EMC China Lab

Introduction to the RED-EN 18031 Testing Project

Views :
Update time : 2025-03-11

Background

On January 12, 2022, the Official Journal of the European Union published Delegated RegULation 2022/30/EU, which mandates compliance with Article 3.3(d), (e), and (f) of the RED (Radio Equipment Directive). This regulation requires applicable wireless devices in the EU market to meet cybersecurity, personal data privacy, and fraud protection standards. The goal is to enhance the cybersecurity of such devices and strengthen consumer confidence. The regulation will be enforced starting August 1, 2025, providing a 42-month transition period for device manufacturers.

 

Introduction to the RED-EN 18031 Testing Project(图1)


In 2024, the EU published the en 18031 standard, which defines cybersecurity requirements for RED compliance.

 

EN 18031 Series: The Basis for Cybersecurity Evaluation under RED

- EN 18031-1 – Corresponding to Article 3.3(d), applicable to all networked devices. It evaluates cybersecurity mechanisms such as authentication, secure updates, and communication encryption. The standard requires that device designs do not compromise network infrastructure, restrict unauthorized use of network resources, and prevent service disruptions.

- EN 18031-2 – Corresponding to Article 3.3(e), targeting data-processing devices (e.g., wearables, child monitoring devices). It mandates log recording, user notifications, and data deletion mechanisms to protect personal data and privacy. Devices must integrate encryption and access control mechanisms to prevent data bREACHes.

- EN 18031-3 – Corresponding to Article 3.3(f), for financial transaction devices (e.g., payment terminals). It requires software integrity verification and transaction tracking mechanisms to prevent financial fraud. Devices must be capable of identifying and blocking fraudulent activities.

 

Comparison of EN 18031 and ETSI EN 303 645

- EN 18031 builds upon the ETSI standard but introduces stricter requirements while adding “not applicable” conditions for greater flexibility.

- Companies already compliant with the ETSI standard will find it easier to pass the EN 18031 evaluation.

 

Mandatory Enforcement Date

- August 1, 2025 – Enforcement begins after a 42-month transition period.

 

Scope of Cybersecurity Requirements

The requirements apply to both directly and indirectly connected wireless radio equipment. Supported wireless communication technologies include, but are not limited to:

- Wi-Fi, Bluetooth, ZigBee, 4G/5G, LoRa, and more.

 

This means that almost all wireless devices with networking capabilities must comply with cybersecurity regulations—including smartphones, smartwatches, and industrial wireless communication devices.

 

RED-EN 18031 Testing Project

Cybersecurity Evaluation

- Authentication mechanisms

- Secure storage

- Key management

- Traffic control

 

Traditional RED Testing

- Electromagnetic Compatibility (EMC)

- Radio Frequency (RF) Performance

- Electrical Safety (LVD)

 

Required Documents for RED-en 18031 certification

- Application form

- Product specification

- User manual

- Circuit schematic

- PCB layout

- BOM list

- CDF (Constructional Data Form)

- Antenna report

- Risk assessment report

 

## JJR Laboratory (China) Services

JJR Laboratory in China provides certification services that can help you save up to 50% on certification costs.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
EU Toy and Children's Product Regulations EU Toy and Children's Product Regulations
12 .01.2025
EU toy rules require compliance with 2009/48/EC and EN71/EN62115 tests for safety and chemicals; JJR...
Canadian Toy and Children's Product Regulations Canadian Toy and Children's Product Regulations
11 .30.2025
Canadian toy rules require safe design, electrical checks, and limits on lead, mercury and phthalate...
Is CE Certification Accepted in Australia Is CE Certification Accepted in Australia
11 .30.2025
CE isn’t accepted in Australia; products need SAA, EMC and RCM tests to meet AS/NZS standards. JJR L...
How to Get Children's Product Certificate (CPC)? How to Get Children's Product Certificate (CPC)?
11 .30.2025
Get a CPC by testing to CPSIA/CPSC standards and meeting all required certificate details. JJR LAB o...
Is RoHS Compliance Required in the US? Is RoHS Compliance Required in the US?
11 .30.2025
US has no mandatory RoHS; CP65 limits toxics. RoHS checks metals and phthalates to EU limits. JJR La...
SDoC Required for NBTC Wireless NVRs SDoC Required for NBTC Wireless NVRs
11 .30.2025
Thailand requires SDoC for all Wireless NVRs per NBTC 1035-2562; ensure RF compliance, Wi-Fi checks,...
Does Your Product Require FCC ID or SDoC? Does Your Product Require FCC ID or SDoC?
11 .30.2025
Know if your product needs FCC ID or SDoC: wireless devices require FCC ID with RF tests; others use...
What is EN 18031 Cybersecurity? What is EN 18031 Cybersecurity?
11 .29.2025
EN 18031 ensures EU radio devices meet cybersecurity, privacy, and anti-fraud rules. Tested to EN180...

Leave Your Message