EN 18031
EN 18031 is the harmonised standard series for the Radio Equipment Directive cybersecurity requirements (Art. 3(3)(d), (e), (f)). Parts, mechanisms and assessment.
Updated This page as Markdown
In short
EN 18031 is a series of three European standards (EN 18031-1, -2, -3) that specify how radio equipment meets the cybersecurity requirements of the Radio Equipment Directive, Article 3(3)(d), (e) and (f): network protection, protection of personal data and privacy, and protection against fraud. Applying them gives presumption of conformity since the Commission listed them in the Official Journal in January 2025, with restrictions on some options. The RED requirements apply to radio equipment placed on the market since 1 August 2025.
What is EN 18031?
EN 18031 is the set of harmonised European standards for the cybersecurity requirements of the Radio Equipment Directive (RED). It has three parts that mirror the three legal requirements: EN 18031-1 for Article 3(3)(d), the network must not be harmed (internet-connected radio equipment); EN 18031-2 for Article 3(3)(e), protection of personal data and privacy (equipment that processes personal data, plus toys, childcare and wearable equipment); EN 18031-3 for Article 3(3)(f), protection against fraud (equipment handling money or virtual currency). Any Wi-Fi, Bluetooth, LTE or Zigbee device sold in the EU is radio equipment, so this covers most IoT products.
The standards describe security “mechanisms” and, for each, requirements, assessment criteria and decision trees. The mechanisms in part 1 include access control (ACM), authentication (AUM), secure updates (SUM), secure storage (SSM), secure communication (SCM), resilience (RLM), network monitoring (NMM), traffic control (TCM), confidential cryptographic keys (CCK), general equipment capabilities (GEC) and cryptography (CRY). Part 2 adds logging (LGM), deletion (DLM) and user notification (UNM).
Where is it defined?
Three legal acts and the standards themselves. The Radio Equipment Directive 2014/53/EU contains the requirements in Article 3(3). Commission Delegated Regulation (EU) 2022/30 activated points (d), (e) and (f), applicable to equipment placed on the market from 1 August 2025. Commission Implementing Decision (EU) 2025/138 of 28 January 2025 listed EN 18031-1, -2 and -3 (2024 editions) in the Official Journal, which grants presumption of conformity, with restrictions: the presumption does not apply, for instance, where the manufacturer lets the user operate the equipment without setting a password, and there are further exclusions for some requirements in parts 2 and 3. The standards were written by CENELEC and are sold by the national standards bodies.
What it means in practice
EN 18031 is the first harmonised standard that forces a security assessment onto every connected consumer device, and it is the rehearsal for the Cyber Resilience Act. What we see when assessing IoT products against it:
- The decision trees are the method. Each requirement starts with applicability questions. A device without a user interface may answer “not applicable” to parts of AUM; a device with a web interface may not. Documenting the reasoning is half the work.
- Default passwords end here. The restriction in the implementing decision means a device with a shared or empty default password cannot claim presumption of conformity. Per-device credentials or a forced setup step are the common fixes.
- Secure update (SUM) is the usual gap. Updates must be authenticated and integrity-protected, which means signed firmware and a boot chain that checks the signature. Where secure boot is missing, the update mechanism alone will not pass.
- Conceptual and functional assessment both count. The standard asks whether the design is sufficient and whether the implementation actually works. Testing the device, not just reading the design, is required for the second part.
Zyberum assesses products against EN 18031, writes the technical documentation and tests the mechanisms. The declaration of conformity is yours as the manufacturer; where the restrictions apply, a notified body has to be involved, and we are not one.
Common misunderstandings
EN 18031 is not the CRA, but the two overlap heavily: the CRA’s Annex I requirements cover the same ground and more, and the CRA is designed to take over this role once it applies in full. Work done for EN 18031 is not lost. And a RED test report from a lab is not a certificate: the RED knows CE marking and declarations of conformity, not security certificates.
FAQ
Frequently asked questions
Which products need EN 18031?
Radio equipment that can communicate over the internet falls under Article 3(3)(d) and therefore EN 18031-1. If it processes personal data, or is a toy, childcare or wearable device, Article 3(3)(e) and EN 18031-2 apply too. Equipment that handles money or virtual currency adds Article 3(3)(f) and EN 18031-3. A Wi-Fi smart plug typically needs parts 1 and 2.
Can I self-declare conformity with EN 18031?
Yes, where you apply the standards in full and none of the restrictions in Implementing Decision (EU) 2025/138 applies to your product. Where a restriction applies, for example because the user is allowed to operate the device without a password, you cannot rely on the presumption and need a notified body for that requirement.
How does EN 18031 relate to the Cyber Resilience Act?
The two overlap heavily. EN 18031 covers the RED cybersecurity requirements for radio equipment now; the CRA covers all products with digital elements from 11 December 2027 with broader requirements. Design decisions, documentation and tests done for EN 18031 carry over to the CRA, which is designed to take over this role once it applies in full.
Sources
Related pages
- GlossaryCyber Resilience Act (CRA)The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements. Scope, duties, classes, 2026 and 2027 deadlines.
- GlossaryBLE SecurityHow Bluetooth Low Energy devices pair, encrypt and authorise access: what the Core Specification defines, which pairing modes protect and what we find in device tests.
- InsightsRED Cybersecurity and EN 18031: What Wireless Devices NeedSince 1 August 2025 radio equipment sold in the EU must meet the RED cybersecurity requirements. What EN 18031 demands and how it relates to the CRA.
- For your industryCybersecurity for IoT Device Makers: RED EN 18031, CRA and Device TestsWhat IoT device makers must do: RED with EN 18031 since August 2025, the Cyber Resilience Act from 2026, the device attack surface, typical findings and a first project.
- ServicesConnected products that stay secure for their whole lifetime.IoT penetration testing, firmware analysis and secure development for connected devices. Get your products ready for the EU Cyber Resilience Act.
- ServicesMake your products CRA-compliant, without slowing development.Get CRA-ready: gap analysis, secure development lifecycle, vulnerability handling, SBOM and penetration testing for products with digital elements.
