In force now
RED / EN 18031
Since 1 August 2025 a radio product that can connect to the internet cannot be CE-marked for the EU without meeting cybersecurity essential requirements. This is the rule that already bites, two years before the CRA does.
What counts as radio equipment
Far more than people expect. Anything that transmits or receives radio and can connect to the internet, directly or through something else: wireless cameras, access-control readers, industrial sensors, drones, wearables, smart meters, connected medical and toy products. If it has Wi-Fi, Bluetooth, LTE or LoRa in it and it reaches a network, the delegated act applies. The three parts of EN 18031 map to three different concerns, and a product can be in scope of one part and not another.
The three parts of EN 18031
- Part 1 — network protection: the product must not be the way into the network
- Part 2 — personal data and privacy, for products that process it
- Part 3 — protection from fraud, for products handling money or crypto
What an assessment actually looks for
- No shared or default credentials across a production run
- A secure update mechanism, with signatures that are actually checked
- Encrypted communication, and certificate validation that is not switched off
- Exposed debug and service interfaces closed on the production build
- Secrets not readable off the flash with a programmer and an afternoon
THE DATES
Where this stands today
-
Delegated Regulation (EU) 2022/30 adopted
-
EN 18031 harmonised standards adopted
-
Cybersecurity requirements apply to new products
-
CRA applies in full and takes over
What to do about it
- Decide which parts of EN 18031 apply, per product rather than per catalogue
- Test against the standard before the notified body does, not after
- Fix the findings in firmware, where they are cheap, rather than in a recall
- Carry the evidence forward — the CRA will ask for the same things and more
- Ask the same questions of the modules you buy in: their weakness becomes yours
What it costs to get wrong
There is no turnover-percentage fine here. The sanction is market access: a market surveillance authority can require the product to be brought into conformity, restrict its sale, order a withdrawal or a recall, and the CE marking cannot lawfully be affixed without the assessment. For a manufacturer that is a harder outcome than a fine, because it arrives with the stock already built.
WHAT WE DO ABOUT IT
The services that close this gap
Not the whole catalogue — these are the ones that map onto the obligations above. If something here is already covered internally, say so and we will scope around it.
Penetration testing
A real attack, run by people who have done it for a living, ending in a report your engineers can act on and your auditor will accept.
Read more VMVulnerability management
Continuous discovery, prioritised by what is actually reachable and actually exploited — not by a scanner dumping ten thousand findings on your team.
Read more IoT / OTIoT and OT security
Cameras, controllers and machines that shipped with no security and cannot be patched. We segment them, watch them and stop them talking to strangers.
Read moreNot sure whether RED / EN 18031 applies to you?
Tell us your sector, your headcount and what you sell. We will tell you which regimes catch you and what the first three things to do are — in writing, at no charge, because half the organisations that ask turn out not to be in scope and we would rather say so.