RED Article 3.3(d)(e)(f) cybersecurity obligations became mandatory for new wireless products placed on the EU market from 1 August 2025. The core 2026 change is not whether to do cybersecurity, but that member states are progressively enforcing it and widening market-surveillance sampling. If RF and safety pass but cybersecurity is missing or the risk assessment fails, you cannot issue a valid DoC and cannot affix the CE mark.
What the three clauses govern:
(d) network protection — stop the device becoming an attack entry point; weak passwords and open unprotected ports are risk points.
(e) personal-data and privacy protection — location, children's, and health data need protection; children's devices are a focal point.
(f) financial-fraud protection — devices with payment or transfer functions need anti-fraud capability.
Quick rule: connected devices meet at least d; add e if personal data is processed; add f if payments are involved.
The EN 18031 three-piece set
EN 18031 is a harmonised standard listed in the EU Official Journal, split into three parts:
-1 maps to (d) network protection,
-2 maps to (e) privacy,
-3 maps to (f) anti-fraud.
It covers control points like access control, authentication, secure update, encrypted communication, and log retention. Published August 2024, it entered the Official Journal in January 2025.
Companies may use other technical routes for equivalent argument, but lose the harmonised-standard presumption of conformity, face heavier argument work, and higher review risk. In practice most projects just adopt this standard. The equivalent path usually still needs a notified body, costing more overall.
2025/138 limitation clauses are the watershed
EU Implementing Decision 2025/138 lists limiting situations; once triggered, the corresponding part loses its harmonised presumption and cannot be self-declared — a notified body must assess.
1. Read the main text, not the annex
The standard's annex is only technical reference; compliance judgement reads the normative clauses of the main text.
2. Blank passwords force notified-body assessment
Products shipped with a blank default password, or no forced first-time password change, must go through notified-body assessment.
Children's and financial-device boundaries:
·Childcare and toy devices lacking parental-control functions must go to a notified body; with full parental control they can still self-declare.
·Payment terminals and smart devices with payment functions fall under part -3, with no self-declaration channel — all need notified-body involvement.
Hitting a limit is not a violation; adjusting the design removes it, but adds lead time and cost.
2026 enforcement is tightening
In 2026 member states step up EN 18031 enforcement with market sampling of civilian connected wireless devices. Cybersecurity is no longer optional — it is a statutory requirement. In-vehicle components type-approved under UN R155, and some devices under sector-specific regulation, may be exempt from this RED cybersecurity obligation.
Note: the old safety standards EN 60950-1 and EN 60065 are long withdrawn; the current harmonised version is EN IEC 62368-1:2020/A11. The 2023 edition is not yet in the Official Journal and is not mandatory.
How to choose the compliance path
Ordinary consumer wireless IoT products complete EN 18031 risk assessment and self-test, and the manufacturer can self-declare without a notified body. Notified-body involvement is mandatory for: financial payment terminals, and minors' smart devices lacking controls. Medical and industrial wireless devices follow their sector regulations first.
Documentation is the decider: security design docs, threat model, conformance argument, vulnerability-scan records, and user security guidance — incomplete files stall the review. Keep technical files at least ten years. Aligning RF/EMC and cybersecurity requirements early cuts later re-certification trouble.
New common pitfalls
Many think it is just a few extra tests — it is a complete security-assessment system. Some think self-declaration covers all products — hit a limitation and you need a notified body. Also distinguish China's GB 44495 from EN 18031: the former is a domestic whole-vehicle national standard, the latter an EU wireless-device standard; different scopes.
Manage firmware changes by grade: only a substantive change touching security-related logic needs re-assessment; ordinary feature iteration that does not touch security control points needs no re-evaluation. Any security-related firmware change, whether or not re-tested, must update the technical file and change record.
Practical advice
At kickoff, make cybersecurity a baseline requirement — access control, authentication, secure update, encrypted communication, and logging planned at the hardware/software architecture stage. Ship secure by default: disable weak passwords, close excess ports, support secure update and tamper resistance.
1. Pick the right notified body
Confirm the NB holds RED cybersecurity qualification and knows your product category; quotes and schedules vary widely.
2. Put document pre-review in the contract
Some bodies offer upfront document pre-review — write remediation rounds into the contract before signing. EN 18031 is already a hard gate for EU wireless products; assigning document responsibility early reduces overseas risk.
BlueAsia covers connected-vehicle, wireless, and multi-country certifications and can help you map EN 18031 together with RED RF/EMC, intervening early rather than patching later.
Contact: King Email: king.guo@cblueasia.comAddress: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China
BlueAsia delivers more than service!
Related News