Skip to content
Zyberum Cyber Security Firm
Menu
IoTCompliance

RED Cybersecurity and EN 18031: What Wireless Devices Need

Since 1 August 2025 radio equipment sold in the EU must meet the RED cybersecurity requirements. What EN 18031 demands and how it relates to the CRA.

Zyberum Security Team · Published · 6 min read

If your product has Wi-Fi, Bluetooth, cellular or any other radio and can reach the internet, a new set of rules has applied to it since 1 August 2025: the cybersecurity requirements of the Radio Equipment Directive (RED). Without them, no CE mark.

What changed

The RED (2014/53/EU) always contained three optional requirements in Article 3(3). Delegated Regulation (EU) 2022/30 switched them on:

  • Article 3(3)(d): the device must not harm the network or misuse its resources.
  • Article 3(3)(e): the device must protect personal data and privacy.
  • Article 3(3)(f): the device must protect against fraud.

Point (d) applies to internet-connected radio equipment in general. Point (e) also applies to toys, childcare products and wearables. Point (f) applies to devices that let users transfer money or virtual currency.

The standard: EN 18031

The harmonised standards follow the three requirements:

Standard Covers Requirement
EN 18031-1 Internet-connected radio equipment Network protection, Art. 3(3)(d)
EN 18031-2 Equipment processing personal data Privacy, Art. 3(3)(e)
EN 18031-3 Equipment processing virtual money or monetary value Fraud protection, Art. 3(3)(f)

They are built around security mechanisms that you either implement or justify as not applicable:

  • Access control and authentication
  • Secure update
  • Secure storage
  • Secure communication
  • Resilience against denial of service
  • Management of cryptographic keys, and up-to-date cryptography
  • No known exploitable vulnerabilities, no unnecessary interfaces and services

The catch: restrictions

The standards were published in the Official Journal in January 2025 with restrictions. In a few cases, applying the standard does not give you presumption of conformity. The best known one: if your device lets the user skip setting a password, you cannot self-declare on that basis. Similar limits exist for parental access controls in toys and for some update mechanisms in part 3.

If a restriction hits your product, you need a notified body. It pays to check this early.

What this means in engineering terms

Most teams we work with stumble over the same points:

  1. Default passwords. One shared default password across all devices is no longer acceptable. Use unique per-device credentials or force a change at setup.
  2. Updates. You need a secure update mechanism: signed images, verified before installation, with protection against rollback.
  3. Open interfaces. Debug ports, test services and unused network services must be closed or protected in the shipped product.
  4. Stored secrets. Keys and credentials must be protected on the device, not sitting in plain flash.
  5. Known vulnerabilities. You have to know which components you ship, and that they do not contain known exploitable vulnerabilities.

RED today, CRA tomorrow

The Cyber Resilience Act covers the same topics for all products with digital elements and applies in full from 11 December 2027. Work you do now for EN 18031 is not wasted: secure updates, access control and vulnerability handling are core CRA requirements too.

The practical route: test the device against EN 18031 now, fix what comes up, and build the process side (SBOM, vulnerability handling, support period) with the CRA in mind.

We test devices against these requirements and help close the gaps. See IoT security or CRA compliance.

FAQ

Frequently asked questions

Which devices fall under the RED cybersecurity requirements?

Radio equipment that can communicate over the internet, directly or through another device. In addition, toys, childcare products and wearables with radio functions must protect personal data, and devices that handle money transfers must protect against fraud.

Can I self-declare conformity with EN 18031?

Yes, if you apply the harmonised standards in full and none of the published restrictions apply to your product. If a restriction applies, for example because users can choose not to set a password, you need a notified body.

Does the CRA replace the RED cybersecurity requirements?

Yes, eventually. The Cyber Resilience Act covers the same ground more broadly and applies in full from 11 December 2027. Until then the RED requirements remain mandatory for radio equipment.

Call usBook a call

Pick a time that suits you

Open in a new tab