CE‑RED EN 18031 Cybersecurity Standard – Cost Breakdown

2026-08-20

Many companies new to EN 18031 mistakenly think they can obtain a separate cybersecurity certificate. In reality, EN 18031 is a harmonised standard under the EU RED Directive – governing cybersecurity, privacy, and user‑data protection for wireless devices.

This standard does not issue a standalone certificate – its security content is integrated into the whole‑product RED technical file. Actual costs are concentrated in security assessment, evidence documentation, and whether a Notified Body is involved. Many first‑time teams struggle with document requirements – budgets easily go out of control. When comparing quotes, don't just look at the total – itemised breakdowns are essential.


1. What Are the Actual Cost Components?

EN 18031‑related costs split into three main parts:

·Base RED RF/EMC.

·Cybersecurity assessment.

·Documentation and consulting.

Industry quotes vary – some include documentation in testing, others charge separately. When comparing, align the scope – check line by line – don't sign a bundled lump‑sum quote lightly.

1.1 Base RED RF/EMC costs

·This is the testing wireless devices already require.

·Ordinary short‑range products: RF + EMC – roughly RMB 5,000–30,000.

·Cellular and multi‑band high‑power products cost more.

·RF/EMC and cybersecurity are independent – don't merge them into one total – otherwise budget gaps appear later.

1.2 Cybersecurity assessment costs (three tiers)

Based on product function and risk level:

Tier                                           Scope                                                                                          Typical Cost (RMB)

Basic              RED 3.3(d) only – network protection                                                                     30,000–80,000

Medium         RED 3.3(d) + (e) – privacy protection                                                                    50,000–100,000

Full             High‑sensitivity data – threat modelling + security controls                                  150,000–300,000

·Products that run locally, do not connect to the internet, and do not process user data – may exempt some clauses – do not apply the full tier.

1.3 Documentation and consulting

Even with self‑declaration, you must produce:

·Security architecture, threat model, security‑control justification – full set.

·If your team lacks capability – external support is needed.

·Document quality directly determines review smoothness – poor documentation undermines all prior testing.


  2. NB Path vs. Self‑Declaration – How to Choose

Whether a Notified Body (NB) is required is the key cost differentiator – not all products need NB. Companies should self‑check against the (EU) 2025/138 limitation list. If the product qualifies for self‑declaration – significant savings are possible.

Some agents may push NB solutions to increase their own revenue – don't be unilaterally guided. If any limitation applies – EN 18031 loses its presumption of conformity – self‑declaration is not allowed.

For NB review: fees are charged as review acceptance fees – quotes vary significantly – confirm the currency. For RED 3.3(d/e/f), most NBs only review documents and reports – factory audits are not mandatory – don't default to budgeting for them.


  3. Hidden Costs – Often Overlooked

The quote total is not the full project cost – two hidden areas are often missed.

·Freeze firmware versions before formal testing – changing firmware mid‑test invalidates results – requiring re‑queuing.

·Remediation rework: threat‑model defects or insufficient security‑control justification require retesting – adding costs and time. A low‑cost gap analysis upfront prevents expensive later rework.

·Multiple directives: some products are subject to RED, RoHS, etc. Medical wireless devices fall under MDR – exempt from RED 3.3(d/e/f) – no EN 18031 needed. Documents can be cross‑referenced – but testing/NB fees are mostly independent.


  4. 2025 Timeline

RED 3.3(d)(e)(f) cybersecurity provisions take effect from 1 August 2025 – applying only to new products placed on the EU market after that date. Products already legally on the market before 1 August may continue selling – no retrospective testing.

Plan new projects early – don't leave technical documents to the last minute.


  5. BlueAsia's End‑to‑End Approach

BlueAsia offers full CE‑RED + EN 18031 compliance services – including path determination, gap analysis, document writing, and NB liaison. We start with a gap assessment – determining self‑declaration vs. NB – avoiding blindly choosing high‑cost paths. For multi‑regulation wireless devices – unified planning controls overall cost and timeline.


  6. Common Misconceptions and Practical Reminders

·EN 18031 has no independent certificate – part of the RED technical file – no standalone "certificate purchase."

·Not all products need NB – if (EU) 2025/138 limitations do not apply – self‑declaration is more cost‑effective.

·Base RED RF quotes are not the full project total – cybersecurity is separately calculated.

·Self‑declaration still requires full technical file retention – failure to produce documents during audits = non‑compliance.

·Medical wireless products under MDR are exempt from RED 3.3(d/e/f) – no EN 18031 required.


For CE‑RED EN 18031 cybersecurity costs, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.