EN 18031 – effective 1 August 2025.
Don't panic. It only applies to newly placed products – first‑time market entry. Old stock sitting in warehouses is not retrospectively covered.
One more boundary: only connected radio equipment. Pure receivers – wireless devices with no network connectivity – are outside this standard's scope.
RED Directive Article 3.3 – existed for over a decade – legally valid all along. It wasn't that no one enforced it – it was that there was no harmonised standard, so manufacturers couldn't produce test evidence that market surveillance would accept. Enforcement agencies had no basis to act. In 2025, EN 18031 entered the Official Journal – Article 3.3 went from paper to real enforcement.
1. EN 18031-1 – General security
14 security objective groups. Network access control, authentication, software integrity, secure updates, attack surface minimisation – all here.
2. EN 18031-2 – Personal data protection
Cameras, smart speakers, wearables – if they collect, store, or transmit user information – -2 applies.
3. EN 18031-3 – Financial security requirements
Don't just think POS terminals and payment bands – think bigger. Wireless devices with integrated payment modules – any financial transaction processing capability – all in -3's scope. In‑vehicle built‑in payment modules – this is a major Tier‑1 blind spot.
二、14 Security Objective Groups – Exemption Rules
1. Not every clause is mandatory
No OTA capability – software‑update security objectives are not applicable. Only local physical interfaces, no network ports – network access control can be simplified.
2. Exemptions are not self‑declared
You can't just say "not applicable" and move on – that happens daily in factories. Labs don't accept that. Exemptions require applicability justification in the test plan – written assessment – lab review and approval – only then can items be excluded. A casual excuse won't cut it.
三、Factory Default Passwords and the Module A Path
This is the most widely misunderstood rumour in the industry. Many clients are scared by agents: "Your device has a factory default password – Module A is dead – you must go to an NB."
Listen carefully. EN 18031 is a harmonised standard. If you fully meet all applicable clauses – whether or not there's a default password – the Module A self‑declaration path remains open. Only if the device cannot meet EN 18031 requirements – and cannot rely on the harmonised standard for presumption of conformity – does NB assessment become necessary. A default password itself does not block Module A.
1. Relationship with RED Module A
Once EN 18031 is a harmonised standard, compliant wireless devices can still use Module A – no NB mandatory. The process is the same as EMC and RF testing: engage a lab for EN 18031 assessment, issue a report, integrate into the TCF, sign the DoC.
2. Major hidden trap – some clauses lack harmonised standard effect
Most manufacturers are completely unaware of this. The EU Official Journal explicitly notes that some EN 18031 sub‑clauses do not have the effect of presumption of conformity. For the corresponding security objectives, you cannot rely on the standard for compliance presumption – NB involvement is required. If your product falls exactly within those clauses – Module A is unavailable. Before submission, map your product features against the clauses with harmonised effect – line by line. Avoid last‑minute compliance‑path changes and budget overruns.
四、TLS Protocol and Encryption Requirements
1. TLS version specifications
TLS must use currently recognised secure cipher suites. 1.3 recommended – compatibility scenarios may allow fallback to 1.2. TLS 1.1 is considered weak encryption – mainstream lab assessments do not accept it.
Note the wording: the standard does not explicitly "prohibit" TLS 1.1 – it's that in practical assessment, it is not accepted. When referencing the standard, use precise language.
2. Self‑developed encryption protocols
Pre‑shared keys: minimum 128 bits. Certificate systems must have a complete, verifiable chain – with a trusted root certificate source. For self‑developed encryption protocols, the manufacturer must demonstrate that security strength is not lower than the current recognised baseline – and cannot simply be equated to TLS 1.2.
Penetration testing is a lab assessment method – not a mandatory standard requirement. Don't let third parties add extra tests.
3. Password policy
The standard does not set a hard password‑length requirement. However: brute‑force protection is mandatory – login locking, access delays – these are required.
五、EN 18031 and CRA – Don't Confuse Them
Two different things. EN 18031 is a RED Article 3.3 harmonised standard – only governs radio‑connected devices – effective 1 August 2025. CRA is a product‑category‑wide cybersecurity regulation – wired and wireless – all connected digital products – full lifecycle coverage. CRA's formal effective date is 11 December 2027 – currently in transition. Don't confuse the transition period with the mandatory date.
六、Module Assessment Report Reuse – Boundaries
If a wireless module has completed EN 18031 assessment – the whole product cannot directly reuse the module report. The whole product must conduct an independent full applicability assessment.
In many projects, manufacturers assume that if the module passed, the whole product is exempt – only to have their TCF review blocked – requiring supplementary assessment – causing project delays.
七、EN 18031 – Practical Implementation
1. Test methodology characteristics
EN 18031 testing is completely different from traditional EMC or RF testing. It's not automated instrument‑script testing – it's a systematic security assessment. Engineers must manually review firmware security design documentation, code‑signing mechanisms, password policies, port controls, and security logging capabilities – item by item.
·Low‑power IoT sensors: shorter assessment cycles.
·In‑vehicle T‑Boxes, industrial routers: longer cycles.
Assessment costs are higher than standard EMC and safety projects – documentation review + manual penetration assessment – higher labour costs.
Manufacturers must prepare documentation in advance: security architecture design, threat model analysis, password policy description, secure development lifecycle documentation. Hardware companies preparing these documents for the first time – it takes significant time.
2. EN 18031 vs. penetration testing
EN 18031 is a structured security capability assessment – with defined test items and unified pass/fail criteria. Penetration testing is an open‑ended attack simulation – no fixed test list.
Passing EN 18031 does not mean the product can resist all cyberattacks – it only proves compliance with RED Article 3.3's statutory security baseline. Market surveillance can still impose higher requirements under general cybersecurity laws. Operator and financial‑sector tenders often require deeper penetration testing and source‑code audits on top of EN 18031. EN 18031 is the compliance floor – not the security ceiling.
3. Applicability justification documentation – filing requirements
The full set of applicability justification documents must be included in the RED TCF – not just kept inside the test report. Customs and EU market surveillance authorities request the full TCF archive – not a single test report. Avoid missing files or incorrect filing locations during regulatory audits.
For EN 18031 certification, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
相关新闻