← All standards
CEN / CENELECRadio Equipment Directive

What is EN 18031?

EN 18031 is a three-part European standard series setting common security requirements for radio equipment. Applying EN 18031 gives presumption of conformity with Radio Equipment Directive Article 3(3)(d), (e) and (f), subject to published restrictions.

Key takeaways

  1. EN 18031-1 covers network protection, EN 18031-2 covers privacy and personal data, and EN 18031-3 covers fraud protection.
  2. Commission Implementing Decision (EU) 2025/138 cited all three parts in the Official Journal, with restrictions that remove part of the presumption.
  3. The underlying obligation has been mandatory since 1 August 2025 under Delegated Regulation (EU) 2022/30.
  4. EN 18031 confers no presumption of conformity with the Cyber Resilience Act, because it is harmonised under a different instrument.
  5. EN 18031 test evidence still carries into a Cyber Resilience Act technical file, because the two instruments assess the same security mechanisms.

What does each part of EN 18031 cover?

Each part answers one point of Radio Equipment Directive Article 3(3). A product can fall under one part, two or all three, and the equipment categories decide which.

PartRED pointObjectiveEquipment covered
EN 18031-1:2024Article 3(3)(d)The network is not harmed and network resources are not misused.Internet-connected radio equipment.
EN 18031-2:2024Article 3(3)(e)Personal data and the privacy of the user and the subscriber are safeguarded.Internet-connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment.
EN 18031-3:2024Article 3(3)(f)Fraud is prevented, through better control of transfers of money and virtual currency.Internet-connected radio equipment processing virtual money or monetary value.

Does EN 18031 give presumption of conformity?

Yes, under the Radio Equipment Directive, and not in full. Commission Implementing Decision (EU) 2025/138 of 28 January 2025 cited EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 in the Official Journal, and attached restrictions to each. Work inside a restriction and the presumption does not reach it, so that part of the file needs its own argument or a notified body.

  • The rationale and guidance text inside the standards is informative. It confers no presumption of conformity on its own.
  • The clauses that allow a user to decline to set or use a password are excluded, so a product that ships with no access control cannot rely on the standard for that point.
  • For equipment intended for children, the clauses are excluded where the product provides no parental or guardian access control.
  • In EN 18031-3, one assessment criterion on secure updates is excluded from the citation.

Read the restrictions in the Annex of the Implementing Decision before you rely on a clause. A test report that quotes a restricted clause as though it settled the point is the most common finding a market surveillance authority can raise on this series.

Which security mechanisms does EN 18031 assess?

The series works through named mechanism families rather than a flat requirement list. Each family runs a decision tree: decide whether the mechanism applies to the product, then assess whether the implementation is appropriate.

CodeMechanismDefined in part
ACMAccess control mechanism1, 2, 3
AUMAuthentication mechanism1, 2, 3
SUMSecure update mechanism1, 2, 3
SSMSecure storage mechanism1, 2, 3
SCMSecure communication mechanism1, 2, 3
RLMResilience mechanism1
NMMNetwork monitoring mechanism1
TCMTraffic control mechanism1
CCKConfidential cryptographic keys1, 2, 3
GECGeneral equipment capabilities1, 2, 3
CRYCryptography1, 2, 3
DLMDeletion mechanism2
UNMUser notification mechanism2, 3
LGMLogging mechanism3

Does EN 18031 count for the Cyber Resilience Act?

EN 18031 confers no presumption of conformity with the Cyber Resilience Act. Presumption under Article 27 of Regulation (EU) 2024/2847 needs a standard cited in the Official Journal under that Regulation. The harmonised set being drafted for the Cyber Resilience Act is the EN 40000 series for horizontal requirements and the ETSI EN 304 6xx series for product categories. Neither has been cited.

The evidence still travels. A product assessed against EN 18031 has already tested the mechanisms the Cyber Resilience Act asks about in Annex I, so the test reports become supporting evidence in the technical file rather than wasted work.

