Guides and playbooks/Radio Equipment Directive
CYBERSECURITYREDEN 18031

Cybersecurity under the Radio Equipment Directive, and how EN 18031 is applied

EN 18031-1/-2/-3:2024 · Playbook, 4 sections · August 2026
Download the PDF
TL;DRFive things to take away
  • 01Commission Delegated Regulation (EU) 2022/30 activates Article 3(3)(d), (e) and (f) of the RED for specified categories of radio equipment, and as amended those requirements have applied since 1 August 2025.
  • 02Implementing Decision (EU) 2025/138 cites EN 18031-1, -2 and -3 in the Official Journal, with four restrictions that are material to the conformity route rather than cosmetic.
  • 03The most common self-inflicted trigger is the password option. Presumption is lost where clauses 6.2.5.1 and 6.2.5.2 are applied so the user may set no password at all. Requiring a credential on every interface keeps Annex II open.
  • 04Four gates decide whether you can self-declare. One failure sends that single requirement to Annex III or Annex IV, not the whole product.
  • 05Legally available is not the same as ready. Whether controlled evidence exists today for each control is the separate question that usually delays the declaration.

What applies, and to which equipment

Applying EN 18031 to a specific product is the manufacturer's responsibility.

European Commission guidance on the EN 18031 restrictions

Which equipment is caught

Caught. Anything that can reach the internet, on its own or through a phone, gateway, or router. Connected sensors, cameras, wearables, appliances, industrial gateways, toys and childcare equipment, and any product that also carries a payment or virtual-currency function.

Still caught, often assumed otherwise. Equipment sold business-to-business, equipment behind a customer firewall, and equipment whose connectivity is provided by an integrated third-party module. Connectivity that is present but disabled by default is still connectivity.

Excluded. Equipment covered by the specified aviation, motor-vehicle, and medical-device exclusions in Delegated Regulation (EU) 2022/30, and equipment with no internet reachability at all. Both need a written determination, not an assumption.

Two things the cybersecurity file does not settle

Article 3(1)(a) health and safety, Article 3(1)(b) EMC, and Article 3(2) efficient use of spectrum remain part of the same conformity assessment, and questions about antennas, modified housings, shielding, or enabled bands ordinarily need a competent testing laboratory. No route conclusion follows from EN 18031 evidence alone.

And a CE-marked module is evidence, not cover. The object of assessment is the final radio equipment placed on the market under the manufacturer's name. A supplier declaration for an incorporated module or router is supporting evidence subject to integration conditions, and where a router leaves its original housing that evidence may no longer be representative.

DateWhat happens
30 Jan 2025Implementing Decision (EU) 2025/138 cites the three EN 18031 parts in the Official Journal, with four restrictions attached.
1 Aug 2025Articles 3(3)(d), (e) and (f) are enforceable for products placed on the EU market from this date, with no transition for new placements.
11 Dec 2027Delegated Regulation (EU) 2022/30 is repealed and the Cyber Resilience Act applies in full, extending the obligations beyond radio equipment.

The controls a good assessment finds

EN 18031 names mechanisms. Conformity is carried by the controls behind them, decided per assessment unit rather than once for the product. A control is only evidence when it is reproducible: each control needs a named implementation in the declared configuration, an artefact showing it works, and a production step that reproduces it on every unit. A control shown on an engineering sample but not enforced in manufacturing does not support the declaration.

Four gates decide whether you can sign this yourself

Annex II internal production control lets the manufacturer declare conformity alone, and Article 17(4) allows it only where the cited standards are applied in full. Every gate must pass for each applicable requirement. One failure sends that requirement to Annex III or Annex IV.

GateThe questionIf no
1. ScopeIs the requirement in scope? Decide 3(3)(d), (e) and (f) separately from product facts: internet reachability, personal data, and money or virtual-currency transfer.Out of scope, with the functions examined recorded.
2. CoverageDoes a cited standard cover it? Check the product type and its interfaces fall inside the relevant part.No presumption. Annex III or IV.
3. Full applicationIs the standard applied in full? Every applicable mechanism assessed by the standard's method, every assessment unit given a verdict, every not-applicable decision justified.Partial application. Annex III or IV.
4. RestrictionsDo the Official Journal restrictions leave presumption intact for the implementation actually chosen?Presumption lost. Notified Body.

The four Official Journal restrictions

  • The password option, all three parts. Presumption is lost where clauses 6.2.5.1 and 6.2.5.2 are applied so the user may set no password at all. Commission guidance is that no third-party assessment is required if the manufacturer disregards that option, so requiring a credential on every interface keeps Annex II open. This is the most common self-inflicted trigger.
  • Secure update, EN 18031-3 clause 6.3.2.4. Presumption is removed for those assessment criteria, and Commission guidance states third-party conformity assessment is mandatory where the clause applies. If the product transfers monetary value, settle this before planning a self-declared release.
  • Parental control, EN 18031-2. Presumption is lost for the specified toy and childcare clauses where parental or guardian access control is not ensured. Establish first whether the product is inside those clauses at all.
  • Rationale and guidance sections. Those sections set no specifications and confer no presumption, so conclusions must be tied to the normative requirements. No third-party assessment follows from this restriction alone.

If a Notified Body is required, only the failing requirement goes to Annex III or IV. The rest can still run under Annex II. The body must be notified for that specific requirement, its certificate must match the declared configuration, and the Declaration of Conformity must name the procedure actually used.

Six questions to ask first

More than two answers of no means the file does not yet support the declaration.

BoundaryAre the hardware revisions, firmware versions, applications, and backend services in the declared configuration identified?
ApplicabilityDoes each 3(3)(d), (e) and (f) conclusion rest on stated product facts and an evidence reference?
RestrictionsIs the password option addressed on every interface, and clause 6.3.2.4 checked if Part 3 applies?
ControlsDoes every applicable control have a named implementation, an artefact proving it works, and a verdict?
ProductionDo provisioning, credential generation, key injection, and hardening reproduce the assessed configuration on every unit?
DeclarationDoes the DoC name the cybersecurity requirements, the standards applied, and the procedure actually used?

Summary and interpretation only, not a conformity assessment or legal advice. The manufacturer retains responsibility for the conformity assessment, the technical documentation, and the EU Declaration of Conformity.

THE RED CYBERSECURITY READINESS ASSESSMENT

Work through scope, restrictions, and evidence for one product and get a structured result: which of Article 3(3)(d), (e) and (f) apply, whether the four gates pass, and which controls have no evidence behind them yet. One product, about twenty minutes.

Run the assessment

Built for regulated industries

ISO 9001ISO 13485ISO 27001EU MDR / IVDRGDPRFDA