Wireless products exported to the EU – key date: 1 August 2025. From this date, RED Directive 3.3(d)(e)(f) cybersecurity provisions take effect for newly placed products. Simply put: wireless‑enabled devices must have cybersecurity conformity evidence – without it, the CE mark is invalid – customs clearance fails – and European e‑commerce listings are blocked.
Existing products already on the market benefit from stock tolerance. As of mid‑2026, not many manufacturers in China have fully completed the process and obtained evidence. Many mistakenly think it's just a few extra tests – in reality, it's a complete security‑assessment framework.
·3.3(d): network protection – devices must not become attack gateways – weak passwords and unprotected ports are now compliance issues.
·3.3(e): personal data and privacy – devices handling user traffic, location, or personal data must have corresponding protection measures. Children's devices are a regulatory focus.
·3.3(f): financial fraud protection – products supporting transfers, payments, or virtual‑currency transactions must implement anti‑fraud capabilities – payment terminals and NFC‑enabled devices are in scope.
Decision logic:
·Connected → at least (d).
·Processes personal data → add (e).
·Payment‑related → add (f).
2. Harmonised Standard – EN 18031
Industry mainstream reference: EN 18031 series:
‑1 → (d) network protection.
‑2 → (e) privacy protection.
‑3 → (f) anti‑fraud.
The standard covers access control, authentication, secure updates, encrypted communication, logging, and other security controls.
EN 18031 is published in the EU Official Journal – but it's not the only option. Companies may use other technical solutions for equivalent evidence – but the compliance burden is high – most projects use this standard.
3. CE‑RED EN 18031 Cybersecurity Verification
Step 1: Scope determination
First, determine which clauses your product triggers.
·In‑vehicle T‑Box as part of a complete vehicle: RED compliance responsibility rests with the vehicle manufacturer – T‑Box components are not exempt. If the T‑Box or module is sold separately – all three clauses must be assessed.
·Children's watches: RED 3.3(e) applies to radio device communication processing personal data – if the device stores location locally and does not connect to a network – (e) is not triggered.
Step 2: Gap assessment
Check your current implementation against EN 18031 controls. Common non‑conformities:
·Firmware upgrades without signature verification.
·Factory‑empty passwords.
Also check: secure storage, encryption strength, logging.
Produce a gap‑assessment report – this is the input for design remediation and testing – do not skip this step.
Step 3: Three Commission limitations
Under Implementing Decision (EU) 2025/138, three scenarios cause EN 18031 to lose its harmonised‑standard status – self‑declaration is not allowed – an NB must be involved:
·No default password at factory.
·Child device has access controls but lacks parental controls.
·Financial device uses only a single security‑update scheme.
These conditions do not mean the product is non‑compliant – fixing the design removes the limitation.
Step 4: Choose your path
·If the product does not trigger any of the three limitations → manufacturer can self‑declare DoC.
·If any limitation is triggered → must use NB assessment – security documents reviewed, functional tests run – only after the type‑examination certificate can you affix the CE mark.
In practice, most clients encounter limitations and need NB involvement.
Step 5: Documentation and implementation
·Smooth project: 2 months.
·With documentation and remediation: 3+ months.
The real bottleneck is usually not testing – it's the full technical documentation. Solid security architecture and vulnerability analysis make testing smoother.
Ordinary RF RED test costs are relatively limited – adding cybersecurity, especially with NB assessment – significantly increases total costs – depending on the assessment scope.
4. How to Choose a Notified Body
·Confirm the NB has RED cybersecurity competence.
·Ensure they are familiar with your product category.
·Quotes and schedules vary – some NBs require upfront document pre‑review.
·Before signing, confirm whether the quote includes remediation rounds – avoid unexpected fees mid‑test.
5. Required Technical Documents
·Security design documents.
·Threat model analysis.
·Compliance evidence for each control.
·Vulnerability scans and functional test records.
·User security guidance.
Document completeness directly affects NB review efficiency – last‑minute document assembly causes project delays.
6. Relationship with Other Regulations
·EN 18031: product‑level security for radio equipment.
·GDPR: data protection – separate – they cannot substitute for each other. Products entering the EU still need separate data‑compliance measures.
Also distinguish from the CRA – which has independent obligations from RED 3.3(d/e/f) – don't confuse them.
7. Timeline Example
Wi‑Fi module project:
·Scope determination: 1 week.
·Gap remediation: 3 weeks.
·NB document review: 2 weeks.
·Testing: 2 weeks.
·Issuance: 1 week.
Smooth total: ~2 months. Projects with document delays: 4 months – common.
8. Certificate Verification Reminder
·NB‑issued RED type‑examination certificates: NANDO only lists NB qualifications – not individual product certificates – obtain product certificates from the issuing NB.
·Self‑declaration path: no central database – companies keep DoC and test documents – when audited, you must produce them quickly – that's true compliance.
Firmware updates: only substantive changes affecting security logic require re‑assessment – routine feature updates that do not touch security controls do not require re‑evaluation.
For CE‑RED EN 18031 cybersecurity verification, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.
Related News