Welcome to GCDC official website!

Information

Always pay attention to the global certification trends of wireless products

Smart_Lock_FCC_RED_Security

Edit: GCDC  Affiliation: Certification Information  Views: 8  Release time: 2026-07-20

Smart door locks integrating Wi-Fi, Bluetooth, NFC, and biometric sensors operate at the intersection of three regulatory domains: FCC Part 15C (RF emission), CE-RED (RF + cybersecurity), and increasingly, sector-specific IoT security regulations such as the EU Cyber Resilience Act (CRA) and the UK PSTI Act. For lock manufacturers, the FCC and CE-RED dual-certification path has expanded beyond traditional RF testing: the CE-RED cybersecurity clause (Article 3.3 d/e/f) and the CRA's secure-by-design requirements now demand evidence of vulnerability management, secure update mechanisms, and default password policies — requirements that are absent from FCC. This article examines the evolving FCC+RED dual-certification landscape for smart door locks.

GTG广测集团实验室

FCC vs. CE-RED — Shared RF Testing Ground

Smart door locks contain three radio categories that must pass both FCC and CE-RED:

  • Bluetooth LE (FCC §15.247 / RED EN 300 328): Shared test items: conducted power, OBW, PSD, band-edge. RED-unique: receiver blocking (EN 300 328 §4.3.1.11) and adaptivity — both have no FCC equivalent.
  • Wi-Fi 2.4 GHz (FCC §15.247 / RED EN 300 328): Same sharing profile as Bluetooth. Locks that use Wi-Fi as a bridge to cloud services typically operate as station devices — if the lock also functions as a Soft AP for initial pairing, the RED Adaptivity test must cover the AP operating mode.
  • NFC (FCC §15.225 / RED EN 300 330): The lock's NFC reader (13.56 MHz) used for access card / phone tap-to-unlock must meet field strength and frequency tolerance limits. The metal lock body can detune the NFC antenna — matching must be done in the assembled lock, not on a bare PCB.

Approximately 60-65% of RF test data is shared between FCC and RED. The incremental RED testing cost for a lock already FCC-certified is approximately the receiver blocking + adaptivity tests plus RED-specific spurious emission limits.

GTG广测集团实验室

The Cybersecurity Dimension — RED Article 3.3 and CRA

RED Article 3.3(d/e/f) gives the European Commission authority to mandate cybersecurity requirements for connected devices. While formal delegated acts are still in development, RED Notified Bodies increasingly request evidence of cybersecurity practices during conformity assessment:

  • No universal default passwords — each lock must ship with a unique pairing code, or mandate password change on first setup
  • Software update mechanism via authenticated and encrypted channel
  • Vulnerability disclosure policy — a public contact point for security researchers to report findings

For a smart lock, smart lock RED cybersecurity compliance documentation typically includes: a security architecture description, a threat model covering physical access + wireless attack vectors, and the firmware update mechanism design specification. This documentation is not required for FCC.

Frequently Asked Questions

Q1 Is SAR evaluation required for a smart door lock?

For a wall-mounted door lock with ≥20 cm separation distance from the user's body during normal operation, both FCC (KDB 447498) and RED (EN 62479) accept the MPE (Maximum Permissible Exposure) evaluation path instead of SAR — no SAR testing is required. The lock's manual must state the minimum installation distance from the user.

 

Q2 How does the metal door lock body affect FCC and RED testing?

The metal lock body acts as a parasitic ground plane — it can detune the PCB antenna's resonant frequency by 50-150 MHz and alter the radiation pattern. FCC and RED testing must be performed with the lock assembled in its final housing. Testing on a bare PCB with a plastic test fixture will not produce representative RF data for a metal-housed lock.

 

Q3 Does a smart lock with Fingerprint sensor need additional FCC testing?

The fingerprint sensor itself is a passive capacitive/optical sensor and does not emit intentional RF — it is covered under FCC Part 15B unintentional emissions as part of the digital device circuitry. However, the fingerprint module's MCU and SPI/I2C communication bus may generate clock harmonics in the 30-300 MHz range that contribute to the Part 15B radiated emission profile.

 

Q4 Is UK PSTI compliance required in addition to CE-RED?

The UK PSTI Act 2022 (Product Security and Telecommunications Infrastructure) mandates three baseline security requirements for consumer IoT devices: no default passwords, vulnerability disclosure policy, and transparency on security update duration. These overlap substantially with RED Article 3.3 and CRA — a single security compliance program can cover both UK and EU requirements.

 

Q5 Battery-powered vs. hardwired locks — different FCC/RED treatment?

Battery-powered locks have no AC conducted emissions path — FCC Part 15B and RED EMC testing focus on radiated emissions only. Hardwired locks (AC or PoE powered) must additionally test AC mains conducted emissions. Battery-powered locks using replaceable AA/AAA batteries are treated as portable devices — the battery compartment's proximity to the antenna must be checked for body-loading effects (user's hand bridging the battery to the antenna).

 
 

This content is for informational reference only. For inquiries, please contact us.

Phone: +86 13925591357 | Email: net04@gtggroup.com | https://www.gtggroup.cn

Online Application

Service line 13925591357

*

*

*

*

Please fill in the real information, we will contact you within 24 hours!

Consultation

WeChat

二维码Add Wechat

QQ

QQ consultation

2123664179