Ongoing Compliance / Maintenance

Certified once isn't compliant forever

A CE or FCC file freezes the day it's issued. The regulations don't. Harmonised standards get revised, exemptions expire on fixed calendar dates, and delegated acts add new obligations to products already on the market — none of it triggered by anything you did. We track what's changed against your actual product line and tell you before it's a problem, not after a market-surveillance letter or a customs hold.

Last updated 8 September 2026

Aug 2025EN 18031 (RED cybersecurity) became mandatory — for radios certified years earlier
11 Dec 2026 – 31 Dec 2027RoHS Annex III/IV lead-solder exemptions expire on staggered dates
11 Sep 2026CRA Article 14 incident-reporting duties start, for products already on sale

Why an already-certified product can fall out of step

Three real mechanisms do this, all without a single component on the product changing. Harmonised standard references get revised in the EU Official Journal, and a Declaration of Conformity that still cites a withdrawn version loses its presumption of conformity. Exemptions carry their own sunset dates set at EU level, independent of when a given product was first certified — RoHS Annex III/IV lead-solder exemptions expire on a staggered schedule running from 11 December 2026 through 31 December 2027. And delegated or implementing acts can add obligations that reach backward to products already for sale: RED's cybersecurity requirements (EN 18031) became mandatory in August 2025 for radio equipment that, in many cases, had been CE-marked for years beforehand.

Source: Delegated Regulation (EU) 2022/30, Art. 3(3)(d)(e)(f); Directive 2011/65/EU (RoHS) Annex III/IV exemption review decisions; Regulation (EU) 2024/2847 (Cyber Resilience Act), Art. 14.

What this looks like on real products

A Bluetooth speaker CE-marked in 2023Certified two years before EN 18031 existed. The RED file needs reviewing against the cybersecurity delegated act before the product can keep lawfully being placed on the EU market — the physical speaker hasn't changed, the file it relies on has fallen behind.
An appliance using a RoHS lead-solder exemptionSome Annex III/IV exemptions expire on a fixed date regardless of when the product itself was certified. Once the exemption lapses, continuing to rely on it without a renewed justification or a redesign is a compliance gap that opens on a calendar date, not a design change.
A Wi-Fi-connected sensor or smart-home deviceFalls under CRA Article 14 the moment it has an actively exploited vulnerability or a severe security incident, with reporting obligations that apply regardless of how long ago the product was certified or how old the current production run is.

What we actually do

We track the specific regulations, standards revisions and exemption dates relevant to each product's actual technical scope — not a generic regulatory newsletter — matched against your real product line and its radio/battery/materials profile. When something changes, we tell you which SKUs are affected and how much runway you have, and where a re-test, an updated declaration or a technical file amendment is genuinely needed, we manage that through the same accredited-lab relationships we use for first-time certification.

Questions

What is post-certification regulatory monitoring?

An ongoing service that tracks regulatory changes affecting products you've already certified and placed on the market — revised harmonised standards, expiring exemptions, and new delegated or implementing acts — and flags which of your specific products are affected before a deadline hits, rather than waiting for a market-surveillance letter or a customs hold.

Why would an already-certified product become non-compliant without changing?

Three real mechanisms: harmonised standard references get revised in the EU Official Journal, and a Declaration of Conformity citing a withdrawn version loses its presumption of conformity; exemptions have fixed sunset dates regardless of when a product was first certified (RoHS Annex III/IV lead-solder exemptions expire on staggered dates from 11 December 2026 through 31 December 2027); and delegated acts can add obligations that reach back to products already on sale, such as the RED cybersecurity requirements (EN 18031) that became mandatory in August 2025 for radio equipment certified years earlier.

What kinds of products need this?

Anything with a technical file that was closed years, or even months, ago and hasn't been revisited since: Bluetooth or Wi-Fi products certified before August 2025 and never checked against the RED cybersecurity delegated act, products relying on a RoHS Annex III/IV exemption with its own expiry date, and any connected device now in scope of the Cyber Resilience Act's incident-reporting duties (Article 14, live from 11 September 2026) regardless of when it was first placed on the market.

How is ongoing regulatory monitoring priced?

Differently from a one-off certification project, since it scales with how many products and markets are being tracked rather than a single test scope. Our reference point from real signed engagements is from £1,500/year for a single ongoing role such as an EU or UK Authorised/Responsible Representative; a monitoring programme across a wider product line is scoped to the portfolio on a call.

Where we fit

Most teams treat certification as a project with an end date, then stop looking at it. The regulations don't stop moving once the file closes. We're the ongoing layer that keeps watching after the certificate is issued — so a standards revision or an exemption deadline shows up as a scheduled task, not a surprise from a customs officer or a marketplace compliance team.

Book a scoping call

Get updates

Get regulatory updates for your markets and product

Tell us which markets you sell into and what kind of product it is, and we'll send you the changes that actually apply — not a general newsletter.