Triplicate

EU RED cybersecurity rules: EN 18031 and Regulation 2022/30 from August 2025

Since 1 August 2025, many radio products sold in the EU, such as internet-connected devices, toys, childcare and wearable equipment and products handling money, must meet the cybersecurity requirements of Articles 3(3)(d), (e) and (f) of the Radio Equipment Directive. The EN 18031 harmonised standards give a presumption of conformity, but with restrictions: in some cases a notified body must assess the product.

Checked against official sources: 2026-10

At a glance

LawCommission Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive 2014/53/EU
Applies from1 August 2025
RequirementsArticle 3(3)(d) network protection, (e) personal data and privacy, (f) protection from fraud
StandardsEN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024, cited under Implementing Decision (EU) 2022/2191
EN 18031-1Internet-connected radio equipment
EN 18031-2Radio equipment processing data, such as toys, childcare and wearable equipment
EN 18031-3Internet-connected equipment processing virtual money or monetary value
Notified bodiesOnly bodies notified for Articles 3.3.d/e/f can issue EU-type examination certificates (24 listed in the Commission's guidance)

Who is affected

Delegated Regulation (EU) 2022/30 was adopted in response to concerns over the resilience of some products to cyber-attacks. It makes the essential requirements in Articles 3(3)(d), (e) and (f) of the Radio Equipment Directive apply to specified classes of radio equipment from 1 August 2025: protecting networks, protecting personal data and privacy, and protecting against fraud.

The European Commission asked CEN and CENELEC for three generic standards: EN 18031-1 for internet-connected radio equipment, EN 18031-2 for radio equipment processing data, such as toys, childcare and wearable equipment, and EN 18031-3 for internet-connected equipment processing virtual money or monetary value. Their requirements overlap to a high degree.

Restrictions on the presumption of conformity

Conformity assessment

Self-assessment under internal production control (module A) is allowed only if the relevant EN 18031 standard is applied and not affected by the restrictions. A voluntary third-party assessment is always possible under Article 17 of the Radio Equipment Directive. Only notified bodies competent for cybersecurity under the Delegated Regulation can issue EU-type examination certificates; the NANDO database can be filtered by Articles 3.3.d/e/f.

The Commission does not advise on how to apply the standards to specific products; that responsibility lies with the manufacturer. Future legislation such as Regulation (EU) 2024/2847 will also affect connected products.

Step by step

  1. Check whether your radio product falls in a class covered by Delegated Regulation (EU) 2022/30, such as internet-connected equipment, toys, childcare or wearable equipment, or equipment handling money.
  2. Identify which of EN 18031-1, EN 18031-2 and EN 18031-3 apply and assess the product against them.
  3. Check the restrictions: password options, parental access control under EN 18031-2 and secure updates under EN 18031-3.
  4. Use self-assessment (module A) only if the standard applies without restrictions; otherwise go to a notified body competent for Articles 3.3.d/e/f, found in NANDO.
  5. Update the technical documentation and the EU declaration of conformity to include Articles 3(3)(d), (e) and (f).

Documents you usually need

Common problems and how to avoid them

The product lets users skip setting a password.

What to do: The default-password clauses then give no presumption of conformity, so a notified body assessment is needed, or remove that option.

A payment-capable device is self-assessed under EN 18031-3.

What to do: The secure update clause 6.3.2.4 gives no presumption, so a third-party assessment is mandatory.

A connected toy has no parental access control.

What to do: EN 18031-2 clauses 6.1.3 to 6.1.6 then give no presumption; add parental or guardian access control or use a notified body.

The declaration of conformity was not updated after 1 August 2025.

What to do: Add the Article 3(3)(d), (e) and (f) requirements and the standards applied.

Sources

  1. Guidance on the application of the harmonised standards series EN 18031:2024 in support of Commission Delegated Regulation 2022/30 European Commission (DG GROW), published by Spain's Ministry for Digital Transformation
  2. Guide for the application of the harmonised standards of the Radio Equipment Directive cybersecurity requirements ESMIG

Rules change often. This note is practical guidance based on the sources above, not legal advice. Confirm current requirements with the authority, your importer or a licensed customs broker before you ship.

Share with a colleagueWhatsAppLinkedInX

Trade notes

Had this problem? Share how you solved it

Tell us what happened and what worked. We read every message. With your permission we may add your case to this note, without your name or company.

Common questions

What is EN 18031?

A series of three harmonised standards, EN 18031-1, -2 and -3 (2024), that support the cybersecurity requirements of the Radio Equipment Directive under Delegated Regulation (EU) 2022/30.

Since when do the RED cybersecurity rules apply?

Since 1 August 2025.

Can I self-certify?

Yes, with module A, but only if the relevant EN 18031 standard applies without being affected by its restrictions; otherwise a notified body is needed.

Which products are covered?

Specified classes of radio equipment, such as internet-connected equipment, equipment processing data like toys, childcare and wearable equipment, and equipment processing virtual money or monetary value.

How do I find a notified body for RED cybersecurity?

Search the NANDO database filtered by Articles 3.3.d/e/f; the Commission's guidance cites 24 competent bodies.

More free tools

Triplicate is free and keeps getting better. Found it useful? Support Triplicate ♥