EMC China Lab

What is EN 18031 Compliance Certification?

Views :
Update time : 2025-03-11

Recently, the European Commission announced in its official journal, Office Journal (OJ), that the en 18031 series of standards have been incorporated into the Radio Equipment Directive (Directive 2014/53/EU) as harmonized standards. This decision aims to further regULate cybersecurity requirements for radio equipment, enhancing compliance and security for devices entering the EU market.

 

As the cybersecurity requirements outlined in the EN 18031 series will become mandatory from August 1, 2025, this represents a significant shift for wireless equipment manufacturers.

 

What is EN 18031 Compliance Certification?(图1)


Background and Significance

The EN 18031 series of standards were developed jointly by the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC), primarily focusing on cybersecurity requirements for radio equipment. The inclusion of this series marks a crucial step in the EU's efforts to enhance cybersecurity for radio equipment, providing manufacturers with a clear technical framework while simplifying the process of entering the EU market.

 

Composition of the EN 18031 Series

The EN 18031 series consists of three parts, each addressing different types of radio equipment and their security requirements. In 2022, the European Commission also introduced cybersecurity requirements under Article 3(3) of the directive.

 

en 18031-1:2024

- Scope: Internet-connected radio equipment.

- Compliance Requirements: Must meet the basic requirements of Article 3(3)(d) of the Radio Equipment Directive, which introduces cybersecurity measures to "prevent network harm and service degradation."

 

EN 18031-2:2024

- Scope: Includes internet-connected devices, childcare equipment, toy devices, and wearable devices.

- Compliance Requirements: Must meet the basic requirements of Article 3(3)(e) of the Radio Equipment Directive, introducing cybersecurity measures to "protect personal data and user privacy."

 

EN 18031-3:2024

- Scope: Radio equipment handling virtual currency or monetary value.

- Compliance Requirements: Must meet the basic requirements of Article 3(3)(f) of the Radio Equipment Directive, introducing cybersecurity measures to "prevent fraud in wireless devices handling virtual currency."

 

Restrictions in the Harmonized EN 18031 Standards Listed in the OJ

EN 18031-1:2024

- If users are allowed to not set or use any passwords (Sections 6.2.5.1 and 6.2.5.2), the device does not meet the requirements of Article 3(3)(d) of the directive.

- The "rationale" and "guidance" sections of the standard do not provide a presumption of conformity with the basic requirements of Article 3(3)(d).

 

EN 18031-2:2024

- If users are allowed to not set or use any passwords (Sections 6.2.5.1 and 6.2.5.2), the device does not meet the requirements of Article 3(3)(e).

- For specific devices like children's equipment, if parental or guardian access control is not ensuRED (e.g., Section 6.1.3.4.2), the device does not comply with Article 3(3)(e).

- The "rationale" and "guidance" sections do not provide a presumption of conformity with Article 3(3)(e).

 

EN 18031-3:2024

- If users are allowed to not set or use any passwords (Sections 6.2.5.1 and 6.2.5.2), the device does not meet the requirements of Article 3(3)(f).

- Section 6.3.2.4 outlines assessment criteria for security updates, listing four different implementation categories, including digital signatures, secure communication mechanisms, and access control mechanisms. However, no single approach is sufficient for financial asset security assessment.

- Manufacturers of products covered by EN 18031-3:2024 cannot ensure compliance with Article 3(3)(f) solely based on the product’s design. Therefore, third-party conformity assessment is mandatory.

- The "rationale" and "guidance" sections do not provide a presumption of conformity with Article 3(3)(f).

 

These restrictions indicate that while the EN 18031 series provides a cybersecurity framework for radio equipment, some devices may still fail to fully meet the essential requirements of the Radio Equipment Directive in the following areas:

- User password setup and usage.

- Parental or guardian access control for children's devices.

- Security evaluation of devices handling virtual currency.

 

For radio equipment that is partially compliant, non-compliant, or lacks harmonized standards, the conformity assessment process must involve a Notified Body (NB) for evaluation.

 

Impact on Manufacturers

The implementation of the EN 18031 series will drive manufacturers to strengthen the cybersecurity of their devices while providing greater security assurance for users. These standards will also help regulate the EU radio equipment market and boost consumer confidence in wireless devices.

 

Since the RED cybersecurity requirements will be enforced from August 1, 2025, all products entering the EU market after this date must comply. Manufacturers must act quickly to ensure compliance with the new cybersecurity requirements.

 

Key Actions for Manufacturers:

1. Determine whether products fall under the restricted clauses.

2. Document additional security measures.

3. Select the appropriate certification pathway.

 

Cybersecurity Testing and Certification Services by JJR Laboratory

JJR Laboratory provides comprehensive testing and evaluation services to help manufacturers meet cybersecurity compliance requirements.


Email:hello@jjrlab.com


Leave Your Message


Write your message here and send it to us


Related News
Read More >>
 RCM AS/NZS CISPR 32:2023 Testing for Power Adapte RCM AS/NZS CISPR 32:2023 Testing for Power Adapte
02 .02.2026
JJR provides CMS/EMC testing per AS/NZS CISPR 32:2023 via a CNAS & ISO/IEC 17025 accredited lab,...
How to get Australia SAA Compliance? How to get Australia SAA Compliance?
02 .02.2026
Entering the AU/NZ market requires SAA compliance based on AS/NZS standards, with testing by CMS, CN...
Does Canada Require RoHS Compliance Does Canada Require RoHS Compliance
02 .02.2026
Canada controls hazardous substances under CEPA. RoHS testing to IEC standards is recommended. CMS, ...
EU CE LVD, EMC, RoHS Directives Compliance Guide EU CE LVD, EMC, RoHS Directives Compliance Guide
02 .02.2026
EU CE LVD, EMC, RoHS compliance guide covering standards, testing and DoC, with CMS, CNAS, ISO/IEC 1...
Quick Guide to the CE-LVD Low Voltage Directive Quick Guide to the CE-LVD Low Voltage Directive
02 .02.2026
CE-LVD ensures electrical products meet EU safety rules within voltage limits, tested to EN standard...
Global Certification Guide for Lithium Batteries Global Certification Guide for Lithium Batteries
02 .01.2026
Lithium battery certifications in Thailand, Korea, India, Australia, and Saudi Arabia. CMS/CNAS/ISO/...
Compliance of Amazon 18650 Lithium Battery Product Compliance of Amazon 18650 Lithium Battery Product
02 .01.2026
Amazon 18650 batteries face removal; sellers must meet UN38.3, UL, FCC, MSDS standards. JJR CMS, CNA...
What is CE Certification and EU Authorized Represe What is CE Certification and EU Authorized Represe
02 .01.2026
CE Certification requires an EU Authorized Representative. JJR labs (CMS, CNAS, ISO/IEC 17025) provi...

Leave Your Message