RFID Compliance and Certification: What Manufacturers Need to Know

RFID is used in a wide range of industrial and commercial applications, from automatic identification and access control to production lines, logistics, asset tracking and Industry 4.0.

In industrial applications, RFID is often not used as a standalone technology. RFID readers and sensors can, for example, be integrated into automation systems via IO-Link, with the resulting data transferred to higher-level control, IT or IIoT systems.

This creates a combination of radio technology, industrial communication, sensor technology and digital infrastructure.

From a compliance perspective, it is therefore important to understand the complete system architecture.

RFID certification, IO-Link conformity and regulatory radio compliance are separate topics.

What is RFID?

RFID stands for Radio Frequency Identification.

A typical RFID system consists of:

  • RFID reader or interrogator
  • RFID transponder or tag
  • Antenna
  • Control and processing electronics
  • Software

Information is transferred between the reader and the transponder using radio technology.

RFID is used for applications such as:

  • Product identification
  • Inventory management
  • Asset tracking
  • Access control
  • Production control
  • Tool management
  • Automation
  • Logistics

The actual radio technology depends on the RFID system being used.

For regulatory purposes, simply identifying a product as “RFID” is therefore not sufficient.

Important parameters include:

  • Frequency
  • Transmit power
  • Bandwidth
  • Modulation
  • Antenna
  • Operating mode
  • Intended use

RFID Is Not One Single Technology

RFID systems can operate in different frequency ranges.

Common applications include:

  • LF – Low Frequency
  • HF – High Frequency
  • UHF – Ultra High Frequency
  • Other specialized RFID systems

A well-known example of HF RFID operates around 13.56 MHz.

In industrial and logistics applications, UHF RFID in the 865–868 MHz range in Europe is also widely used.

This distinction is important because the applicable regulatory requirements can differ significantly depending on the frequency range.

13.56 MHz RFID

RFID systems operating around 13.56 MHz are used for applications including identification, access control, ticketing, industrial applications and contactless communication.

From a regulatory perspective, factors such as the following may need to be considered:

  • Frequency
  • Field strength
  • Antenna configuration
  • Operating mode
  • Modulation
  • Emissions

For relevant Short Range Device applications in Europe, the applicable regulatory framework and current harmonised standards need to be identified.

The exact test scope depends on the implementation of the device.

UHF RFID

UHF RFID is widely used in logistics, warehousing and industrial automation.

In Europe, the 865–868 MHz range is particularly relevant.

A specific ETSI harmonised standard, EN 302 208, addresses RFID equipment operating in the relevant UHF bands and specifies technical requirements and measurement methods.

The assessment can include parameters such as:

  • Frequency range
  • Output power
  • Antenna gain
  • Channel occupancy
  • Emissions
  • Operating mode
  • Reader configuration

The regulatory assessment should therefore not be based simply on the term “UHF RFID.”

The actual RF configuration needs to be evaluated.

RFID Readers and RFID Tags Need to Be Considered Separately

An important point in compliance planning is the distinction between the reader and the tag.

An RFID reader typically contains an active transmitter and therefore needs to be assessed with regard to its radio emissions.

A passive RFID tag, on the other hand, normally does not contain its own active transmitter.

This means:

The reader and the tag have different technical and regulatory characteristics.

The manufacturer should therefore clearly identify which component is actually the subject of the regulatory assessment.

RFID and the Antenna

The antenna is an essential part of an RFID system.

Particularly for RFID readers, the antenna configuration can have a significant influence on the RF characteristics of the product.

Relevant parameters can include:

  • Antenna type
  • Antenna gain
  • Number of antennas
  • Antenna location
  • Cable losses
  • Impedance
  • Radiation pattern
  • Switching between multiple antennas

Changing the antenna can therefore affect the compliance scope.

This is particularly relevant when the original regulatory assessment was based on a specific antenna configuration.

