EN 18031‑Based CE Cybersecurity Testing – Cost Breakdown

2026-08-10

Since the RED cybersecurity provisions became mandatory on 1 August 2025, products with wireless and network connectivity exporting to the EU can no longer avoid EN 18031 testing. Manufacturers familiar with standardised RED RF and EMC testing – where quotes are fairly consistent – are confused when they see EN 18031 quotes ranging from RMB 30,000 to 300,000 – a ten‑fold difference.

一、First, Understand This: It's Not a Standalone Charge

EN 18031 is not a separate certificate – it's a harmonised standard under the RED Directive – satisfying RED Article 3.3 cybersecurity compliance. The correct term is RED cybersecurity compliance based on EN 18031. After testing, the report is integrated into the overall CE‑RED technical file – the manufacturer signs the DoC.

Cybersecurity is an add‑on to the base RED certification. Base RED (RF + EMC): domestic labs – RMB 6,000–20,000 – foreign labs – RMB 18,000–40,000. Cybersecurity assessment is separately charged – not included in the base RED quote.

  二、EN 18031 Test Fees – The Biggest Cost Item

EN 18031 assessment has two parts: document/concept assessment and functional testing – documentation workload is significant. Most market quotes are bundled – they may not break down the three items separately.

·Basic devices (ordinary headphones, smart‑home sensors): only EN 18031-1 triggered – test fees RMB 30,000–80,000.

·Medium‑risk devices (smartwatches, industrial routers): additional privacy‑data encryption, access control, remote‑access security – EN 18031-1 + EN 18031-2 – RMB 50,000–100,000.

·High‑risk devices (POS terminals, financial transaction devices): all three sub‑standards – EN 18031-1, -2, -3 – RMB 150,000–300,000.

One common confusion: ordinary wireless medical devices generally only require -1 and -2 – -3 is not mandatory. Medical devices also need to meet MDR requirements – don't mix the two regulatory systems.

·Why the cost gap?

Test depth is directly tied to product functionality. Products handling personal data require -2 privacy tests. Products involving financial transactions require -3 fraud‑prevention tests. A simple connected sensor vs. a payment terminal – test items differ by several times – costs naturally differ by several times.

  三、Notified Body (NB) Fees

Under EU Implementing Decision (EU) 2025/138, if the product triggers the listed conditions (e.g., allowing password‑free login, child devices lacking parental controls) – those clauses lose presumption of conformity – Type‑B type‑examination is mandatory.

NB fees:

·Document review: RMB 8,000–15,000.

·Factory audit: RMB 5,000–10,000 (including travel).

Certification issuance fees are often overestimated. Type‑B type‑examination has no official fixed pricing – different NBs quote differently. For consumer electronics, NB review + certification is typically a few thousand euros – not "€20,000 starting." High‑risk financial devices push the cost higher.

If your product can use the self‑declaration path – no NB involvement – this cost is saved. Confirm this at project kick‑off.

  四、EN 18031 – Remediation and Hidden Costs

1. Firmware remediation

Issues found require firmware changes. Simple issues (disabling debug logs, changing default passwords, improving password policies): 1–3 days. More involved (communication encryption upgrade, firmware security re‑design): 1–4 weeks.

2. Hardware modifications

Some security issues cannot be fixed in firmware – require hardware changes. Adding a security chip (e.g., NXP SE050): hardware + development – roughly €5,000 (not just the chip). Developing a secure update mechanism: €2,000–5,000. Budget for hardware remediation.

3. Debug sample requirements

Penetration testing requires, in addition to 2–3 production samples, engineering debug samples with debug interfaces exposed – some scenarios require root access. Fully locked‑down production samples cannot complete deep security assessment – many projects stall at this step.

4. Expedite and ongoing maintenance

Expedite services typically add 30–50% – roughly €2,000–5,000. Basic devices: ideal 8 weeks compressed to 4 – but expedite availability depends on lab and NB scheduling – some projects cannot be expedited.

RED Type‑B certificates: no mandatory annual surveillance – if the product is unchanged, no annual fee. Firmware changes affecting security mechanisms require NB change assessment. Ordinary functional upgrades do not. The CRA will bring additional ongoing security maintenance obligations – don't mix the two regulatory systems.

  五、Total Cost Reference – By Product Type

·Simple products (connected sensors): EN 18031-1 only – test fees RMB 30,000–50,000 – no NB – total RMB 30,000–80,000.

·Medium products (Wi‑Fi routers, smart cameras): EN 18031-1 + -2 – test fees RMB 50,000–100,000 – NB may be required – total RMB 80,000–150,000.

·High‑risk products (POS terminals): all three sub‑standards – test fees RMB 150,000–300,000 – NB mandatory – total RMB 200,000–400,000+.

All figures are exclusive of tax. Cross‑border projects – VAT, cross‑border transfer fees, translation/notarisation – budget separately.

  六、EN 18031 – How to Control Costs

Security‑by‑design saves money. If you build default‑password policies, firmware signature verification, communication encryption, and debug‑interface access control into the design phase – remediation rounds are fewer. Last‑minute firmware fixes – each remediation round adds 1–4 weeks.

Using pre‑certified security modules can reduce some protocol‑layer testing by roughly 30%. If you already have ETSI EN 303 645 reports, risk‑assessment and security‑architecture documents can be reused – reducing document‑preparation time by ~20% – but: reports cannot directly substitute EN 18031 testing – all test items must still be fully executed.

1. Prepare security documentation in advance

A significant portion of EN 18031 review is documentation. Threat‑model analysis, risk‑assessment matrix, security‑architecture description, vulnerability‑management plan – these cannot be written in a day or two. Many projects spend only 3–4 weeks on testing – but document preparation, because internal security systems weren't ready, dragged on for over two months.

If your R&D team doesn't have dedicated security staff – we recommend bringing in an external security consultant at the project‑definition stage. Consultant fees: a few thousand euros – but can compress document preparation from two months to 2–3 weeks – far cheaper than project delays.

2. Vulnerability disclosure and post‑market maintenance

EN 18031-1 requires manufacturers to have a vulnerability‑disclosure policy and security‑update mechanism – a mandatory RED 3.3 obligation – included in the TCF. Disclosure channels do not require a public website – email and forms are acceptable.

Post‑market firmware changes – whether they require NB notification – depends on the scope. Simple functional optimisations – no. Changes affecting security mechanisms – require re‑test reports. Each retest: a few thousand euros. Confirm the maintenance plan at project kick‑off – avoid frequent post‑market retests.

3. ETSI EN 303 645 can help – but cannot substitute

Products with ETSI EN 303 645 certification – documentation (e.g., risk assessments) can be reused – reducing document‑preparation time by ~20%. But: you cannot directly reference the original test reports – all EN 18031 test items must still be fully executed. EN 18031 goes deeper than 303 645 – especially privacy‑data handling and financial security.

Products with 303 645: testing timeline 6–8 weeks. Without: 8–12 weeks. Doing 303 645 first then EN 18031 – total cost is higher than EN 18031 alone – only suitable for products targeting both EU and non‑EU markets.


For EN 18031 cybersecurity testing costs, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.