EN 18031 Certification Steps – EU Cybersecurity Compliance Full Process

2026-07-30

From 1 August 2025, all new wireless devices placed on the EU market must complete EN 18031 cybersecurity assessment. This change comes from RED Directive Article 3.3 – turning cybersecurity from industry best practice into a regulatory mandate. For manufacturers, EN 18031 is a new compliance framework – not something you can solve with a few extra test reports.

1. EN 18031's Place in the RED System

EN 18031 is a harmonised standard under RED Article 3.3 – sitting alongside RF and EMC testing. It is a system of three sub‑standards.

  2. The Three Sub‑Standards – Division of Labour

·EN 18031‑1: General cybersecurity requirements – covers all connected wireless devices – security updates, access control, password policies, security logs, etc.

·EN 18031‑2: Personal‑data protection – for devices handling user privacy data.

·EN 18031‑3: Financial transaction protection – for connected radio equipment handling monetary value or virtual currency transfers.

·Ordinary consumer electronics typically only need ‑1.

·Child watches, health‑monitoring devices handling sensitive personal data – ‑2 is also mandatory.

·Payment‑enabled smart terminals need ‑3.

Note: "payment function" here means initiating financial transactions – not simply scanning QR codes or receiving payment notifications. Many NFC‑equipped devices that only do card reading without transaction processing are misjudged as needing ‑3. Match your product's data handling accurately – not every product runs all three sub‑standards.

  3. EN 18031 – Mandatory Date and Transition Rules

1 August 2025 is the watershed. The trigger is the first market‑placement date – not the certificate completion date. Existing models already placed before that date can continue selling until stock is exhausted. New RED applications for new models must complete EN 18031 assessment from this date.

Transition detail often missed: after 1 August 2025, if an existing model undergoes a major change (hardware architecture or firmware architecture changes) – it is treated as a new product – EN 18031 must be completed. Old certificates are not automatically permanent.

Additionally: in‑vehicle radio equipment under vehicle WVTA regulation is exempt from RED 3.3(e) privacy and 3.3(f) fraud‑prevention clauses – only 3.3(d) (EN 18031‑1) is required. Automotive products do not need the full ‑1 and ‑2 suite.

  4. Certificate Ownership – Get This Straight

There is no independent EN 18031 certificate. When an NB issues a certificate, it is a RED type‑examination certificate with the EN 18031 standard referenced on it. Test reports are included in the RED TCF technical documentation package.

  5. Notified Body (NB) Involvement – Triggers

5.1 Loss of presumption of conformity ≠ mandatory NB
Harmonised standards have limiting clauses. If the device's authentication scheme allows skipping authentication or no password – the corresponding clause loses presumption of conformity. Losing presumption means you cannot rely on self‑assessment plus claimed compliance. Manufacturers can either:

·Engage an NB for type‑examination, or

·Perform an equivalent risk assessment and technical justification for regulatory audit.

In practice, most manufacturers choose the NB route – simpler and direct. But legally, it is not the only path.

5.2 Default passwords are NOT a trigger
Factory‑default passwords and allowing password‑free use are two different things. As long as the user is forced to change the default password on first boot, the limiting clause is not triggered. Many manufacturers misread the limiting clause and assume their product must go NB – but forced‑first‑change products are not subject to this.

Additionally, the RED system has no official Class 1/2/3 device classification – the classifications circulated domestically are informal summaries – always refer to the standard text.

5.3 Which devices are exempt?
The key criterion: does the device have internet connectivity capability? Devices with only local RF communication and no internet access do not trigger RED 3.3 – EN 18031 is not required. In‑vehicle broadcast radios and FM receivers are generally exempt. However, if they integrate 4G or Wi‑Fi connectivity, assessment is still required. Devices that actively transmit but are not internet‑connected – exemption is conditional on confirming that internet access is impossible – do not equate a pure RF transmitter with automatic exemption.

