Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryIoTCompliance

EN 18031

EN 18031 is the harmonised standard series for the Radio Equipment Directive cybersecurity requirements (Art. 3(3)(d), (e), (f)). Parts, mechanisms and assessment.

Updated This page as Markdown

In short

EN 18031 is a series of three European standards (EN 18031-1, -2, -3) that specify how radio equipment meets the cybersecurity requirements of the Radio Equipment Directive, Article 3(3)(d), (e) and (f): network protection, protection of personal data and privacy, and protection against fraud. Applying them gives presumption of conformity since the Commission listed them in the Official Journal in January 2025, with restrictions on some options. The RED requirements apply to radio equipment placed on the market since 1 August 2025.

What is EN 18031?

EN 18031 is the set of harmonised European standards for the cybersecurity requirements of the Radio Equipment Directive (RED). It has three parts that mirror the three legal requirements: EN 18031-1 for Article 3(3)(d), the network must not be harmed (internet-connected radio equipment); EN 18031-2 for Article 3(3)(e), protection of personal data and privacy (equipment that processes personal data, plus toys, childcare and wearable equipment); EN 18031-3 for Article 3(3)(f), protection against fraud (equipment handling money or virtual currency). Any Wi-Fi, Bluetooth, LTE or Zigbee device sold in the EU is radio equipment, so this covers most IoT products.

The standards describe security “mechanisms” and, for each, requirements, assessment criteria and decision trees. The mechanisms in part 1 include access control (ACM), authentication (AUM), secure updates (SUM), secure storage (SSM), secure communication (SCM), resilience (RLM), network monitoring (NMM), traffic control (TCM), confidential cryptographic keys (CCK), general equipment capabilities (GEC) and cryptography (CRY). Part 2 adds logging (LGM), deletion (DLM) and user notification (UNM).

Where is it defined?

Three legal acts and the standards themselves. The Radio Equipment Directive 2014/53/EU contains the requirements in Article 3(3). Commission Delegated Regulation (EU) 2022/30 activated points (d), (e) and (f), applicable to equipment placed on the market from 1 August 2025. Commission Implementing Decision (EU) 2025/138 of 28 January 2025 listed EN 18031-1, -2 and -3 (2024 editions) in the Official Journal, which grants presumption of conformity, with restrictions: the presumption does not apply, for instance, where the manufacturer lets the user operate the equipment without setting a password, and there are further exclusions for some requirements in parts 2 and 3. The standards were written by CENELEC and are sold by the national standards bodies.

What it means in practice

EN 18031 is the first harmonised standard that forces a security assessment onto every connected consumer device, and it is the rehearsal for the Cyber Resilience Act. What we see when assessing IoT products against it:

  • The decision trees are the method. Each requirement starts with applicability questions. A device without a user interface may answer “not applicable” to parts of AUM; a device with a web interface may not. Documenting the reasoning is half the work.
  • Default passwords end here. The restriction in the implementing decision means a device with a shared or empty default password cannot claim presumption of conformity. Per-device credentials or a forced setup step are the common fixes.
  • Secure update (SUM) is the usual gap. Updates must be authenticated and integrity-protected, which means signed firmware and a boot chain that checks the signature. Where secure boot is missing, the update mechanism alone will not pass.
  • Conceptual and functional assessment both count. The standard asks whether the design is sufficient and whether the implementation actually works. Testing the device, not just reading the design, is required for the second part.

Zyberum assesses products against EN 18031, writes the technical documentation and tests the mechanisms. The declaration of conformity is yours as the manufacturer; where the restrictions apply, a notified body has to be involved, and we are not one.

Common misunderstandings

EN 18031 is not the CRA, but the two overlap heavily: the CRA’s Annex I requirements cover the same ground and more, and the CRA is designed to take over this role once it applies in full. Work done for EN 18031 is not lost. And a RED test report from a lab is not a certificate: the RED knows CE marking and declarations of conformity, not security certificates.

FAQ

Frequently asked questions

Which products need EN 18031?

Radio equipment that can communicate over the internet falls under Article 3(3)(d) and therefore EN 18031-1. If it processes personal data, or is a toy, childcare or wearable device, Article 3(3)(e) and EN 18031-2 apply too. Equipment that handles money or virtual currency adds Article 3(3)(f) and EN 18031-3. A Wi-Fi smart plug typically needs parts 1 and 2.

Can I self-declare conformity with EN 18031?

Yes, where you apply the standards in full and none of the restrictions in Implementing Decision (EU) 2025/138 applies to your product. Where a restriction applies, for example because the user is allowed to operate the device without a password, you cannot rely on the presumption and need a notified body for that requirement.

How does EN 18031 relate to the Cyber Resilience Act?

The two overlap heavily. EN 18031 covers the RED cybersecurity requirements for radio equipment now; the CRA covers all products with digital elements from 11 December 2027 with broader requirements. Design decisions, documentation and tests done for EN 18031 carry over to the CRA, which is designed to take over this role once it applies in full.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab