EN 18031 Cybersecurity Testing for the Radio Equipment Directive (RED)

Cyber threats targeting connected devices have become a stark reality for every industry, and the radio equipment sector is no exception. With more products incorporating wireless capabilities, manufacturers are under increasing pressure to prove their devices are cyber-secure before placing them on the European market.

To address these concerns, the European Commission published Delegated Regulation 2022/30/EU under the Radio Equipment Directive (RED), setting forth specific cybersecurity requirements for radio devices. Come August 1, 2025, these new requirements will be in full force.

Thus, if you produce or sell radio-enabled equipment in the EU, you must ensure your devices are protected against cyber risks, ranging from network threats to privacy violations and even monetary fraud.

Scope of EN 18031 Cybersecurity Testing

EN 18031 is a newly published series of European cybersecurity standards designed to address the Radio Equipment Directive’s (RED) cybersecurity requirements. Its main goal is to ensure that radio devices are designed with security measures that are strong enough to defend against known and emerging cyber threats.

  • Core Objective: Strengthen device security by protecting network resources, user privacy, and monetary transactions.
  • Key Stakeholders: Manufacturers, integrators, retailers, and compliance teams all have a vested interest in adopting EN 18031. Failing to align with these standards can lead to regulatory hurdles and broader reputational risks if security incidents occur.

EN 18031 Cybersecurity at Its Core

EN 18031 is tailored to help products comply with the RED’s cybersecurity provisions, focusing on:

  • Network Protection (avoiding negative impacts on wireless networks or misuse of resources),
  • Privacy Protection (guarding personal data and user confidentiality), and
  • Monetary Fraud Prevention (addressing secure transactions and payment flows).

Implications for the Industry

By following EN 18031’s guidelines, manufacturers can:

  • Demonstrate Compliance: Avoid lengthy third-party certification if no restricted clause is triggered.
  • Establish Trust: Show regulators and consumers that products are designed with security in mind.
  • Reduce Fraud & Risk: Standardized controls, such as strong password enforcement or secure update mechanisms, mitigate potential cyberattacks that lead to data breaches or financial loss.

Ultimately, EN 18031 is more than a checkbox exercise. Implemented correctly, it pushes organizations to design, test, and maintain safer radio-equipped devices, benefiting not just compliance efforts but also long-term security and brand reputation.

RED Cybersecurity: EN 18031-1, -2, and -3 Explained

EN 18031-1: Network Protection

Ensures radio equipment doesn’t harm network infrastructure or misuse resources. Includes secure boot, encrypted communications, and strong access controls. If devices allow skipping passwords, manufacturers lose the presumption of conformity and require Notified Body involvement.

EN 18031-2: Privacy Protection

Secures personal data in IoT devices, wearables, and smart home products through privacy-by-design, limited data exposure, and parental controls for children’s data. Not implementing required parental controls triggers restrictions and mandates Notified Body review.

EN 18031-3: Monetary Fraud Prevention

Applies to devices handling payments, like point-of-sale terminals or e-wallets. Requires secure update mechanisms—no single measure is enough. Manufacturers unable to show enhanced security lose the presumption of conformity.

Achieving EN 18031 Compliance

Under EN 18031, radio devices must meet specific security benchmarks. These benchmarks include password enforcement, network protection, privacy safeguards, and fraud prevention. Penetration testing (pen testing) is an effective way to:

  • Expose Vulnerabilities Early
  • Validate Compliance Requirements
  • Demonstrate Due Diligence

Step 1: Gap Analysis

The first step is to evaluate your current security posture against EN 18031 requirements:

  • Initial Assessment: Evaluate existing device designs, firmware security, and authentication against EN 18031.
  • Documentation Review: Inspect policies, processes, and code repositories for nonconformities.
  • Restrictions Check: Identify any restricted clauses (e.g., password skipping). If triggered, a Notified Body becomes mandatory.

Step 2: Implementation and Development

Once you’ve identified gaps, it’s time to integrate security controls throughout the product lifecycle:

  • Technical Controls: Enforce strong cryptography, mandatory passwords, secure boot, and encrypted updates.
  • Policies and Processes: Enhance your secure SDLC, patch management, and incident response procedures.
  • Team Collaboration: Engage engineering, product, and compliance functions early, especially if your device handles financial data or requires parental controls.

Step 3: Validation and Testing

After implementing the necessary controls, verify their effectiveness through targeted testing and compliance checks:

  • Penetration Testing: Confirm real-world resilience, mapping vulnerabilities to relevant EN 18031 clauses.
  • Functional Testing: Ensure new security measures don’t break user flows or device performance.
  • Compliance Checks:
    • Self-Assessment: If no restricted clauses apply, sign a Declaration of Conformity.
    • Notified Body: If restricted clauses are triggered, involve a Notified Body for a formal conformity assessment.

Applus+ Laboratories Provides Accredited EN 18031 Testing

Implementing the EN 18031 standards in full enables a faster, more cost-effective self-assessment route. Furthermore, pen testing remains essential, mapping real-world attack scenarios to each requirement and pinpointing places where additional safeguards are needed.

If you’re interested in discussing how Applus+ can assist you with your cybersecurity testing needs, contact us!