EN 18031 mechanismCRA requirementWhat the requirement asks for
ACM, AUMAnnex I Part I (2)(d)Protection from unauthorised access by appropriate control mechanisms, including authentication and identity management.
SSM, CCK, CRYAnnex I Part I (2)(e) and (f)Confidentiality of stored, transmitted and processed data, and integrity of data, commands, configuration and programs.
SCMAnnex I Part I (2)(e)Encryption of data in transit, argued from the same test evidence.
SUMAnnex I Part II (7)Mechanisms to distribute updates securely, and automatically where applicable for security updates.
RLM, TCM, NMMAnnex I Part I (2)(h) and (i)Availability of essential functions after an incident, and limiting the negative impact on other devices or networks.
GECAnnex I Part I (2)(a) and (j)Release without known exploitable vulnerabilities, and minimising attack surfaces including external interfaces.
DLMAnnex I Part I (2)(m)The possibility for users to remove all data and settings permanently and securely.
LGMAnnex I Part I (2)(l)Recording and monitoring of relevant internal activity, including access to and modification of data.

The mapping is an evidence-reuse aid, not a conformity claim. A Cyber Resilience Act assessment still has to run against Annex I on the basis of the Article 13(2) risk assessment for the product.

When does EN 18031 apply?

The standard itself is voluntary. The obligation underneath it is not, and it has been in force since 1 August 2025.

DateWhat happenedInstrument
29 October 2021The Commission adopted the delegated regulation activating Radio Equipment Directive Article 3(3)(d), (e) and (f).Reg. (EU) 2022/30
28 January 2025The Commission cited EN 18031-1, EN 18031-2 and EN 18031-3 as harmonised standards, with restrictions.Dec. (EU) 2025/138
1 August 2025The three cybersecurity points became mandatory for the covered radio equipment.Reg. (EU) 2022/30
11 December 2027The Cyber Resilience Act applies in full to products with digital elements, including radio equipment already covered by EN 18031.Reg. (EU) 2024/2847

Questions about EN 18031

What is EN 18031?

EN 18031 is a three-part European standard series setting common security requirements for radio equipment. Commission Implementing Decision (EU) 2025/138 of 28 January 2025 cited all three parts in the Official Journal, so applying them gives presumption of conformity with Radio Equipment Directive Article 3(3)(d), (e) and (f), subject to published restrictions.

When does EN 18031 apply?

Delegated Regulation (EU) 2022/30 made Radio Equipment Directive Article 3(3)(d), (e) and (f) mandatory from 1 August 2025. EN 18031 is the harmonised route to demonstrating conformity with those three points from that date.

What are the restrictions on EN 18031?

Commission Implementing Decision (EU) 2025/138 cited the three parts with restrictions. The rationale and guidance text inside the standards is informative and confers no presumption, the clauses that let a user decline to set a password are excluded, and the child-equipment clauses are excluded where no parental access control is provided.

Does EN 18031 give presumption of conformity with the Cyber Resilience Act?

No. EN 18031 is harmonised under the Radio Equipment Directive, not under Regulation (EU) 2024/2847. Presumption of conformity with the Cyber Resilience Act needs a standard cited in the Official Journal under that Regulation, and no such standard has been cited yet.

Do I need EN 18031 and the Cyber Resilience Act at the same time?

A radio product placed on the EU market meets Radio Equipment Directive Article 3(3)(d), (e) and (f) now, and meets the Cyber Resilience Act from 11 December 2027. Both apply to the same product in that window, and the EN 18031 test evidence supports the Annex I argument.

What is the difference between EN 18031 and ETSI EN 303 645?

EN 18031 is harmonised under the Radio Equipment Directive and carries legal presumption of conformity. ETSI EN 303 645 is a consumer IoT baseline that carries none, and is used because laboratories test against it. The two overlap heavily in subject matter.

Sources

Last updated on 2026-09-04.

Turn EN 18031 test evidence into a CRA technical file

Record the risk assessment, map each Annex I requirement to the evidence that supports it, and export an Annex VII dossier and an EU Declaration of Conformity.