CE-RED EN 18031 Cybersecurity: Validity and Renewal Rules

2026-09-08

1. Two Compliance Carriers — Do Not Mix Them

Under self-declaration, what lands on paper is a Declaration of Conformity. The declaration itself has no expiry; if the product is unchanged, the cited harmonised standard remains valid and the technical file is complete, it stands. But reading that as "done once and good forever" will get you into trouble — any one of three events forces a re-evaluation: a standard revision, a material product change, or a shift in the threat landscape.

Under a notified body, what you get is a type-examination certificate with a statutory maximum validity of five years, renewable on expiry. There is also a production-phase surveillance set by the body per the specific directive and risk assessment — not every project runs on a "on-site every year" basis.

2. When Must the Declaration Be Re-Issued

A harmonised standard is revised. When a standard is listed in the official gazette it carries a transition period; within that period both old and new versions are valid, and only after it ends is the old version fully superseded. Whether the old report still works and how much must be added depends on what the new version changed and on the assessment conclusion; the technical file and declaration must be updated to match.

The product undergoes a material change. A major firmware rewrite, adding a wireless function, or swapping a wireless component all constitute a fresh placing on the market, and the cybersecurity requirement then applies even if the older version shipped long ago. The call is not yours alone — a pre-change assessment is the safest move.

The security mechanism itself moves. Change the credential policy, update mechanism or cipher suite and the risk-assessment conclusion shifts; the control list and assessment report must be redone, not patched with a few edited pages.

3. Threat Evolution Must Be Managed Continuously

The maintenance plan states a defect-handling flow, and it must actually run: discover, assess, fix and notify, with response times by severity. A disclosed component issue or a changed attack surface both count as items to handle.

The support period is a commitment, not decoration. If the maintenance plan states a support length, then before it ends you either extend support or state clearly in the documentation and user instructions. Writing it without doing it draws attention from market surveillance and from channel partners.

4. How to Keep the Documents and Records

The technical file is kept for at least ten years counted from the date the last product is placed on the EU market. This start point is often misremembered — it is not the production-stop date, nor the day the last batch sells out.

Risk-assessment and maintenance records are best kept across the product's full life cycle. If a security incident actually occurs, being able to show that an assessment was done at the time and the process followed is the most useful pair of documents you have.

5. Renewal Is Not Automatic

On the notified-body route, apply for renewal before the certificate expires. The body checks whether the standard changed or the product changed, and decides between a differential assessment and a full re-evaluation. Projects where hardware and protocol stack are untouched carry far less work, but no step is skipped.

On the self-declaration side there is no "renewal" action, yet there is a need to "re-issue the declaration". After a standard revision or product change, the standard number cited in the declaration and the clauses it covers must be updated synchronously — do not leave the year out.

6. Another Regulation's Date

The Cyber Resilience Act (CRA) becomes fully applicable on 11 December 2027, and it is a different thing from the RED Article 3(3) cybersecurity requirement. The documents you build under EN 18031 today help later, but the two have different conformity-assessment paths and documentation demands, so do not expect one file to serve both.

Making the risk assessment, control list and maintenance plan solid now means most of the draft can be reused directly when CRA arrives — effectively saving a round ahead of time.

7. How to Save Time

For projects of this kind, clients get a compliance ledger: standard version, certificate status, change records and support-period milestones all logged, with a reminder before expiry so it does not rest on memory.

For those managing multiple market accesses at once, BlueAsia's one-stop testing and certification puts each region's expiry milestones on one timeline, handling renewal and change together wherever possible in a single pass.


Contact: King Email: king.guo@cblueasia.comAddress: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!