RFID and Pre-Tested or Certified Modules

Many manufacturers use RFID or RF modules to simplify product development.

Again, an important principle applies:

Certification of a module does not automatically mean certification of the finished product.

The final integration can be affected by:

  • Antenna
  • Enclosure
  • Output power
  • Power supply
  • Installation position
  • Additional electronics
  • Other radio technologies
  • Firmware
  • Operating modes

Manufacturers therefore need to determine under which conditions an existing module approval can be used in the final product.

RFID and EMC

RFID products are frequently used in industrial environments.

These environments can contain significant electromagnetic disturbances caused by motors, variable-frequency drives, switching power supplies and other industrial equipment.

The EMC assessment of the finished product is therefore an important part of compliance.

Depending on the product, this can include:

  • Radiated emissions
  • Conducted emissions
  • ESD
  • Radiated immunity
  • Conducted immunity
  • EFT/Burst
  • Surge

The exact requirements depend on the product, its intended environment and the target market.

A certified RFID module therefore does not automatically demonstrate EMC compliance of the complete industrial product.

RFID in Industrial Applications

In industrial environments, RFID is often not used as a standalone device.

A typical architecture may look like this:

RFID Tag → RFID Reader → IO-Link → IO-Link Master → PLC → Industrial Network → IT / IIoT

This creates several different technical layers.

The RF characteristics of the RFID reader need to be considered separately, while the communication between the reader and the control system may take place through an industrial wired interface.

This distinction is important when defining the compliance scope.

What Is IO-Link?

IO-Link is a standardised point-to-point communication technology for sensors and actuators and is standardised in IEC 61131-9.

IO-Link supports functions such as:

  • Bidirectional communication
  • Parameterisation
  • Diagnostics
  • Process data transmission
  • Device information
  • Identification
  • Remote configuration

IO-Link is not a conventional fieldbus. It is designed as a standardised point-to-point connection between an IO-Link device and an IO-Link master.

For RFID manufacturers, IO-Link can provide an important interface for integrating RFID data into an industrial automation architecture.

RFID and IO-Link

An RFID reader can be implemented as an IO-Link device.

In this case, the reader handles the RF communication with the RFID tag, while IO-Link provides the connection to the higher-level automation system.

A simplified architecture could look like this:

RFID Tag

↓

RFID Reader

↓

IO-Link

↓

IO-Link Master

↓

Industrial Ethernet

↓

PLC / Controller

↓

IT System

↓

IIoT / Cloud

From a compliance perspective, the individual communication layers need to be distinguished.

The RFID interface is a radio application.

A conventional IO-Link connection is a wired communication interface.

IO-Link Is Not Automatically a Radio Technology

This distinction is important.

Standard IO-Link uses a wired connection and is standardised in IEC 61131-9.

Therefore, using conventional IO-Link does not by itself create an additional radio approval requirement.

The situation is different with IO-Link Wireless.

IO-Link Wireless uses radio communication and operates in the 2.4 GHz ISM band. The technology uses mechanisms such as frequency division and channel hopping for wireless communication.

It therefore needs to be considered as an RF interface and assessed against the applicable regulatory requirements.

IO-Link Wireless

IO-Link Wireless is particularly useful in applications where cables are difficult or undesirable to use.

Examples include:

  • Mobile machines
  • Robotics
  • Rotating components
  • Difficult-to-access sensors
  • Flexible production cells

From a compliance perspective, IO-Link Wireless should be treated differently from conventional wired IO-Link.

In addition to the industrial communication requirements, RF parameters such as:

  • Frequency
  • Transmit power
  • Bandwidth
  • Channel occupancy
  • Antennas
  • Simultaneous transmission
  • EMC
  • RF exposure where applicable

may need to be considered.

RFID, IO-Link and IIoT

The combination of these technologies creates a continuous data path through the industrial environment.

An RFID system can, for example, identify a workpiece.

The information can then be transferred via IO-Link to the automation controller.

