecycle.
Change Management
Any change to a certified product that could affect RF performance requires evaluation for compliance impact. Component substitutions, firmware updates, antenna modifications, and mechanical changes may require retesting or recertification. Manufacturers must maintain change control procedures that identify potentially impactful changes and route them for compliance evaluation.
Permissive change rules define when modifications can be made without full recertification. Understanding these rules enables efficient product updates while maintaining compliance. Changes exceeding permissive change allowances require new testing and updated certification.
Post-Market Obligations
Certified devices must continue to meet requirements throughout their market life. Regulators may conduct market surveillance, request device samples for testing, or investigate interference complaints. Manufacturers must be prepared to demonstrate ongoing compliance and respond to regulatory inquiries.
Product labeling and user documentation must accurately reflect certified parameters and provide the required user information. Labels carry the FCC ID or the CE mark and the associated declarations, along with the RF exposure separation distance where one applies. Electronic labeling is now widely accepted for devices with an integrated display, allowing the identifiers to be shown in a software menu rather than printed on the enclosure, provided the information is accessible without special accessories and is also supplied in the packaging or documentation. Updates to regulatory requirements may force label or documentation changes even for products already in distribution.
Regulatory Monitoring
Wireless regulations evolve continuously as spectrum allocations change, new technologies emerge, and regulators respond to interference issues or policy objectives. Manufacturers must monitor regulatory developments to ensure continued compliance and identify opportunities enabled by regulatory changes.
Industry associations, regulatory newsletters, and specialized consultants provide regulatory intelligence services. Active participation in standards development and regulatory proceedings enables manufacturers to influence future requirements and gain early insight into upcoming changes.
Summary
Wireless and radio compliance spans a broad range of requirements that shape a product from initial band selection through post-market surveillance. Unlike many safety regimes, it constrains the design itself: the choice of frequency band determines the applicable rules, the antenna and mechanical layout determine exposure performance, and the access mechanism required in one region may be absent in another.
The principal areas are human exposure limits expressed as SAR and MPE, transmitter certification in each target market, adherence to spectrum allocations including coordinated schemes such as AFC in the 6 GHz band, interference mitigation through emission limits and access mechanisms, DFS for radar protection, transmit power control for efficient sharing, modular approval for integration flexibility, and software security for reconfigurable radios. Layered above the statutory requirements sit the industry and operator certification programs that determine whether a device can actually reach a network or carry a familiar logo.
Two habits distinguish teams that navigate this landscape efficiently. The first is early engagement: exposure performance, band plans, and module selection are cheap to change during product definition and expensive to change after tooling. The second is treating compliance as a continuing obligation, since harmonized standard references are withdrawn, delegated acts are superseded, and coordination requirements evolve while a product is still on the market.
Related Topics
Radio compliance sits at the intersection of electromagnetic compatibility, spectrum policy, and the certification machinery that governs market access. The following topics provide complementary background: