# EN 18031

> EN 18031 is a series of three European standards (EN 18031-1, -2, -3) that specify how radio equipment meets the cybersecurity requirements of the Radio Equipment Directive, Article 3(3)(d), (e) and (f): network protection, protection of personal data and privacy, and protection against fraud. Applying them gives presumption of conformity since the Commission listed them in the Official Journal in January 2025, with restrictions on some options. The RED requirements apply to radio equipment placed on the market since 1 August 2025.

EN 18031 is the harmonised standard series for the Radio Equipment Directive cybersecurity requirements (Art. 3(3)(d), (e), (f)). Parts, mechanisms and assessment.

Source: https://zyberum.com/glossary/en-18031 · Updated: 2026-10-07

## What is EN 18031?

EN 18031 is the set of harmonised European standards for the cybersecurity requirements of the Radio Equipment Directive (RED). It has three parts that mirror the three legal requirements: EN 18031-1 for Article 3(3)(d), the network must not be harmed (internet-connected radio equipment); EN 18031-2 for Article 3(3)(e), protection of personal data and privacy (equipment that processes personal data, plus toys, childcare and wearable equipment); EN 18031-3 for Article 3(3)(f), protection against fraud (equipment handling money or virtual currency). Any Wi-Fi, Bluetooth, LTE or Zigbee device sold in the EU is radio equipment, so this covers most IoT products.

The standards describe security "mechanisms" and, for each, requirements, assessment criteria and decision trees. The mechanisms in part 1 include access control (ACM), authentication (AUM), secure updates (SUM), secure storage (SSM), secure communication (SCM), resilience (RLM), network monitoring (NMM), traffic control (TCM), confidential cryptographic keys (CCK), general equipment capabilities (GEC) and cryptography (CRY). Part 2 adds logging (LGM), deletion (DLM) and user notification (UNM).

## Where is it defined?

Three legal acts and the standards themselves. The Radio Equipment Directive 2014/53/EU contains the requirements in Article 3(3). Commission Delegated Regulation (EU) 2022/30 activated points (d), (e) and (f), applicable to equipment placed on the market from 1 August 2025. Commission Implementing Decision (EU) 2025/138 of 28 January 2025 listed EN 18031-1, -2 and -3 (2024 editions) in the Official Journal, which grants presumption of conformity, with restrictions: the presumption does not apply, for instance, where the manufacturer lets the user operate the equipment without setting a password, and there are further exclusions for some requirements in parts 2 and 3. The standards were written by CENELEC and are sold by the national standards bodies.

## What it means in practice

EN 18031 is the first harmonised standard that forces a security assessment onto every connected consumer device, and it is the rehearsal for the Cyber Resilience Act. What we see when assessing IoT products against it:

- **The decision trees are the method.** Each requirement starts with applicability questions. A device without a user interface may answer "not applicable" to parts of AUM; a device with a web interface may not. Documenting the reasoning is half the work.
- **Default passwords end here.** The restriction in the implementing decision means a device with a shared or empty default password cannot claim presumption of conformity. Per-device credentials or a forced setup step are the common fixes.
- **Secure update (SUM) is the usual gap.** Updates must be authenticated and integrity-protected, which means signed firmware and a boot chain that checks the signature. Where secure boot is missing, the update mechanism alone will not pass.
- **Conceptual and functional assessment both count.** The standard asks whether the design is sufficient and whether the implementation actually works. Testing the device, not just reading the design, is required for the second part.

Zyberum assesses products against EN 18031, writes the technical documentation and tests the mechanisms. The declaration of conformity is yours as the manufacturer; where the restrictions apply, a notified body has to be involved, and we are not one.

## Common misunderstandings

EN 18031 is not the CRA, but the two overlap heavily: the CRA's Annex I requirements cover the same ground and more, and the CRA is designed to take over this role once it applies in full. Work done for EN 18031 is not lost. And a RED test report from a lab is not a certificate: the RED knows CE marking and declarations of conformity, not security certificates.

## FAQ

**Which products need EN 18031?**

Radio equipment that can communicate over the internet falls under Article 3(3)(d) and therefore EN 18031-1. If it processes personal data, or is a toy, childcare or wearable device, Article 3(3)(e) and EN 18031-2 apply too. Equipment that handles money or virtual currency adds Article 3(3)(f) and EN 18031-3. A Wi-Fi smart plug typically needs parts 1 and 2.

**Can I self-declare conformity with EN 18031?**

Yes, where you apply the standards in full and none of the restrictions in Implementing Decision (EU) 2025/138 applies to your product. Where a restriction applies, for example because the user is allowed to operate the device without a password, you cannot rely on the presumption and need a notified body for that requirement.

**How does EN 18031 relate to the Cyber Resilience Act?**

The two overlap heavily. EN 18031 covers the RED cybersecurity requirements for radio equipment now; the CRA covers all products with digital elements from 11 December 2027 with broader requirements. Design decisions, documentation and tests done for EN 18031 carry over to the CRA, which is designed to take over this role once it applies in full.

## Sources

- [Commission Implementing Decision (EU) 2025/138 (harmonised standards EN 18031-1, -2, -3)](https://eur-lex.europa.eu/eli/dec_impl/2025/138/oj)
- [Commission Delegated Regulation (EU) 2022/30 (activation of Article 3(3)(d), (e), (f) RED)](https://eur-lex.europa.eu/eli/reg_del/2022/30/oj)
- [Directive 2014/53/EU (Radio Equipment Directive), Article 3(3)](https://eur-lex.europa.eu/eli/dir/2014/53/oj)

## Related

- [Cyber Resilience Act (CRA)](https://zyberum.com/glossary/cyber-resilience-act)
- [BLE Security](https://zyberum.com/glossary/ble-security)
- [RED Cybersecurity and EN 18031: What Wireless Devices Need](https://zyberum.com/insights/red-en-18031-cybersecurity)
- [Cybersecurity for IoT Device Makers: RED EN 18031, CRA and Device Tests](https://zyberum.com/for/iot-device-makers)
- [Connected products that stay secure for their whole lifetime.](https://zyberum.com/iot-security)
- [Make your products CRA-compliant, without slowing development.](https://zyberum.com/cyber-resilience-act)

---
Zyberum GmbH. Canonical page: https://zyberum.com/glossary/en-18031