The automation system can subsequently make the data available to IT systems or IIoT platforms through industrial networks and appropriate integration interfaces.

This creates a typical architecture:

RFID → IO-Link → Automation → IT/OT Integration → IIoT

For manufacturers, this means that RFID is increasingly part of a larger connected system rather than an isolated RF device.

What Does IIoT Mean for Compliance?

IIoT extends the functionality of a product beyond its physical radio interface.

A modern industrial device may:

  • Collect data
  • Store data
  • Transfer data over industrial networks
  • Update firmware
  • Change parameters remotely
  • Communicate with cloud systems
  • Interact with other machines

This can introduce additional compliance considerations.

Depending on the product and target market, manufacturers may need to consider topics such as:

  • Cybersecurity
  • Software
  • Network communication
  • Remote access
  • Firmware updates
  • Data integrity
  • Product security
  • Industrial security requirements

The actual regulatory relevance depends on the product and the applicable market requirements.

RFID and Cybersecurity

The cybersecurity considerations for a simple passive RFID tag are very different from those of a connected RFID gateway.

An industrial RFID reader with:

  • Ethernet
  • Wi-Fi
  • IO-Link
  • Web interface
  • Remote configuration
  • Cloud connectivity

is a significantly more complex digital product.

Security architecture should therefore be considered during product development.

Depending on the application, relevant topics can include:

  • Authentication
  • Access control
  • Secure firmware updates
  • Communication security
  • Credential protection
  • Tamper protection
  • Secure configuration

Again, the specific regulatory relevance depends on the product and target market.

RFID in the European Union

For an RFID reader with radio functionality placed on the EU market, the Radio Equipment Directive (RED) is particularly relevant.

The applicable requirements and harmonised standards depend on the specific RFID system and frequency range.

For UHF RFID operating in the relevant 865–868 MHz range, EN 302 208 is an important standard.

Other RFID frequency ranges can require different standards and assessment methods.

The compliance scope should therefore always be defined based on the actual radio implementation.

RFID in the United States

For the US market, the specific RFID technology needs to be assessed against the applicable FCC requirements.

Relevant parameters can include:

  • Frequency
  • Transmit power
  • Bandwidth
  • Emissions
  • Antenna
  • Operating mode

An RFID product designed for the European market should therefore not automatically be considered compliant for the US market.

The regional RF configuration and applicable regulatory requirements need to be assessed separately.

Global RFID Products

The compliance process becomes more complex when an RFID product is intended for multiple markets.

A product may be designed for:

  • EU
  • USA
  • Canada
  • Australia
  • Japan
  • China
  • India
  • Other markets

Frequency allocations, power limits, channel arrangements and testing requirements can differ between these markets.

This is particularly important for UHF RFID, where regional frequency allocations need to be considered during product development.

A global RFID product should therefore be designed with regional regulatory requirements in mind from the beginning.

What Happens When the RFID System Changes?

Technical changes can have a direct impact on the compliance scope.

Examples:

Different antenna

→ Potential change to RF characteristics

Higher output power

→ Potential additional radio assessment

New frequency range

→ New regulatory requirements

Additional Wi-Fi

→ Additional radio technology

IO-Link Wireless instead of wired IO-Link

→ Additional RF assessment

New Ethernet or cloud functionality

→ Potential additional cybersecurity requirements

New power supply

→ Potential EMC and safety impact

Firmware change

→ Potential relevance if RF behaviour, operating modes or security-related functions change

Every significant technical change should therefore be reviewed against the existing compliance scope.

