Since 1 August 2025, EN 18031 cybersecurity testing has become a mandatory part of CE‑RED certification. Smart speakers, Wi‑Fi routers, IoT sensors, security cameras – if your product has wireless functionality and network connectivity for EU export – you can't avoid it.
Labs quote 3–5 weeks. But in practice, cases that pass smoothly are far outnumbered by those that get stuck. Based on 2026 operational data, I'll break down the actual timeline for each step of EN 18031 – what makes it faster, what makes it slower – so you have a realistic picture.
1.1 Core concept: EN 18031 is not a separate certificate. It's a harmonised standard under the RED Directive – used to satisfy RED Article 3.3 cybersecurity requirements. After completing EN 18031 testing, the report is integrated into the overall CE‑RED technical file – the manufacturer signs the DoC.
1.2 Important limitation: some chapters of EN 18031 do not have harmonised presumption of conformity. If your product uses these chapters – even with a lab test report – a Notified Body (NB) must still be involved. This determination is not related to the RED Annex IV list – Annex IV covers RED Articles 3.1 and 3.2 (safety, EMC, RF) – the cybersecurity Article 3.3 NB requirement is based on the limitations annotated within the EN 18031 standard itself. At project kick‑off, confirm whether your product touches chapters without harmonised effect – avoid having to add NB review mid‑way.
1.3 Scope confusion: EN 18031 is triggered by radio equipment + internet connectivity capability – both are required. Pure local Bluetooth headphones, non‑connected sensors, or smart plugs with only local network communication – not in scope. Products with only Bluetooth audio and no Wi‑Fi or Ethernet connectivity – do not trigger EN 18031.
2. Document Preparation – 1 to 4 Weeks
How fast this goes depends entirely on the company's security design foundation and document quality.
EN 18031 requires specialised cybersecurity documents:
·Risk assessment: covering network attacks, data leakage, firmware tampering, and unauthorised access.
·Security design description: encryption protocols, access‑control strategy.
·Data flow diagram: the full chain – collection, transmission, storage, deletion – this is the technical requirement for RED 3.3(e) privacy protection.
Distinction: EN 18031-2 requires a data flow diagram – but it does not conduct GDPR compliance testing. GDPR is a separate regulation – not a RED test item. Vulnerability response mechanisms and CVD (Coordinated Vulnerability Disclosure) policies – these are manufacturer obligations under CRA – not mandatory EN 18031 submission items – don't put CRA documents into the EN 18031 package.
Documents must match the product: if you claim AES‑256 encryption but the product uses AES‑128 – direct failure. If you claim OTA secure updates but the firmware update interface is open without signature verification – the claim is worthless. Companies with solid security design and complete documents: 1–2 weeks. Those preparing from scratch: 1 month or more.
Sample trap: EN 18031 penetration testing requires not only 2–3 production samples – but also debug samples – with debug interfaces and root permissions exposed. Locked‑down production samples alone cannot complete penetration testing – many projects stall because debug samples weren't prepared. Firmware version must match production – default configuration cannot be changed for testing.
3. Lab Testing Phase – 2 to 6 Weeks
This is the core of EN 18031 – and where timeline variability is greatest.
3.1 EN 18031 has three parts:
·EN 18031-1: general security – all connected wireless devices must pass.
·EN 18031-2: personal‑identifiable data – applies when the device processes user privacy data. Not all consumer smart‑home devices automatically trigger -2 – only those handling personal data.
·EN 18031-3: financial transactions – radio equipment directly involved in monetary transactions – e.g., payment terminals. Ordinary industrial controllers without financial transactions – only -1 is needed.
3.2 Timeline:
·Simple products (connected sensors, Wi‑Fi smart plugs): 2–3 weeks.
·Medium complexity (Wi‑Fi routers, smart cameras, multi‑protocol IoT gateways): 3–4 weeks.
·Complex (POS terminals, payment terminals): 4–6 weeks or longer.
3.3 Testing is not just waiting. The lab feeds back issues in real time – firmware tweaks: 2–3 days. Architecture‑level issues or encryption re‑design – not a few days. Common failures:
·Default passwords too simple – no complexity requirement.
·Debug interfaces open – no access control.
·Firmware updates without signature verification.
·Sensitive data transmitted in plain text.
4. Remediation Phase – 1 to 4 Weeks
After the lab identifies issues, remediation begins.
·Simple issues (disabling debug logs, changing default passwords, improving password policies): 1–3 days.
·More involved (communication encryption upgrade, firmware security re‑design): 1–4 weeks.
EN 18031 security issues cannot be bypassed. Going the NB route does not mean security vulnerabilities don't need fixing – NB review also requires EN 18031 compliance. However, if certain standard clauses lack harmonised effect – you may submit alternative technical solutions for NB assessment of equivalence – not every clause must be literally met.
5. Final Stage – 1 to 2 Weeks
After all tests pass and remediation is complete – the lab issues the formal test report. Ideal: 1–2 weeks. If supplementary evidence or document review is needed – the timeline extends.
Technical file compilation – EN 18031 test report, security design documents, risk assessment, data flow diagram, firmware security description – all assembled. The manufacturer signs the RED DoC.
User manual language: for sales in a single EU member state – only that country's official language is required – not all EU official languages – consistent with general CE‑RED language rules.
6. Total Timeline by Product Type
·Simple (connected sensors, Wi‑Fi smart plugs): 4–6 weeks – provided security design is solid, documents complete, and testing has no major issues. If 3–4 non‑conformities require back‑and‑forth – 8 weeks is common.
·Medium complexity (Wi‑Fi routers, smart cameras, multi‑protocol gateways): 6–10 weeks – extra time for more test items and more complex remediation. Architecture‑level vulnerabilities extend further.
·High risk (POS terminals, payment terminals): 10–14 weeks or more – more test items – once issues arise, remediation is unpredictable.
7. 2026 – New Parallel Factors
CRA (Cyber Resilience Act) – vulnerability reporting obligations take effect from 11 September 2026. Manufacturers must report actively exploited security vulnerabilities and serious incidents to ENISA. Full compliance: 11 December 2027.
Distinction: CRA vulnerability reporting is a post‑market operational legal obligation – not a CE‑RED or EN 18031 lab test item. Labs will not test CRA reporting processes. CRA is a separate Act – don't mix it with RED EN 18031 testing. However – security update mechanisms and vulnerability management processes should be designed early – CRA compliance will eventually require them.
For CE‑RED EN 18031 testing timelines, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News