  6. EN 18031 – Pre‑Assessment Phase

6.1 Gap analysis is the first step
Before formal testing, you must complete a gap analysis. Assess against the 14 security objective groups in EN 18031‑1 – marking already‑met, needs‑remediation, and not‑applicable sections. Output: a security objective conformance matrix – the guiding document for the entire certification process.

Applicability exclusions must have thorough technical justification – market surveillance authorities can review the gap‑analysis matrix – unjustified removal of security objectives leads to immediate non‑conformance. The gap‑analysis matrix, threat model, and vulnerability‑management plan are the three most frequently requested documents during audits.

Products without OTA capability – remote‑update security objectives can be excluded. Pure sensor devices with no user‑data storage – data‑protection items can be excluded.

6.2 Technical documentation requirements
EN 18031's documentation requirements are significantly higher than traditional RED. You must submit: security architecture diagrams, threat model analysis, secure development process, vulnerability‑management plan, cryptographic algorithm list, and key‑management scheme. Document preparation: roughly 2 weeks.

  7. Key Points in Test Execution

7.1 TLS encryption requirements
EN 18031 requires prohibiting protocols with known major vulnerabilities – TLS 1.0, 1.1, and all SSL versions are forbidden. TLS 1.2 or 1.3 are allowed. TLS 1.3 is industry best practicenot a mandatory clause.

7.2 Secure boot and firmware protection
EN 18031‑1 requires devices to verify firmware integrity and authenticity during boot – this is the most common failure area. However: the standard does not mandate hardware security chips or hardware root of trust – equivalent firmware integrity verification schemes are acceptable – as long as they achieve protection against unauthorised firmware tampering.

Firmware OTA update mechanisms are also a high‑failure item – having an update channel alone is not enough – you need vulnerability‑fix and rollback‑protection capabilities.

NIST SP 800‑193 (platform firmware resilience guidance) is not a mandatory EN 18031 requirement – labs accept equivalent schemes.

7.3 Common failure items and remediation

·Password policies not meeting complexity requirements – a high‑frequency failure. Default passwords must be forced to change on first use.

·Production firmware must have debug interfaces disabled – all open ports must have business justification.

72‑hour breach notification is a GDPR requirement; 5‑year transaction log retention is a PSD2 requirement. Neither is an EN 18031 test item – but if you are operating in the EU, both must be satisfied – just not through EN 18031.

Test coverage includes: port scanning, protocol fuzzing, and known‑vulnerability validation. Remediation timeline depends on depth – password‑policy adjustments take 1–2 weeks; security‑architecture rework may take months. Leave 4–6 weeks of remediation buffer in project schedules – assuming first‑pass; vulnerabilities add more.

EN 18031 assessment cannot directly reuse UN R155 in‑vehicle cybersecurity reports – the two standard frameworks and security objectives are not interchangeable – automotive Tier‑1s are particularly prone to this trap.

7.4 Document archiving and long‑term maintenance
EN 18031 reports are included in the RED TCF – managed alongside RF and EMC reports. RED requires technical documentation to be retained for 10 years after the last product batch is placed on the market. CRA (from 11 December 2027) has a separate 10‑year retention requirement – the two regulatory obligations have different boundaries – do not merge them.

Manufacturers doing EN 18031 compliance cannot only focus on certification itself – the security‑update mechanism, vulnerability monitoring and patch release, and incident response – these are where the real challenges lie post‑certification.

7.5 CRA 2027 integration
CRA's scope is broader than EN 18031 – covering non‑wireless connected devices and large IoT platforms. Products that have already completed EN 18031 assessment have a good foundation for RED wireless device security – but CRA also requires a Software Bill of Materials (SBOM) and vulnerability disclosure – unique items. Doing EN 18031 now – consider CRA integration simultaneously – avoid duplicate investment in two years.


For EN 18031 certification steps, contact BlueAsia at 13534225140 (King) or king.guo@cblueasia.com.