A Practical Compliance Workflow for RFID Products

1. Define the Product Architecture

First determine:

  • RFID reader or tag
  • Frequency range
  • Antenna
  • Transmit power
  • Operating modes
  • Installation environment
  • Target markets

2. Define the Radio Technology

Document:

  • Frequency
  • Channels
  • Bandwidth
  • Modulation
  • Output power
  • Antenna configuration

3. Identify Additional Interfaces

Determine whether the product also includes:

  • IO-Link
  • IO-Link Wireless
  • Ethernet
  • Wi-Fi
  • Bluetooth
  • USB
  • Cellular
  • Other radio technologies

4. Determine Simultaneous Transmission

If multiple radio technologies are present, determine which transmitters can operate simultaneously.

5. Review Module and Antenna Certifications

For each RF module, document:

  • Existing approvals
  • Permitted antennas
  • Maximum transmit power
  • Installation conditions
  • Regional variants
  • Restrictions

6. Evaluate IO-Link Integration

For an IO-Link device, the relevant technical documentation and conformity requirements of the IO-Link implementation should also be considered.

An IO-Link device, for example, requires a corresponding IODD (IO Device Description).

7. Identify IIoT and Security Functions

If the product has network or cloud functionality, consider:

  • Remote access
  • Firmware updates
  • Authentication
  • Network communication
  • Security functions

8. Define the Target Markets

Regulatory requirements should be determined separately for each target market.

9. Build the Test Plan

Once the product architecture, RF parameters, interfaces and target markets have been defined, the final test plan can be established.

This helps prevent relevant requirements from being overlooked and unnecessary testing from being commissioned.

Common Mistakes With RFID Products

Mistake 1: Treating RFID as Just an Interface

An active RFID reader is a radio device and needs to be assessed accordingly.

Mistake 2: Treating Readers and Tags the Same Way

Readers and passive tags have different technical characteristics and need to be considered accordingly.

Mistake 3: Changing the Antenna at the Last Minute

A different antenna can change the RF characteristics and therefore potentially the compliance scope.

Mistake 4: Treating IO-Link and RFID as the Same Technology

RFID provides the wireless communication with the tag.

Conventional IO-Link is a wired point-to-point communication interface between the device and the IO-Link master.

Mistake 5: Treating IO-Link Wireless Like Conventional IO-Link

IO-Link Wireless uses radio communication and therefore needs to be assessed against the applicable RF requirements.

Mistake 6: Adding IIoT Functions at the End of Development

Cloud connectivity, remote access and firmware updates can introduce additional technical and potentially regulatory considerations.

Mistake 7: Looking Only at Radio Approval

An industrial RFID product may also have significant EMC, safety and potentially cybersecurity requirements.

RFID Should Be Considered as a Complete System

Modern industrial products increasingly integrate RFID into a larger system architecture.

A typical data flow might look like:

RFID Tag

↓

RFID Reader

↓

IO-Link

↓

IO-Link Master

↓

PLC / Industrial Network

↓

IT / MES

↓

IIoT / Cloud

Each layer performs a different function.

From a compliance perspective:

Not every component requires the same type of assessment.

The RF interface, electrical hardware, industrial communication and digital or connected functions should therefore be identified separately and then considered as part of the overall product architecture.

Conclusion

RFID is no longer limited to simple identification applications.

In modern industrial systems, RFID can be combined with IO-Link, Industrial Ethernet, automation systems and IIoT platforms.

This creates an architecture in which several compliance areas can come together:

RFID → RF → EMC → Safety → IO-Link → Industrial Networking → Security → IIoT

For manufacturers, the key question is therefore not simply:

“Which RFID certification do I need?”

It is:

“What requirements arise from the specific architecture of my RFID product in each target market?”

Defining the compliance scope early helps manufacturers identify relevant standards, avoid unnecessary testing and provide laboratories with a solid technical basis for quotation and testing.

How ScopeRight Helps

ScopeRight helps manufacturers define the RF, EMC and Safety compliance scope of their products.

Based on product-specific information, ScopeRight can identify relevant standards, required tests and estimated laboratory effort.

This provides manufacturers with a structured test plan before approaching a laboratory and starting the actual testing process.

Control the Scope. Control the Cost.

ScopeRight