EU RED cybersecurity rules: EN 18031 and Regulation 2022/30 from August 2025
Since 1 August 2025, many radio products sold in the EU, such as internet-connected devices, toys, childcare and wearable equipment and products handling money, must meet the cybersecurity requirements of Articles 3(3)(d), (e) and (f) of the Radio Equipment Directive. The EN 18031 harmonised standards give a presumption of conformity, but with restrictions: in some cases a notified body must assess the product.
Checked against official sources: 2026-10
At a glance
Who is affected
Delegated Regulation (EU) 2022/30 was adopted in response to concerns over the resilience of some products to cyber-attacks. It makes the essential requirements in Articles 3(3)(d), (e) and (f) of the Radio Equipment Directive apply to specified classes of radio equipment from 1 August 2025: protecting networks, protecting personal data and privacy, and protecting against fraud.
The European Commission asked CEN and CENELEC for three generic standards: EN 18031-1 for internet-connected radio equipment, EN 18031-2 for radio equipment processing data, such as toys, childcare and wearable equipment, and EN 18031-3 for internet-connected equipment processing virtual money or monetary value. Their requirements overlap to a high degree.
Restrictions on the presumption of conformity
- The rationale and guidance sections of the three standards give no presumption of conformity.
- Default passwords (clauses 6.2.5.1 and 6.2.5.2): no presumption if users may set no password; no third-party assessment is needed if the manufacturer does not use that option.
- EN 18031-2 clauses 6.1.3 to 6.1.6: no presumption if parental or guardian access control is not ensured.
- EN 18031-3 clause 6.3.2.4 (secure updates): no presumption regardless of product design, so a third-party assessment is mandatory.
Conformity assessment
Self-assessment under internal production control (module A) is allowed only if the relevant EN 18031 standard is applied and not affected by the restrictions. A voluntary third-party assessment is always possible under Article 17 of the Radio Equipment Directive. Only notified bodies competent for cybersecurity under the Delegated Regulation can issue EU-type examination certificates; the NANDO database can be filtered by Articles 3.3.d/e/f.
The Commission does not advise on how to apply the standards to specific products; that responsibility lies with the manufacturer. Future legislation such as Regulation (EU) 2024/2847 will also affect connected products.
Step by step
- Check whether your radio product falls in a class covered by Delegated Regulation (EU) 2022/30, such as internet-connected equipment, toys, childcare or wearable equipment, or equipment handling money.
- Identify which of EN 18031-1, EN 18031-2 and EN 18031-3 apply and assess the product against them.
- Check the restrictions: password options, parental access control under EN 18031-2 and secure updates under EN 18031-3.
- Use self-assessment (module A) only if the standard applies without restrictions; otherwise go to a notified body competent for Articles 3.3.d/e/f, found in NANDO.
- Update the technical documentation and the EU declaration of conformity to include Articles 3(3)(d), (e) and (f).
Documents you usually need
- Technical documentation, including the cybersecurity assessment against EN 18031
- EU declaration of conformity covering Articles 3(3)(d), (e) and (f)
- EU-type examination certificate from a notified body, where required
- Test reports for the applicable EN 18031 standards
Common problems and how to avoid them
What to do: The default-password clauses then give no presumption of conformity, so a notified body assessment is needed, or remove that option.
What to do: The secure update clause 6.3.2.4 gives no presumption, so a third-party assessment is mandatory.
What to do: EN 18031-2 clauses 6.1.3 to 6.1.6 then give no presumption; add parental or guardian access control or use a notified body.
What to do: Add the Article 3(3)(d), (e) and (f) requirements and the standards applied.
Sources
- Guidance on the application of the harmonised standards series EN 18031:2024 in support of Commission Delegated Regulation 2022/30 European Commission (DG GROW), published by Spain's Ministry for Digital Transformation
- Guide for the application of the harmonised standards of the Radio Equipment Directive cybersecurity requirements ESMIG
Rules change often. This note is practical guidance based on the sources above, not legal advice. Confirm current requirements with the authority, your importer or a licensed customs broker before you ship.
Trade notes
Common questions
What is EN 18031?
A series of three harmonised standards, EN 18031-1, -2 and -3 (2024), that support the cybersecurity requirements of the Radio Equipment Directive under Delegated Regulation (EU) 2022/30.
Since when do the RED cybersecurity rules apply?
Since 1 August 2025.
Can I self-certify?
Yes, with module A, but only if the relevant EN 18031 standard applies without being affected by its restrictions; otherwise a notified body is needed.
Which products are covered?
Specified classes of radio equipment, such as internet-connected equipment, equipment processing data like toys, childcare and wearable equipment, and equipment processing virtual money or monetary value.
How do I find a notified body for RED cybersecurity?
Search the NANDO database filtered by Articles 3.3.d/e/f; the Commission's guidance cites 24 competent bodies.
More free tools
Triplicate is free and keeps getting better. Found it useful? Support Triplicate ♥
Prefer no ads? Pro removes all ads · $1/month