1. Fix the Applicability Relationship First
The three clauses of RED Article 3(3) — (d), (e) and (f) — map to EN 18031-1 (network protection), EN 18031-2 (personal-data privacy) and EN 18031-3 (anti-fraud). The determination order: a device that can network triggers at least (d); handling personal data, location data or traffic data adds (e); storing, processing or settling monetary value locally adds (f).
On timing, do not mix them: the European Commission used (EU) 2025/138 — amending the harmonised-standards decision (EU) 2022/2191 — to list the three standards in the Official Journal's harmonised list, published on 30 January 2025; the cybersecurity requirement has applied to newly placed products since 1 August 2025.
2. The Risk Assessment Report Is the Base of the Whole File
Write it in four steps: assets, threats, security mechanisms and residual risk. The asset list covers data, functions and services, each tagged for confidentiality, integrity and availability — a Wi-Fi credential is confidentiality, firmware is integrity, an emergency call is availability.
Threat analysis finds the path against each asset. You may reference the standard's appendix threat list, but you must add your own hardware attack surface; copying it verbatim shows immediately. Each threat gets one protective measure with its parameters written out — "already encrypted" in three words will not pass review.
Write the residual risk honestly. A consumer device cannot resist physical teardown; writing that as accepted with a reason is fine, while hard-writing "risk equals zero" reads as unprofessional.
3. Technical Implementation Documents Prove the Controls Land
The security architecture document draws the security domains, key storage location, secure-boot chain and encrypted channels. If a secure chip or TEE is used, mark the boundary between secure and non-secure zones and the verification mechanism for data crossing it.
Key management covers the full lifecycle: generation, storage, distribution and destruction. Hardware keys go in eFuse or a secure element, not plaintext in flash; each device needs its own factory key, and a whole line sharing one key is what reviewers scrutinise most.
Firmware security covers secure boot, signature verification and anti-rollback, plus OTA encryption, package-integrity checking and fail-back. Communication security states the protocol and suite versions — no low-version TLS allowed — and the token validity and refresh mechanism.
The debug port is a frequent failure point. JTAG, serial and SWD must be closed or authenticated at factory; leaving an open port that lets someone read the firmware voids everything written above.
4. Control List and Clause Mapping
List a control table mapping each control to the applicable (d)(e)(f) clause. Assessment runs per mechanism: concept evaluation, functional-completeness evaluation and functional-sufficiency evaluation, with conclusions that are only pass or fail — no middle grade.
These materials join the RED Annex V technical file; they are not a separate system.
5. The Post-Market Part Must Be Written Too
The maintenance plan states the update strategy, support duration and the defect-handling flow after launch — discover, assess, fix and notify, with response times by severity. Without an internal security team, state the external partner and response mechanism.
A software bill of materials is not a mandatory submission, but keeping one helps — when a component has an issue you can check the impact scope yourself, which saves trouble.
The user documentation must state safe-use prompts, such as changing the default password on first use and updating firmware promptly. The Declaration of Conformity cites the standard with its year — EN 18031-1:2024 — not the number alone.
6. Two Points That Stall Projects
Self-check the three limitations first: allowing the user to set no password, children's devices lacking parent or guardian controls, financial devices whose security updates rely on a single method. Hit any one and you lose the presumption of conformity and must go to a notified body under Module B plus C; if you hit none and apply the standard fully, self-declaration suffices — the online claim that "cybersecurity always needs a notified body" does not hold.
Document retention is at least 10 years from the date the product is placed on the EU market; for continuously produced products it usually runs from the last batch placed. Keep the risk assessment and maintenance records across the product's full life cycle.
7. How to Save Time
For projects of this kind, the risk assessment goes first — fix the applicable clauses and the asset list, and the architecture document and test items behind them have a target.
For products doing RED and other market access at once, BlueAsia's one-stop testing and certification arranges the cybersecurity documents together with the RF, EMC and safety files, so the same piece of information does not end up stated inconsistently.
Contact: King Email: king.guo@cblueasia.com Address: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!
Related News