EMC China Lab

Explanation of EN 18031 Standard Testing Items

Views :
Update time : 2026-08-24

en 18031 certification is a mandatory standard formulated by the European Union for the cybersecurity of radio equipment. This standard is divided into three sub-standards (EN 18031-1 / -2 / -3), which correspond to the protection requirements for network assets, privacy assets, and financial assets, respectively. The following is a detailed analysis of the testing items:


General Testing Items (Applicable to all sub-standards)

  • Authentication Mechanism: Verify whether the equipment has a unique identity identifier (e.g., certificates, digital signatures). The use of default passwords is prohibited, and users are required to change the password upon their first use of the equipment.

  • Secure Update Mechanism: Check whether firmware updates are transmitted through a secure channel (e.g., encrypted communication). Ensure that the update package contains a digital signature to prevent tampering.

  • Resilience Mechanism: Evaluate the recovery capability of the equipment when subjected to cyberattacks (e.g., DDoS attacks). Verify whether the logging function is complete to support audit trail operations.


EN 18031-1: Protection of Network Assets

  • Scope of Application: Connected radio equipment (e.g., routers, smart home devices).

  • Core Testing Items:

  • Traffic Control: Restrict abnormal traffic (e.g., bandwidth abuse) to prevent the malicious occupation of network resources.

  • Network Monitoring: Real-time detection of abnormal behaviors (e.g., unauthorized access) to trigger alerts or execute blocking operations.

  • Service Interruption Protection: Ensure that critical services (e.g., emergency communication services) can still operate normally during an attack.


EN 18031-2: Protection of Privacy Assets

  • Scope of Application: Equipment that processes personal data (e.g., smartwatches, children's toys).

  • Core Testing Items:

  • Data Encryption: Implement end-to-end encrypted transmission for sensitive information (e.g., location data, health records).

  • Access Control: Children's equipment must support parental control permissions (e.g., content filtering, usage time limits).

  • Privacy Data Minimization: Only collect strictly necessary data; excessive data collection is prohibited.


EN 18031-3: Protection of Financial Assets

  • Scope of Application: Equipment involving virtual currency or payment functions (e.g., cryptocurrency wallets, payment terminals).

  • Core Testing Items:

  • Transaction Verification: Mandatory adoption of multi-factor authentication methods (e.g., biometrics + dynamic passwords).

  • Software Integrity: Verify whether the equipment firmware has anti-tampering mechanisms (e.g., hash verification).

  • Fraud Protection: Detect abnormal transaction patterns (e.g., large-amount transfers) and trigger a manual review.


Differences from Other Standards (e.g., ETSI EN 303 645)

  • Stricter Requirements: EN 18031 introduces mechanisms such as access control and logging, and these mechanisms are unconditionally mandatory.

  • Higher Flexibility: Allows certain clauses to be marked as "Not Applicable" (N/A), provided that a reasonable and valid justification is given.


Testing Process and Cycle

  • Prototype Preparation: Prototypes capable of being debugged must be provided (e.g., equipment with Root privileges).

  • Evaluation Phase:

  • Conceptual Evaluation: Document review (approximately 4–8 weeks).

  • Functional Evaluation: Laboratory testing (approximately 6–8 weeks).

  • Rectification and Retesting: If the testing is not passed, the design must be modified according to the report and the equipment must be retested.


Compliance Path Selection

  • Self-Declaration: Only applicable in cases where there are no password exemptions and children's equipment features parental control functions.

  • Third-Party Certification: High-risk equipment (e.g., financial equipment, children's toys) is strictly required to undergo third-party certification.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
Guide to the EN18031 Testing Standard Guide to the EN18031 Testing Standard
10 .08.2026
Discover the complete EN18031 testing standard for IoT devices with JJR. Learn compliance rules for ...
Amazon Lithium Battery Smart Home/3C Sellers Can N Amazon Lithium Battery Smart Home/3C Sellers Can N
10 .08.2026
Amazon bans seller-uploaded lithium battery reports. Partner with JJR Lab for authorized TIC testing...
RoHS Compliance Testing Services RoHS Compliance Testing Services
10 .06.2026
JJR Laboratory China offers RoHS compliance testing to EU 2011/65/EU, (EU) 2015/863 and IEC 62321, c...
Amazon Toy Seller Exporting to Europe Compliance Amazon Toy Seller Exporting to Europe Compliance
10 .06.2026
Ensure Amazon EU toy compliance with JJR LAB. We provide expert CE certification testing for EN 71 a...
US Jewelry Compliance Guide US Jewelry Compliance Guide
10 .06.2026
Ensure US jewelry compliance with JJR Lab. We provide expert testing for CPSC, Prop 65 & Amazon ...
FCC Certification Requirements and Costs for Consu FCC Certification Requirements and Costs for Consu
10 .05.2026
Discover FCC certification requirements, costs, and testing standards for consumer electronics. Trus...
EMC Testing Lab IEC 60601 Medical Electrical Safet EMC Testing Lab IEC 60601 Medical Electrical Safet
10 .03.2026
EMC testing for IEC 60601 medical electrical safety by China JJR Laboratory covers IEC 60601-1, IEC ...
What are the FCC Testing Requirements for Bluetoot What are the FCC Testing Requirements for Bluetoot
10 .02.2026
FCC Bluetooth device certification testing by China JJR Laboratory covers 47 CFR Part 15, ANSI C63.1...

Leave Your Message