EMC China Lab

Explanation of EN 18031 Standard Testing Items

Views :
Update time : 2026-08-24

en 18031 certification is a mandatory standard formulated by the European Union for the cybersecurity of radio equipment. This standard is divided into three sub-standards (EN 18031-1 / -2 / -3), which correspond to the protection requirements for network assets, privacy assets, and financial assets, respectively. The following is a detailed analysis of the testing items:


General Testing Items (Applicable to all sub-standards)

  • Authentication Mechanism: Verify whether the equipment has a unique identity identifier (e.g., certificates, digital signatures). The use of default passwords is prohibited, and users are required to change the password upon their first use of the equipment.

  • Secure Update Mechanism: Check whether firmware updates are transmitted through a secure channel (e.g., encrypted communication). Ensure that the update package contains a digital signature to prevent tampering.

  • Resilience Mechanism: Evaluate the recovery capability of the equipment when subjected to cyberattacks (e.g., DDoS attacks). Verify whether the logging function is complete to support audit trail operations.


EN 18031-1: Protection of Network Assets

  • Scope of Application: Connected radio equipment (e.g., routers, smart home devices).

  • Core Testing Items:

  • Traffic Control: Restrict abnormal traffic (e.g., bandwidth abuse) to prevent the malicious occupation of network resources.

  • Network Monitoring: Real-time detection of abnormal behaviors (e.g., unauthorized access) to trigger alerts or execute blocking operations.

  • Service Interruption Protection: Ensure that critical services (e.g., emergency communication services) can still operate normally during an attack.


EN 18031-2: Protection of Privacy Assets

  • Scope of Application: Equipment that processes personal data (e.g., smartwatches, children's toys).

  • Core Testing Items:

  • Data Encryption: Implement end-to-end encrypted transmission for sensitive information (e.g., location data, health records).

  • Access Control: Children's equipment must support parental control permissions (e.g., content filtering, usage time limits).

  • Privacy Data Minimization: Only collect strictly necessary data; excessive data collection is prohibited.


EN 18031-3: Protection of Financial Assets

  • Scope of Application: Equipment involving virtual currency or payment functions (e.g., cryptocurrency wallets, payment terminals).

  • Core Testing Items:

  • Transaction Verification: Mandatory adoption of multi-factor authentication methods (e.g., biometrics + dynamic passwords).

  • Software Integrity: Verify whether the equipment firmware has anti-tampering mechanisms (e.g., hash verification).

  • Fraud Protection: Detect abnormal transaction patterns (e.g., large-amount transfers) and trigger a manual review.


Differences from Other Standards (e.g., ETSI EN 303 645)

  • Stricter Requirements: EN 18031 introduces mechanisms such as access control and logging, and these mechanisms are unconditionally mandatory.

  • Higher Flexibility: Allows certain clauses to be marked as "Not Applicable" (N/A), provided that a reasonable and valid justification is given.


Testing Process and Cycle

  • Prototype Preparation: Prototypes capable of being debugged must be provided (e.g., equipment with Root privileges).

  • Evaluation Phase:

  • Conceptual Evaluation: Document review (approximately 4–8 weeks).

  • Functional Evaluation: Laboratory testing (approximately 6–8 weeks).

  • Rectification and Retesting: If the testing is not passed, the design must be modified according to the report and the equipment must be retested.


Compliance Path Selection

  • Self-Declaration: Only applicable in cases where there are no password exemptions and children's equipment features parental control functions.

  • Third-Party Certification: High-risk equipment (e.g., financial equipment, children's toys) is strictly required to undergo third-party certification.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
What is RF Testing What is RF Testing
09 .09.2026
Wondering what is RF testing? JJR Laboratory provides expert radio frequency testing services to ens...
How to get MEID Address How to get MEID Address
09 .09.2026
Discover how to obtain your 56-bit Mobile Equipment Identifier (MEID). Learn its format, importance ...
How to get a MAC Address How to get a MAC Address
09 .09.2026
Learn how to obtain a MAC address for your network devices. JJR Lab provides expert IEEE MAC applica...
How to get an IMEI Number How to get an IMEI Number
09 .09.2026
Learn how to obtain an IMEI number for mobile devices with China JJR Laboratory. Understand the 15-d...
Hearing Aid Compatibility (HAC) Testing Hearing Aid Compatibility (HAC) Testing
09 .09.2026
JJR LAB provides expert Hearing Aid Compatibility (HAC) testing for mobile phones. We ensure your de...
Prop 65 Certificate of Compliance Prop 65 Certificate of Compliance
09 .09.2026
Obtain your Prop 65 Certificate of Compliance with JJR Laboratory. We provide expert California Prop...
What is the 16 CFR 1505 Test Standard? What is the 16 CFR 1505 Test Standard?
09 .09.2026
Ensure US electric toy safety and compliance with the 16 CFR 1505 test standard. JJR LAB provides ex...
What is Toy ASTM F963-23 Testing What is Toy ASTM F963-23 Testing
09 .08.2026
Ensure Amazon US toy compliance with ASTM F963-23 testing at JJR Lab. We provide CPSC-accepted lab r...

Leave Your Message