Radio Equipment Directive 2014/53/EU · Delegated Regulation (EU) 2022/30

EN 18031: cybersecurity for radio equipment

Since 1 August 2025, wireless products placed on the EU market must meet the cybersecurity requirements of the Radio Equipment Directive (RED). The harmonised standards EN 18031-1, -2 and -3 are the main route to showing conformity. This guide explains what they cover and how a documented risk assessment fits in.

Background: the RED delegated act

Commission Delegated Regulation (EU) 2022/30 activated three essential requirements of the Radio Equipment Directive 2014/53/EU, Article 3(3):

  • (d) the equipment must not harm the network or misuse network resources
  • (e) it must safeguard personal data and privacy
  • (f) it must protect against fraud involving money or monetary value

The requirements apply to radio equipment placed on the market from 1 August 2025.

The three parts of EN 18031

  • EN 18031-1 — internet-connected radio equipment (Article 3(3)(d), network protection).
  • EN 18031-2 — radio equipment that processes personal data, and toys, childcare equipment and wearables (Article 3(3)(e), privacy).
  • EN 18031-3 — internet-connected radio equipment that processes virtual money or monetary value (Article 3(3)(f), fraud).

What the standards check

Each part defines security mechanisms — for example access control, authentication, secure update, secure storage and communication, resilience, logging and deletion of data — and decision trees that decide whether a mechanism is required for your product. The answers depend on your assets, their security needs and the threats against them. That is why the standards expect you to identify and document assets and risks before justifying each decision.

Restrictions in the Official Journal citation

Commission Implementing Decision (EU) 2025/138 cited EN 18031-1:2024, -2:2024 and -3:2024 in the Official Journal with restrictions. Among them: the “rationale” and “guidance” sections give no presumption of conformity, and a product does not get presumption of conformity if, under clauses 6.2.5.1 and 6.2.5.2, the user may choose not to set or use any password.

If a restriction applies to your product, or you do not apply the standards in full, you need a notified body (EU-type examination, or full quality assurance). Always check the current citation before relying on self-assessment.

Transition to the Cyber Resilience Act

To avoid duplicate rules, Commission Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, when the Cyber Resilience Act applies in full. Radio equipment placed on the market between 1 August 2025 and 10 December 2027 must still meet the RED requirements, and market surveillance of that equipment continues.

How Zybercomply helps

The product threat modeling module records assets with their confidentiality, integrity and availability needs, lists threats per asset with STRIDE and the MITRE EMB3D catalogue, and scores each risk with ETSI TS 102 165-1. The resulting asset list, risk register and treatment decisions are the evidence you need to back up your EN 18031 decision-tree answers in the technical documentation.

Frequently asked questions

What is EN 18031?
EN 18031 is a series of three harmonised European standards (EN 18031-1, -2 and -3) that specify cybersecurity requirements for radio equipment under the RED delegated act (EU) 2022/30.
When does EN 18031 apply?
The RED cybersecurity requirements apply to radio equipment placed on the EU market from 1 August 2025. EN 18031 is the harmonised route to showing conformity with them.
Which products are covered?
Radio equipment that can communicate over the internet, that processes personal, traffic or location data, or that handles virtual money or monetary value — including many IoT devices, wearables, toys and smart-home products.
Do I need a notified body?
Not if you apply the harmonised standards in full and none of the restrictions in Implementing Decision (EU) 2025/138 apply to your product. Otherwise a notified body is required, through EU-type examination or full quality assurance.
How does the Cyber Resilience Act relate to EN 18031?
The Cyber Resilience Act (Regulation (EU) 2024/2847) applies in full from 11 December 2027. From that date the RED cybersecurity delegated act (EU) 2022/30 is repealed by Delegated Regulation (EU) 2026/339, and radio equipment must meet the CRA instead. A solid risk assessment made now carries over.