HomeBlog › Cybersecurity

EN 18031: EU Cybersecurity for Connected Radio Equipment

Since 1 August 2025, Wi-Fi, Bluetooth and IoT devices sold in the EU must meet cybersecurity requirements. Here is what is actually in scope.

Cybersecurity2026-09-02

What changed

The Radio Equipment Directive was extended by a delegated regulation adding cybersecurity, privacy and fraud-protection requirements to Article 3.3. These became applicable on 1 August 2025, and the harmonised standard used to demonstrate conformity is EN 18031, published in three parts: Part 1 for network protection, Part 2 for privacy protection and Part 3 for fraud protection.

Which products are affected

The requirements apply to radio equipment — so any product with Wi-Fi, Bluetooth, cellular or other radio interface — that can communicate over a network or process personal data. In practice: smart home devices, connected appliances, wearables, IoT sensors and gateways, network cameras, smart toys and similar hardware.

The three parts in practice

Part 1 — Network protection

The device must not harm the network it joins, and must resist unauthorised access. Expect questions about authentication, default credentials, update mechanisms and exposed services.

Part 2 — Privacy protection

Personal data and traffic data must be protected. Expect questions about encryption in transit and at rest, data minimisation and how data is deleted on reset.

Part 3 — Fraud protection

The device must resist being used to commit fraud. This mainly concerns devices handling payments or value, but it also covers abuse of network resources.

How to prepare

  1. Document the device's network interfaces and data flows.
  2. Confirm unique per-device credentials and a secure update path.
  3. Verify encryption for stored and transmitted personal data.
  4. Record the assessment, the measures implemented and the rationale in the RED technical file.

This is primarily a documentation and design-review exercise supported by targeted testing, not a penetration test. Manufacturers who treat it as paperwork at the end of a project are the ones who get caught out.

Frequently Asked Questions

When did EN 18031 become applicable?

The cybersecurity requirements under the Radio Equipment Directive became applicable on 1 August 2025, with EN 18031 as the harmonised standard used to demonstrate conformity.

Which products does it apply to?

Radio equipment that connects to a network or processes personal data — including Wi-Fi and Bluetooth devices, IoT hardware, smart home equipment, wearables and connected toys.

Is penetration testing required?

Not in the usual sense. Conformity is demonstrated through a design and documentation assessment against the three parts of EN 18031, supported by targeted testing where relevant, with the evidence kept in the technical file.

Get a Quote for Your Product

Send your product spec and target market — we reply with scope, timeline and cost within one business day.

Email Mr. Tao
Tel / WhatsApp: +86 199-2684-3993 · WeChat: tao19926843993

Beice Testing · CNAS L10966 · CMA 92 · NTEK Group Partner Lab · Shenzhen, China

+86 199-2684-3993 · taowushuang@ntek.org.cn · 中文站