EN 18031-1 maps to RED Article 3.3(d) and handles network protection. As long as a device can network, this clause almost always applies — it has the widest reach. The core point in one line: the device must not become a launchpad to attack others, nor be remotely controlled as a bot. Routers, cameras, smart locks and industrial sensors all sit inside it.
EN 18031-2 maps to 3.3(e) and handles personal data and privacy. It applies only when the device processes personal data, traffic data or location data. Children's watches, baby monitors and fitness bands fall here, and the collection behaviour has to be restrained.
EN 18031-3 maps to 3.3(f) and handles anti-fraud. Only networked devices that support monetary or virtual-currency transactions must pass it. It is the narrowest in scope but the strictest; POS terminals and NFC payment terminals are typical, and every transaction has to be watched.
Access control: who can log in, how the administrator account is protected, whether weak-password limits exist — all need a design document, and the lab then tries to bypass login or reuse an expired token. Whether default accounts are disabled and how password length is required must be written clearly.
Secure communication: is the device's traffic to cloud, app and other devices encrypted? Packet-capture evidence decides. Bluetooth encrypted but Wi-Fi-to-cloud in clear text still fails — the check runs end to end.
Security update: does firmware upgrade carry a digital signature, is transport encrypted, can it roll back on failure? An OTA without signature verification is an open door for malicious firmware flashing — the lab checks this without fail.
Secure configuration and logging: does it ship in a secure state, are unnecessary ports closed, is there a log of anomalies? Manufacturers often miss these, yet they weigh heavily on the score.
Data minimisation: collection must stay within the minimum functionally necessary — it cannot grab everything. Children's devices mandate parental control; high-risk functions like stranger social networking must be restricted, and parental authority cannot be nominal.
Deletion and notification: when a user asks to delete data, it must actually delete; a breach must notify both the regulator and the data subject per data-protection law such as GDPR (regulator within 72 hours). Notifying only consumers does not count — both sides need a trail.
Transaction integrity: every transaction is protected against tampering; multi-factor authentication and secure boot sit in this clause, and the hardware root of trust behind payments must be in place.
Transaction logging: each entry carries timestamp, amount and device fingerprint, traceable for a number of years. The standard sets no uniform retention; follow the target market's regulator (industry common is five to seven years). On logging, the practical advice is local tamper-proof storage primary with cloud backup secondary — the standard's explicit requirement is that logs are tamper-proof and traceable, so cloud-only fails the moment a regulator looks.
Concept evaluation: does the design thinking hold up, are the mechanisms truly aimed at the threats?
Functional-completeness evaluation: are all required controls present — miss one and it fails.
Functional-sufficiency evaluation: does it actually hold up under attack when run — a written plan alone is worthless.
The conclusion is only pass or fail, no middle grade. A single failure means fix and retest; do not expect to slip through ambiguously.
Self-check the three limitations first: allowing no password, children's devices lacking parental control, financial devices whose security updates rely on a single method. Hit any one and you lose the presumption of conformity and must go to a notified body under Module B plus C.
For projects of this kind, the scope determination goes first — fix which clauses trigger and list the asset inventory, so the later test items have a target and you do not test halfway only to find the direction was wrong.
For those doing RED RF and cybersecurity together, BlueAsia's one-stop testing and certification merges the two document sets, submitting the sample once and scheduling once — simpler than splitting between two houses.
Contact: King Email: king.guo@cblueasia.comAddress: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!
Related News