EMC China Lab

RED Cybersecurity EN 18031 Standard

Views :
Update time : 2026-10-01

With the popularization of Internet of Things (IoT) devices and the rapid development of wireless communication technology, cybersecurity and user privacy protection have become core issues in global regulation. Through the Radio Equipment Directive (RED) and its accompanying standard en 18031, the European Union has established strict security thresholds for wireless devices entering the European market, and it will be mandatorily enforced through ce marking certification starting from August 1, 2025.


Meanwhile, the EU Cyber Resilience Act (CRA), whose mandatory enforcement date is tentatively set for the second half of 2027, does not yet have a clearly defined specific definition of compliance. The CRA aims to supplement the cybersecurity areas currently not covered by RED, will in principle adopt RED's enterprise standards, and will make necessary additions and revisions to the standard provisions in the future.

Within the EU, both the red directive requirements and CRA regulations are mandatory. Any product sold in the EU market must comply with the requirements of these two regulations, which will directly relate to ce marking certification.


en 18031 standard and Product Scope

Delegated Regulation 2022/30/EU covers equipment that can communicate via the internet directly or through other equipment (indirectly), and radio equipment that may expose sensitive personal data. For example:

  • Mobile phones, tablets, and laptops

  • Wireless toys and childcare equipment, such as baby monitors

  • Wearable equipment, such as smartwatches and fitness trackers

The product scope corresponding to specific regulatory articles is as follows:

  • Article 3.3 (d): Equipment related to network protection

  • Article 3.3 (e): Equipment processing personal data, traffic data, or location data

  • Article 3.3 (f): Radio equipment that enables the holder or user to transfer money, monetary value, or virtual currency as defined in EU Directive 2019/713 Article 2 (d)

EN 18031 Standard Main Evaluation Content

  • 3.3.(d) en 18031-1:2024: Evaluates Security Assets and Network Assets.

  • 3.3.(e) EN 18031-2:2024: Evaluates Security Assets and Privacy Assets.

  • 3.3.(f) EN 18031-3:2024: Evaluates Security Assets and Financial Assets.


EN 18031 Standard Main Evaluation Items

Requirements for 3.3.(d) EN 18031-1:2024

  • Access control mechanism

  • Authentication mechanism

  • Secure update mechanism

  • Secure storage mechanism

  • Secure communication mechanism

  • Resilience mechanism

  • Network monitoring mechanism

  • Traffic control mechanism

  • Confidential cryptographic keys

  • General device capabilities

  • Cryptography

Requirements for 3.3.(e) EN 18031-2:2024

  • Access control mechanism

  • Authentication mechanism

  • Secure update mechanism

  • Secure storage mechanism

  • Secure communication mechanism

  • General device capabilities

  • Cryptography

  • Logging mechanism

  • Deletion mechanism

  • User notification mechanism

Requirements for 3.3.(f) EN 18031-3:2024

  • Access control mechanism

  • Authentication mechanism

  • Secure update mechanism

  • Secure storage mechanism

  • Secure communication mechanism

  • Confidential cryptographic keys

  • General device capabilities

  • Cryptography

  • Logging mechanism


Action Guide for Manufacturers

Manufacturers should start preparing for the August 2025 mandatory implementation deadline by reviewing existing products and reviewing new product designs to ensure they can comply with the new cybersecurity requirements and obtain the corresponding certifications before the mandatory implementation deadline. This move will mitigate business risks and help ensure a competitive advantage.

If products within the scope do not comply with the requirements, manufacturers may face a series of serious consequences, including but not limited to: product recalls, fines, market entry bans, and reputation loss.

  • Note 1: If the time for data confirmation and rectification is extended, the certification cycle will be postponed accordingly. It is recommended to reserve time for rectification.

  • Note 2: Currently, over 80% of products on the market will involve rectification. Therefore, it is recommended to reserve rectification time in the certification cycle and conduct a preliminary assessment half a year to one year in advance.

  • Note 3: Because the testing contents involved in different products vary and product design schemes are different, it is recommended to conduct a preliminary assessment test for each type of product in advance. After understanding the detailed requirements for that type of product, introduce the testing requirements into the product research and development stage to avoid massive rectifications during certification.


Frequently Asked Questions (FAQ)

1. Which products require compliance?

  • Models that have never been shipped, and products shipped after the mandatory execution date (August 1, 2025), must complete testing and obtain certificates as required.

  • Products that have been shipped before, but still need to be shipped after the mandatory execution date (August 1, 2025), must complete testing and obtain certificates as required.

  • Products that have been shipped before and sold in the EU market, but will no longer be shipped after the mandatory execution date (August 1, 2025): No need to test and certify according to the new requirements.


2. If a product has passed EN 303 645, does it still need to comply with RED 3.3d/e/f?

  • If the product has already passed EN 303 645, it is necessary to supplement the difference testing of EN 18031 on this basis, and then obtain the Notified Body (NB) certificate to meet the compliance requirements.


3. How is the RED 3.3d/e/f certificate issued?

  • After the testing is completed, a test report is issued and submitted to the NB agency for certification. A separate certificate for RED 3.3d/e/f can be issued, or it can be issued together with the original EMC/Safety/RF certificates, etc.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
Australia RCM Certification for Radio Devices Australia RCM Certification for Radio Devices
10 .01.2026
Australia RCM certification for radio devices by China JJR Laboratory covers AS/NZS 4268, CISPR 32, ...
RED Cybersecurity EN 18031 Standard RED Cybersecurity EN 18031 Standard
10 .01.2026
RED Cybersecurity EN 18031 testing by China JJR Lab covers EN 18031-1/-2/-3, RED 3.3(d/e/f), CE comp...
Compliance Testing for EMC Compliance Testing for EMC
10 .01.2026
Compliance Testing for EMC by China JJR Laboratory covers CE, FCC, ISED, RCM, MIC and KC standards, ...
What is Amazon Toy Compliance? What is Amazon Toy Compliance?
09 .30.2026
Amazon Toy Compliance Testing by JJR Laboratory covers ASTM F963-23, CPSIA and EN 71 standards, help...
What is Cytotoxicity ISO 10993-5 What is Cytotoxicity ISO 10993-5
09 .29.2026
ISO 10993-5 cytotoxicity testing at JJR LAB uses cell culture hardware and analyzers to measure cell...
What is Hemocompatibility Testing ISO 10993? What is Hemocompatibility Testing ISO 10993?
09 .29.2026
ISO 10993-4 hemocompatibility testing uses blood-contact test systems, flow probes and analyzers to ...
What is ISO 10993-5 Tests for In Vitro Cytotoxicit What is ISO 10993-5 Tests for In Vitro Cytotoxicit
09 .29.2026
ISO 10993-5 cytotoxicity testing at JJR LAB uses L929 cells, MTT hardware and extraction methods to ...
Electronic Product IEC 62368-1 Safety Testing Electronic Product IEC 62368-1 Safety Testing
09 .28.2026
JJR Lab provides IEC 62368-1 safety testing for AV and ICT products, covering HBSE, electric shock, ...

Leave Your Message