EMC China Lab

EU RED Directive and EN 18031 Cybersecurity Standards

Views :
Update time : 2025-02-26

On January 30, 2025, the Official Journal of the European Union (OJ) officially incorporated the en 18031 series of standards as harmonized standards under the Radio Equipment Directive (RED). This means that starting August 1, 2025, all wireless devices sold in the EU market must comply with this mandatory cybersecurity regULation. Non-compliant products will face market access restrictions, urging manufacturers to accelerate their compliance strategies.

 

Cybersecurity Background of EN 18031 and the red directive

The EU Radio Equipment Directive (RED) requires that all wireless devices sold in the EU meet essential requirements related to:

 

- Safety

- Electromagnetic compatibility

- Efficient use of the radio spectrum

 

Since 2022, the European Commission has introduced additional cybersecurity requirements under Article 3(3) of the directive, including:

 

- Article 3.3(d) – Cybersecurity (Standard: EN 18031-1)

- Article 3.3(e) – Personal Privacy (Standard: EN 18031-2)

- Article 3.3(f) – Fraud Prevention (Standard: EN 18031-3)

 

The EN 18031 series establishes a unified cybersecurity standard to help manufacturers ensure compliance with these new regulations.

 

Scope of Covered Products

The Delegated Regulation 2022/30/EU applies to wireless devices that:

 

- Communicate directly via the internet or indirectly through other devices

- Process and expose sensitive personal data

 

Examples of affected products include:

 

- Smartphones, tablets, and laptops

- Wireless toys and child safety devices, such as baby monitors

- Wearable devices, including smartwatches and fitness trackers

 

Key Assessment Areas of EN 18031

EN 18031-1 (Cybersecurity)

This standard assesses security mechanisms in devices, covering:

 

- Access control and authentication

- Secure updates and storage

- Secure communication protocols

- Confidentiality of cryptographic keys

- General security capabilities

- Cryptographic best practices

- Resilience mechanisms

- Network monitoring and traffic control

 

EN 18031-2 (Personal Privacy)

This standard focuses on privacy protection and includes:

 

- Access control for children's toys

- Logging and record-keeping mechanisms

- Data deletion protocols

- User notification requirements

- External sensing documentation

 

EN 18031-3 (Fraud Prevention)

This standard evaluates financial and fraud-related security aspects, including:

 

- Logging mechanisms

- Device boot integrity and software authenticity

 

Key Differences Between EN 18031 and ETSI EN 303 645

While EN 18031 shares many similarities with ETSI EN 303 645, it imposes stricter requirements on tested devices. However, EN 18031 also provides more flexibility by including “not applicable” conditions for certain requirements.

 

Overall, products that already comply with ETSI EN 303 645 will have a significant advantage in meeting EN 18031 compliance requirements.

 

Recommendations for Manufacturers

Since the RED cybersecurity requirements will become mandatory on August 1, 2025, all new and existing products sold in the EU must comply. Manufacturers should take immediate action to ensure compliance.

 

Key steps for compliance:

1. Review RED applicability

- Determine if your product falls within the scope of RED’s cybersecurity requirements. JJR Lab (China) can assist in this assessment.

 

2. Understand en 18031 standards

- Analyze the specific requirements and limitations of the EN 18031 series and assess their impact on your products.

 

3. Conduct a compliance gap analysis

- Evaluate your current cybersecurity measures against EN 18031 to identify necessary improvements.

 

4. Consult with experts

- Since EN 18031 is a new standard, manufacturers should seek professional guidance from GTG to ensure full compliance.

 

5. Prepare for market entry

- Implement necessary design, testing, and documentation changes to comply with the August 1, 2025 deadline.

- Obtaining a RED Notified Body compliance certificate will help verify product conformity.

 

This version keeps the translation structured, clear, and professional while improving readability. Let me know if you need any refinements!


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
What is ASTM D3359 Compliance Testing What is ASTM D3359 Compliance Testing
03 .27.2026
ASTM D3359 defines a tape test to assess coating adhesion by cross-cutting and peeling, rating resis...
What is 16 CFR 1243 Certification Testing What is 16 CFR 1243 Certification Testing
03 .27.2026
16 CFR 1243 mandates safety testing for infant cushions—covering structure, chemicals, labeling, and...
U.S. CPSC Requirements for Infant Loungers Under 1 U.S. CPSC Requirements for Infant Loungers Under 1
03 .27.2026
Under U.S. Consumer Product Safety Commission 16 CFR 1243, infant loungers must meet strict safety r...
Amazon 16 CFR Part 1210 Compliance Services Amazon 16 CFR Part 1210 Compliance Services
03 .27.2026
US lighter safety law 16 CFR Part 1210 mandates child-resistant, durable design, GCC certification, ...
What is 16 CFR Part 1210 Certification Testing What is 16 CFR Part 1210 Certification Testing
03 .27.2026
16 CFR Part 1210 ensures child-resistant lighter safety under CPSC rules, requiring durability and r...
What Are ASTM F1169 & 16 CFR Part 1213? What Are ASTM F1169 & 16 CFR Part 1213?
03 .26.2026
Crib safety hinges on ASTM F1169 and 16 CFR Part 1213, ensuring structure, material safety, and dura...
How to get the 16 CFR 1270 Test Report? How to get the 16 CFR 1270 Test Report?
03 .26.2026
16 CFR 1270 mandates ASTM F3186-17 tests (gap 4.5", 300 lb strength, anti-pinch) for adult bed...
What is 16 CFR Part 1270 Compliance Testing? What is 16 CFR Part 1270 Compliance Testing?
03 .26.2026
16 CFR Part 1270 compliance ensures bed rails meet ASTM F3186-24 safety; tests cover 4.5 in gaps, ...

Leave Your Message