What Is EN 18031? The CE-RED Cybersecurity Standard Explained

2026-08-25

一、Where EN 18031 comes from

EN 18031 is a harmonized standard under the EU Radio Equipment Directive (RED), governing cybersecurity and mapping to RED Article 3.3(d)(e)(f). CEN and CENELEC published it in August 2024, and it was entered into the EU Official Journal's list of harmonized standards on 30 January 2025; using it for assessment gives you the presumption of conformity.

Be clear: 1 August 2025 is the date Article 3.3(d)(e)(f) cybersecurity obligations become mandatory — from that day, wireless products placed on the EU market must comply. But compliance is not limited to EN 18031; other technical routes are allowed, they just miss the harmonized-standard presumption of conformity, and when a limiting clause is hit you still need a notified body.

1. The three risk types it governs

(d) governs network protection — being connected must not become an attack springboard; weak passwords and open ports count as compliance problems.

(e) governs personal-data privacy — handling user traffic and location needs protective measures, with children's devices a focus.

(f) governs financial fraud — products supporting payments, transfers, or virtual currency must implement anti-fraud capability. Connected at minimum meets d; handling personal data adds e; involving payments adds f — layered on top.

2. Where the three Commission limitations come from

Under EU Implementing Decision 2025/138, three situations strip the corresponding part of its harmonized-standard status, so you cannot self-declare and a notified body must step in: factory-set no password, children's devices lacking parental controls, and financial devices with only a single update method. Hitting any one is not a violation — redesign removes it — but the project adds an NB assessment, raising cost and lead time.

  二、How the standard splits into three parts

1. EN 18031 splits into three parts

-1 maps to (d) network protection, for connected devices; -2 maps to (e) privacy, with children's, toy, and wearable products the focus; -3 maps to (f) anti-fraud, for devices handling money or virtual currency. Each part covers control points like access control, authentication, secure update, encrypted communication, and logging.

2. This is not the only route

It is a harmonized standard in the Official Journal, but not the only path — equivalent proof via other technical routes is possible. The equivalent route misses the harmonized-standard presumption of conformity, demands very high technical argumentation, and carries high review risk, so most real projects just adopt this set to avoid arguing with reviewers.

  三、How it relates to other regulations

EN 18031 governs product-level security of radio equipment and sits in a different system from the GDPR — they cannot substitute for each other. Products entering the EU must implement data-privacy compliance separately.

1. Do not confuse it with the CRA

The EU Cyber Resilience Act and RED 3.3(d/e/f) obligations are independent — one governs product security, the other the full lifecycle. Do not mix them. The CRA has its own scope thresholds; not all RED wireless devices fall under the CRA, so considering both at the design stage is safer.

  四、Which products get triggered

When an in-vehicle module is placed on the market with the whole vehicle, the OEM is the RED compliance responsible party, but the module maker must also ensure the module meets all RED requirements — you cannot offload the obligation entirely onto the car maker. If the module is sold separately as a standalone wireless product, d/e/f all must be assessed. Children's watches, smart speakers, and payment POS terminals are high-frequency hits.

1. How to tell which clause you hit

List the product functions: does it connect, does it process personal data, does it involve payments? Those three questions basically locate which clauses trigger, then run a gap assessment against EN 18031 control items — easier than blind testing.

  五、What the verification path looks like

First scope determination, then item-by-item gap assessment. Hitting one of the three limitations sends you to a notified-body assessment; otherwise the manufacturer can self-declare. Two months smooth, three months or more if document remediation is heavy — what stalls progress is the full technical documentation, not the testing.

1. Documentation is the decider

Security design documents, threat models, conformance arguments, vulnerability-scan records, user security guidance — miss one and the NB review stalls. Rushing materials late often delays; assigning documentation ownership early is steadier.

  六、Common misunderstandings

Some think it is just a few extra tests — wrong, it is a complete security assessment system. Some think self-declaration is universal — wrong, hitting a limitation forces NB involvement. Some confuse GB 44495 with EN 18031 — wrong, one is a domestic whole-vehicle mandatory national standard, the other an EU wireless-device standard; different scopes.

1. Firmware iterations need sorting

Only a substantive change touching security-related logic needs re-assessment; ordinary feature iterations that do not touch security control points need no re-test. But a security-related firmware change, even without re-testing, must still update the technical file and change record — not nothing moves. Graded change management saves a lot of re-testing.

  七、How companies should land it

Treat cybersecurity as a baseline at project kickoff — access control, authentication, secure update, encrypted communication, and logging designed in at the architecture stage. BlueAsia covers connected-vehicle, wireless, and multi-country certification needs and can help you map EN 18031 together with RED RF/EMC, intervening early rather than patching later.

1. Pick the right notified body

When choosing an NB, first confirm it holds RED cybersecurity qualification and knows your product category; quotes and schedules vary widely, and some require upfront document pre-review. Before signing, confirm the quote covers remediation rounds and write the document pre-review requirement into the contract — BlueAsia reminds you these two steps avoid later arguments.


BlueAsia provides one-stop multi-country certification coordination, anticipates the compliance impact of product changes in advance, avoids cross-market compliance risks, and keeps your products exporting and listing steadily.

Contact: King
Email:
king.guo@cblueasia.com
Address: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China

BlueAsia delivers more than service!