Search

The EN 18031 standard has officially come into effect! Such products must be certified by the EU for cybersecurity?

The European Commission passed the Supplementary Authorization Act (EU) 2022/30 in 2022, which clearly requires radio equipment to meet network security, privacy protection and anti-fraud requirements.


New Regulation Timeline

• August 2024: Release supporting standards EN 18031 to refine the cybersecurity clauses in the RED Directive;

• January 30, 2025: EN 18031 is officially included in the RED Directive Coordination Standard List (EU Official Bulletin OJ);

• From August 1, 2025: All radio equipment exported to the EU must comply with the cybersecurity requirements of Article 3(3)(d)(e)(f) of the RED Directive, otherwise it is prohibited to enter the market.


Core content

Regulatory upgrades: From bills to standards, form a complete compliance framework;

Time node: August 2025 is the mandatory execution deadline;

Access conditions: Meet three core requirements: network security (anti-attack), privacy protection (data encryption), and anti-fraud (dual-factor verification).


eu certification


Analysis of core standards: accurate benchmarking of three major clauses


The EN 18031 series standards are divided into three parts, which directly correspond to the three key requirements of Article 3(3) of the RED Directive:


f593ff716a14a7b9ad21d056dd11aff6.png


Full list of scope of application (with exemptions)


eu type examination


1. EN 18031-1 (networking function safety requirements)


For Internet-connected radio equipment, the main evaluation of the security of network assets is to resist network attacks, prevent network resource abuse and service interruption.

Applicable products:


• Mobile phones, tablets;

• Wi-Fi routers, gateways, connected air conditioners, refrigerators and other household appliances;

• Smart TV/TV box and 3G/4G/5G equipment;

• All devices with Wi-Fi communication capabilities;

• Vehicle networking components; power converter in energy systems.


2. EN 18031-2 (Data Security Requirements)


For radio equipment that processes personal data, focus on privacy protection, and equipment requires access control, data encryption and privacy protection mechanisms.

Applicable products:


• Bluetooth devices (TWS headphones, audio), wearable devices (smart watches)

• Baby monitor, smart sensor, on-board GPS

• Air purifiers, vacuum cleaners and other household equipment


3. EN 18031-3 (Financial Functional Security Requirements)


For devices that handle virtual currency or currency value, it is required to have functions to prevent fraud, such as logging, software integrity verification, etc.

Applicable products:


• POS machine, ATM machine

• Any device that supports virtual currency or transfer functions


⚠Exemption scope:

• Medical devices: governed by MDR regulations

• Aviation Equipment: Applicable to Regulation (EU) 2018/1139

• Vehicle emergency system: applicable to Regulation (EU) 2019/2144

• Payment Terminal: Applicable to Directive (EU) 2019/520


eu type examination certificate


Four-step approach to emergency action by manufacturers


Step 1: Product Classification Screening

Match standard categories according to device functions:


• Networking function → EN 18031-1

• Processing personal data → EN 18031-2

• Related to financial transactions → EN 18031-3


Determine whether it is subject to the new regulations


Step 2: In-depth interpretation of technical terms


• Password Force Setting (EN 18031-1): Users must set passwords for the first time to use, and disable the default password

• Parental Control (EN 18031-2): Hardware-level implementation of guardian rights (such as physical buttons + biometrics)

• Multiple security updates (EN 18031-3): Digital signature + access control must be used at the same time (example: signature firmware + dynamic password)


Step 3: Compliance Gap Diagnosis


Key verification:


• Is the default password forced to be disabled?  

• Does data encryption meet the AES-256 standard?  

• Whether security updates adopt a two-factor verification mechanism


Step 4: Authentication path selection


1. Self-declaration: Available when fully complying with the coordination standards (technical documents need to be kept for 10 years)


2. NB organization certification is mandatory if the following situations exist:


• Allow users to skip password settings

• Adopt autonomous access control mode

• Use only a single security update method  





HUAK: Your Reliable Partner for Global Product Testing & Certification
Latest News & Blog about HUAK
How WEEE Testing Protects the Environment and Promotes Sustainable Electronics Recycling
09
Jan
2026
How WEEE Testing Protects the Environment and Promotes Sustainable Electronics Recycling
In today's world, the growing amount of electronic waste, or e-waste, presents significant environmental challenges. As the production and consumption of electronic products continue to rise, the ...
VIEW MORE
Product Testing vs. Quality Assurance Roles
18
Oct
2025
Product Testing vs. Quality Assurance Roles
In today's competitive market, ensuring that products meet safety, functionality, and regulation standards is crucial. This is where product testing services and quality assurance (QA) come into p...
VIEW MORE
EN71 Certification: A Strong Shield for Protecting Children's Safety
28
Sep
2025
EN71 Certification: A Strong Shield for Protecting Children's Safety
The safety of children's toys is a concern that transcends borders, and regulatory standards play a vital role in ensuring that products meet stringent requirements before reaching the hands of yo...
VIEW MORE
Service +
Network Information Security
Certification in EU
Certification in USA
Certification in Canada
Certification in Japan
Certification in China
Certification in Australia
Certification in India
Global Certifications
1-2/F., Building B2, Junfeng Zhongcheng Zhizao Innovation Park, Heping Community, Fuhai Street, Bao'an District, Shenzhen, Guangdong, China
patty@cer-mark.com
+86 13528437881
We use cookies on this site, including third party cookies, to deliver experience for you.
Accept Cookies
Read Privacy Policy