Search

The EN 18031 standard has officially come into effect! Such products must be certified by the EU for cybersecurity?

The European Commission passed the Supplementary Authorization Act (EU) 2022/30 in 2022, which clearly requires radio equipment to meet network security, privacy protection and anti-fraud requirements.


New Regulation Timeline

• August 2024: Release supporting standards EN 18031 to refine the cybersecurity clauses in the RED Directive;

• January 30, 2025: EN 18031 is officially included in the RED Directive Coordination Standard List (EU Official Bulletin OJ);

• From August 1, 2025: All radio equipment exported to the EU must comply with the cybersecurity requirements of Article 3(3)(d)(e)(f) of the RED Directive, otherwise it is prohibited to enter the market.


Core content

Regulatory upgrades: From bills to standards, form a complete compliance framework;

Time node: August 2025 is the mandatory execution deadline;

Access conditions: Meet three core requirements: network security (anti-attack), privacy protection (data encryption), and anti-fraud (dual-factor verification).


eu certification


Analysis of core standards: accurate benchmarking of three major clauses


The EN 18031 series standards are divided into three parts, which directly correspond to the three key requirements of Article 3(3) of the RED Directive:


f593ff716a14a7b9ad21d056dd11aff6.png


Full list of scope of application (with exemptions)


eu type examination


1. EN 18031-1 (networking function safety requirements)


For Internet-connected radio equipment, the main evaluation of the security of network assets is to resist network attacks, prevent network resource abuse and service interruption.

Applicable products:


• Mobile phones, tablets;

• Wi-Fi routers, gateways, connected air conditioners, refrigerators and other household appliances;

• Smart TV/TV box and 3G/4G/5G equipment;

• All devices with Wi-Fi communication capabilities;

• Vehicle networking components; power converter in energy systems.


2. EN 18031-2 (Data Security Requirements)


For radio equipment that processes personal data, focus on privacy protection, and equipment requires access control, data encryption and privacy protection mechanisms.

Applicable products:


• Bluetooth devices (TWS headphones, audio), wearable devices (smart watches)

• Baby monitor, smart sensor, on-board GPS

• Air purifiers, vacuum cleaners and other household equipment


3. EN 18031-3 (Financial Functional Security Requirements)


For devices that handle virtual currency or currency value, it is required to have functions to prevent fraud, such as logging, software integrity verification, etc.

Applicable products:


• POS machine, ATM machine

• Any device that supports virtual currency or transfer functions


⚠Exemption scope:

• Medical devices: governed by MDR regulations

• Aviation Equipment: Applicable to Regulation (EU) 2018/1139

• Vehicle emergency system: applicable to Regulation (EU) 2019/2144

• Payment Terminal: Applicable to Directive (EU) 2019/520


eu type examination certificate


Four-step approach to emergency action by manufacturers


Step 1: Product Classification Screening

Match standard categories according to device functions:


• Networking function → EN 18031-1

• Processing personal data → EN 18031-2

• Related to financial transactions → EN 18031-3


Determine whether it is subject to the new regulations


Step 2: In-depth interpretation of technical terms


• Password Force Setting (EN 18031-1): Users must set passwords for the first time to use, and disable the default password

• Parental Control (EN 18031-2): Hardware-level implementation of guardian rights (such as physical buttons + biometrics)

• Multiple security updates (EN 18031-3): Digital signature + access control must be used at the same time (example: signature firmware + dynamic password)


Step 3: Compliance Gap Diagnosis


Key verification:


• Is the default password forced to be disabled?  

• Does data encryption meet the AES-256 standard?  

• Whether security updates adopt a two-factor verification mechanism


Step 4: Authentication path selection


1. Self-declaration: Available when fully complying with the coordination standards (technical documents need to be kept for 10 years)


2. NB organization certification is mandatory if the following situations exist:


• Allow users to skip password settings

• Adopt autonomous access control mode

• Use only a single security update method  





HUAK: Your Reliable Partner for Global Product Testing & Certification
Latest News & Blog about HUAK
How to Ensure Your Product Is WPC-Compliant Before Entering the Indian Market
20
Dec
2025
How to Ensure Your Product Is WPC-Compliant Before Entering the Indian Market
When entering the Indian market with wireless communication products, obtaining the WPC license in India is a critical step. The Wireless Planning and Coordination (WPC) Wing of India's Department...
VIEW MORE
Breaking News: UL 62368-1:2025 (4th Edition) Officially Released on July 31, 2025!
15
Sep
2025
Breaking News: UL 62368-1:2025 (4th Edition) Officially Released on July 31, 2025!
Following the releases of the international standard IEC 62368-1:2023 (4th Edition) and the European standard EN IEC 62368-1:2024 (4th Edition), the US standard UL 62368-1:2025 (4th Edition) has now b...
VIEW MORE
Australia and New Zealand update electromagnetic compatibility standards for lighting equipment
07
Aug
2025
Australia and New Zealand update electromagnetic compatibility standards for lighting equipment
AS/NZS CISPR 15:2025– Radio disturbance characteristics of electrical lighting and similar equipment – Limits and methods of measurement – is the joint Australian/New Zealand standard for electroma...
VIEW MORE
Service +
Network Information Security
Certification in EU
Certification in USA
Certification in Canada
Certification in Japan
Certification in China
Certification in Australia
Certification in India
Global Certifications
1-2/F., Building B2, Junfeng Zhongcheng Zhizao Innovation Park, Heping Community, Fuhai Street, Bao'an District, Shenzhen, Guangdong, China
patty@cer-mark.com
+86 13528437881
We use cookies on this site, including third party cookies, to deliver experience for you.
Accept Cookies
Read Privacy Policy