EMC China Lab

Is EN 18031 Cybersecurity Compliance Mandatory?

Views :
Update time : 2025-04-22

With only 100 days left until the mandatory enforcement of en 18031, many IoT device manufacturers have yet to initiate their certification processes. This wait-and-see attitude may stem from the "soft landing" precedent set by the UK's PSTI Act in 2022. Back then, many businesses successfULly avoided risk by betting on policy delays or loosening. However, in Brussels, the dynaMICs surrounding cybersecurity certification have fundamentally shifted: according to Article 17 of the Cyber Resilience Act and ENISA's "2025 Cybersecurity Certification White Paper," EN 18031 has been established as a technical support standard for the Cyber Resilience Act, forming a "trinity" regulatory framework alongside the GDPR. This means that companies attempting to replicate the PSTI wait-and-see strategy are essentially betting on a losing game.

 

Is EN 18031 Cybersecurity Compliance Mandatory?(图1)


Historical Experience: The EU's Enforcement of Technical Regulations

While some manufacturers remain skeptical about the enforcement of EN 18031 (thinking it might be "all talk, no action" like some technical standards), the EU has historically had a strong enforcement record in areas related to national security, privacy protection, and public safety, with almost no "unfinished business" cases.

 

Counterexamples:

- RED Directive: In the past, some manufacturers attempted to bypass EMC or RF testing through loopholes, but this was limited to areas with lower technical risks (e.g., Bluetooth signal interference). However, once safety risks are involved (e.g., battery explosion hazards), the EU's enforcement is strict, even including product recalls. Similarly, cybersecurity testing will not be overlooked.

 

- GDPR (General Data Protection Regulation): When GDPR came into effect in 2018, there were concerns about its difficult enforcement. However, through hefty fines (e.g., Amazon €746 million, Meta €1.2 billion) and cross-border cooperation, the EU established its authority. GDPR has since become a global benchmark for privacy protection.

 

The Special Nature of Cybersecurity: The EU Has Elevated It to National Security Status

The core of EN 18031 is to prevent network attacks that could cripple critical infrastructure, leak private information, or trigger public safety incidents, which is fundamentally different from traditional safety, emc testing:

 

- Extension of GDPR: Device vulnerabilities leading to data leaks can directly trigger GDPR fines (e.g., smart home cameras leaking user privacy).

 

- EU Cyber Resilience Act: The new regulation passed in 2024 explicitly requires connected devices to meet cybersecurity standards (such as vulnerability fixes, security updates), and EN 18031 will serve as its technical foundation.

 

- Geopolitical Drivers: After the Russia-Ukraine conflict, the EU has zero tolerance for network attacks in critical areas like energy, communication, and transportation. For example, a camera being hacked could serve as a gateway for attacking the power grid.

 

Signals of EN 18031's Mandatory Enforcement

- Clear timeline: EN 18031 will be enforced from August 1, 2025. Similar to GDPR, the EU will allow a transition period but will not delay its implementation.

 

- Leading companies have already acted: Major international and domestic companies, such as Samsung, Philips, Hikvision, and Dahua, began en 18031 certification in 2024. By Q1 2025, over 60% of their certified products will be compliant. These leading manufacturers’ market insights are sharp and should not be ignored.

 

- High compliance costs for manufacturers: Devices that fail to comply with EN 18031 will not receive the CE mark, meaning they will be unable to enter the EU market. Manufacturers cannot afford to take this risk.

 

The Future of Cybersecurity

- Short-term (1-2 years): EN 18031 will continue as a supplementary provision to the RED Directive but will work in tandem with the Cyber Resilience Act, forming a "dual constraint."

 

- Long-term (3-5 years): Cybersecurity will likely become an independent, mandatory certification system, much like medical devices (MDR) or automobiles (E-mark). The driving factors include:

 

- Technical complexity: Cybersecurity involves ongoing threats (like zero-day vulnerabilities) and requires dynamic assessment, which is incompatible with static RF/EMC testing modes.

 

- Cross-industry demand: Smart cars, industrial IoT, and medical devices all require unified cybersecurity standards, making independent certification more efficient.

 

Conclusion

- No unfinished business: The EU has firmly positioned cybersecurity as a core aspect of "digital sovereignty," and EN 18031 serves as a technical implementation tool, working alongside GDPR and the Cyber Resilience Act to form a complete regulatory chain.

 

- Manufacturers have no choice: Compliance is the only path to entering the EU market. With leading companies already starting certification, the entire industry will be forced to follow suit.

 

- Trend towards independent certification: In the future, cybersecurity certification will likely be detached from the RED Directive, becoming an independent module, and may even require regular updates (e.g., annual vulnerability scans).

 

Recommendations for Manufacturers:

Start preparing for EN 18031 compliance immediately, focusing on the following cost items:

 

1. Security Development Lifecycle (SDLC) modifications;

2. Third-party vulnerability scanning and penetration testing;

3. Automated deployment of security update mechanisms.

 

The cost of delay is far higher than the cost of compliance.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
WEEE Registration for Waste Electrical &Electr WEEE Registration for Waste Electrical &Electr
12 .15.2025
WEEE registration ensures EU recycling compliance per 2012/19/EU for EEE categories 1–6. Tests per E...
MSDS Chemical Safety Testing MSDS Chemical Safety Testing
12 .15.2025
JJR LAB provides MSDS chemical safety testing per legal standards, covering 16 sections on hazards, ...
What Are the Differences Between UK REACH and EU R What Are the Differences Between UK REACH and EU R
12 .15.2025
UK REACH, separate from EU REACH since 2021, lags in SVHC and Annex XVII updates; compliance testing...
E-Cigarette GB 41700 Compliance Testing E-Cigarette GB 41700 Compliance Testing
12 .15.2025
GB 41700-2022 mandates safety, materials, emissions, and nicotine limits for e-cigarettes in China. ...
What Are the Testing Items of California Propositi What Are the Testing Items of California Propositi
12 .13.2025
California Proposition 65 (CA65) testing covers CA products, assessing toxic chemicals like lead, ca...
E-Cigarette EU TPD Testing E-Cigarette EU TPD Testing
12 .13.2025
E-Cigarette EU TPD Testing by JJR LAB: nicotine, carbonyls, metals, flavors, glycols & TSNAs tes...
Testing Certification for E-cigarettes Exported to Testing Certification for E-cigarettes Exported to
12 .13.2025
E-cigarettes exported to the EU must meet RoHS, REACH, TPD, FCM, battery, CE, and PCN-UFI standards....
What is Amazon US CPC Certification? What is Amazon US CPC Certification?
12 .12.2025
Amazon US CPC Certification ensures children’s products meet safety standards. JJR Lab provides test...

Leave Your Message