Many companies new to EN 18031 mistakenly think they can obtain a separate cybersecurity certificate. In reality, EN 18031 is a harmonised standard under the EU RED Directive – governing cybersecurity, privacy, and user‑data protection for wireless devices.
This standard does not issue a standalone certificate – its security content is integrated into the whole‑product RED technical file. Actual costs are concentrated in security assessment, evidence documentation, and whether a Notified Body is involved. Many first‑time teams struggle with document requirements – budgets easily go out of control. When comparing quotes, don't just look at the total – itemised breakdowns are essential.
EN 18031‑related costs split into three main parts:
·Base RED RF/EMC.
·Cybersecurity assessment.
·Documentation and consulting.
Industry quotes vary – some include documentation in testing, others charge separately. When comparing, align the scope – check line by line – don't sign a bundled lump‑sum quote lightly.
1.1 Base RED RF/EMC costs
·This is the testing wireless devices already require.
·Ordinary short‑range products: RF + EMC – roughly RMB 5,000–30,000.
·Cellular and multi‑band high‑power products cost more.
·RF/EMC and cybersecurity are independent – don't merge them into one total – otherwise budget gaps appear later.
1.2 Cybersecurity assessment costs (three tiers)
Based on product function and risk level:
Tier Scope Typical Cost (RMB)
Basic RED 3.3(d) only – network protection 30,000–80,000
Medium RED 3.3(d) + (e) – privacy protection 50,000–100,000
Full High‑sensitivity data – threat modelling + security controls 150,000–300,000
·Products that run locally, do not connect to the internet, and do not process user data – may exempt some clauses – do not apply the full tier.
1.3 Documentation and consulting
Even with self‑declaration, you must produce:
·Security architecture, threat model, security‑control justification – full set.
·If your team lacks capability – external support is needed.
·Document quality directly determines review smoothness – poor documentation undermines all prior testing.
2. NB Path vs. Self‑Declaration – How to Choose
Whether a Notified Body (NB) is required is the key cost differentiator – not all products need NB. Companies should self‑check against the (EU) 2025/138 limitation list. If the product qualifies for self‑declaration – significant savings are possible.
Some agents may push NB solutions to increase their own revenue – don't be unilaterally guided. If any limitation applies – EN 18031 loses its presumption of conformity – self‑declaration is not allowed.
For NB review: fees are charged as review acceptance fees – quotes vary significantly – confirm the currency. For RED 3.3(d/e/f), most NBs only review documents and reports – factory audits are not mandatory – don't default to budgeting for them.
3. Hidden Costs – Often Overlooked
The quote total is not the full project cost – two hidden areas are often missed.
·Freeze firmware versions before formal testing – changing firmware mid‑test invalidates results – requiring re‑queuing.
·Remediation rework: threat‑model defects or insufficient security‑control justification require retesting – adding costs and time. A low‑cost gap analysis upfront prevents expensive later rework.
·Multiple directives: some products are subject to RED, RoHS, etc. Medical wireless devices fall under MDR – exempt from RED 3.3(d/e/f) – no EN 18031 needed. Documents can be cross‑referenced – but testing/NB fees are mostly independent.
4. 2025 Timeline
RED 3.3(d)(e)(f) cybersecurity provisions take effect from 1 August 2025 – applying only to new products placed on the EU market after that date. Products already legally on the market before 1 August may continue selling – no retrospective testing.
Plan new projects early – don't leave technical documents to the last minute.
5. BlueAsia's End‑to‑End Approach
BlueAsia offers full CE‑RED + EN 18031 compliance services – including path determination, gap analysis, document writing, and NB liaison. We start with a gap assessment – determining self‑declaration vs. NB – avoiding blindly choosing high‑cost paths. For multi‑regulation wireless devices – unified planning controls overall cost and timeline.
6. Common Misconceptions and Practical Reminders
·EN 18031 has no independent certificate – part of the RED technical file – no standalone "certificate purchase."
·Not all products need NB – if (EU) 2025/138 limitations do not apply – self‑declaration is more cost‑effective.
·Base RED RF quotes are not the full project total – cybersecurity is separately calculated.
·Self‑declaration still requires full technical file retention – failure to produce documents during audits = non‑compliance.
·Medical wireless products under MDR are exempt from RED 3.3(d/e/f) – no EN 18031 required.
For CE‑RED EN 18031 cybersecurity costs, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News