Search

The EN 18031 standard has officially come into effect! Such products must be certified by the EU for cybersecurity?

The European Commission passed the Supplementary Authorization Act (EU) 2022/30 in 2022, which clearly requires radio equipment to meet network security, privacy protection and anti-fraud requirements.


New Regulation Timeline

• August 2024: Release supporting standards EN 18031 to refine the cybersecurity clauses in the RED Directive;

• January 30, 2025: EN 18031 is officially included in the RED Directive Coordination Standard List (EU Official Bulletin OJ);

• From August 1, 2025: All radio equipment exported to the EU must comply with the cybersecurity requirements of Article 3(3)(d)(e)(f) of the RED Directive, otherwise it is prohibited to enter the market.


Core content

Regulatory upgrades: From bills to standards, form a complete compliance framework;

Time node: August 2025 is the mandatory execution deadline;

Access conditions: Meet three core requirements: network security (anti-attack), privacy protection (data encryption), and anti-fraud (dual-factor verification).


eu certification


Analysis of core standards: accurate benchmarking of three major clauses


The EN 18031 series standards are divided into three parts, which directly correspond to the three key requirements of Article 3(3) of the RED Directive:


f593ff716a14a7b9ad21d056dd11aff6.png


Full list of scope of application (with exemptions)


eu type examination


1. EN 18031-1 (networking function safety requirements)


For Internet-connected radio equipment, the main evaluation of the security of network assets is to resist network attacks, prevent network resource abuse and service interruption.

Applicable products:


• Mobile phones, tablets;

• Wi-Fi routers, gateways, connected air conditioners, refrigerators and other household appliances;

• Smart TV/TV box and 3G/4G/5G equipment;

• All devices with Wi-Fi communication capabilities;

• Vehicle networking components; power converter in energy systems.


2. EN 18031-2 (Data Security Requirements)


For radio equipment that processes personal data, focus on privacy protection, and equipment requires access control, data encryption and privacy protection mechanisms.

Applicable products:


• Bluetooth devices (TWS headphones, audio), wearable devices (smart watches)

• Baby monitor, smart sensor, on-board GPS

• Air purifiers, vacuum cleaners and other household equipment


3. EN 18031-3 (Financial Functional Security Requirements)


For devices that handle virtual currency or currency value, it is required to have functions to prevent fraud, such as logging, software integrity verification, etc.

Applicable products:


• POS machine, ATM machine

• Any device that supports virtual currency or transfer functions


⚠Exemption scope:

• Medical devices: governed by MDR regulations

• Aviation Equipment: Applicable to Regulation (EU) 2018/1139

• Vehicle emergency system: applicable to Regulation (EU) 2019/2144

• Payment Terminal: Applicable to Directive (EU) 2019/520


eu type examination certificate


Four-step approach to emergency action by manufacturers


Step 1: Product Classification Screening

Match standard categories according to device functions:


• Networking function → EN 18031-1

• Processing personal data → EN 18031-2

• Related to financial transactions → EN 18031-3


Determine whether it is subject to the new regulations


Step 2: In-depth interpretation of technical terms


• Password Force Setting (EN 18031-1): Users must set passwords for the first time to use, and disable the default password

• Parental Control (EN 18031-2): Hardware-level implementation of guardian rights (such as physical buttons + biometrics)

• Multiple security updates (EN 18031-3): Digital signature + access control must be used at the same time (example: signature firmware + dynamic password)


Step 3: Compliance Gap Diagnosis


Key verification:


• Is the default password forced to be disabled?  

• Does data encryption meet the AES-256 standard?  

• Whether security updates adopt a two-factor verification mechanism


Step 4: Authentication path selection


1. Self-declaration: Available when fully complying with the coordination standards (technical documents need to be kept for 10 years)


2. NB organization certification is mandatory if the following situations exist:


• Allow users to skip password settings

• Adopt autonomous access control mode

• Use only a single security update method  





HUAK: Your Reliable Partner for Global Product Testing & Certification
Latest News & Blog about HUAK
Product Safety Test: Ensuring Global Compliance and Consumer Trust
08
Oct
2025
Product Safety Test: Ensuring Global Compliance and Consumer Trust
In today's highly regulated markets, a product safety test is more than a regulatory requirement—it is a cornerstone of consumer trust, brand reputation, and global market access. Companies manuf...
VIEW MORE
Breaking News: UL 62368-1:2025 (4th Edition) Officially Released on July 31, 2025!
15
Sep
2025
Breaking News: UL 62368-1:2025 (4th Edition) Officially Released on July 31, 2025!
Following the releases of the international standard IEC 62368-1:2023 (4th Edition) and the European standard EN IEC 62368-1:2024 (4th Edition), the US standard UL 62368-1:2025 (4th Edition) has now b...
VIEW MORE
The EU is seeking public comment on cobalt restrictions in the Toy Safety Directive
30
Sep
2025
The EU is seeking public comment on cobalt restrictions in the Toy Safety Directive
The European Commission is seeking public comment on a draft revision to Annex A of Annex II to the Toy Safety Directive (2009/48/EC). The focus of the revision is on cobalt, which is classified as a ...
VIEW MORE
Certification Service +
Certification in EU
Certification in USA
Certification in Canada
Certification in Japan
Certification in China
Certification in Australia
Certification in India
Global Certifications
1-2/F., Building B2, Junfeng Zhongcheng Zhizao Innovation Park, Heping Community, Fuhai Street, Bao'an District, Shenzhen, Guangdong, China
patty@cer-mark.com
+86 13528437881
We use cookies on this site, including third party cookies, to deliver experience for you.
Accept Cookies
Read Privacy Policy