What EN 18031 Actually Is
EN 18031 is not a standalone regulation. It is a harmonised standards series that translates three essential requirements of the European Radio Equipment Directive, or RED, into technical practice. Its legal basis is Commission Delegated Regulation (EU) 2022/30, which defines which products these requirements apply to.
The series consists of three parts, each addressing a different provision of Article 3(3) of the Radio Equipment Directive:
- EN 18031-1 specifies network protection under Article 3(3)(d) — protection against harm to networks or network services.
- EN 18031-2 specifies the protection of personal data and privacy under Article 3(3)(e).
- EN 18031-3 specifies fraud protection under Article 3(3)(f), relevant for devices that enable monetary transfers.
Since 1 August 2025, compliance with these three standards establishes a presumption of conformity with the corresponding RED requirements. In practice, this means manufacturers who apply EN 18031 can rely on it as evidence that the relevant legal requirement is met, without needing to demonstrate it separately through other technical means.
Who This Affects
Delegated Regulation (EU) 2022/30 defines the scope precisely — and more broadly than many manufacturers initially assume. It covers, in principle, any internet-connected radio equipment: any device capable of communicating over the internet, whether directly or through another device.
Directly Affected Product Categories
- Connected consumer electronics and smart-home devices
- Wi-Fi routers, connected televisions, and smart speakers
- Mobile phones, tablets, and laptops with radio interfaces
- Childcare equipment, toys, and wearables with internet access
- Industrial IoT sensors and controllers with online connectivity
- Payment terminals and devices enabling monetary transfers
The indirect-connection clause is particularly important: devices that are not themselves directly connected to the internet, but communicate through another device — such as a sensor transmitting via a gateway — also fall under the definition of "internet-connected radio equipment." This is especially relevant for components and subassemblies that are not perceived as end products themselves but form part of a connected architecture, such as cellular modems, routers, and data-acquisition units in cabinets and metering rooms.
Not every one of the three sub-requirements automatically applies to every device. Fraud protection under EN 18031-3, for example, only applies if the device actually enables monetary transfers; protection of personal data under EN 18031-2 only applies if the device processes such data.
Why the Date Matters So Much
1 August 2025 is not a symbolic milestone. It marks an immediately enforceable legal obligation with no transition period. Unlike the Cyber Resilience Act, whose main requirements only take full effect on 11 December 2027, or NIS2, whose scope depends on national transposition, EN 18031 has already been in force for more than a year.
This timing gap has a critical consequence: companies that plan their compliance efforts exclusively around the 2026 and 2027 CRA deadlines risk overlooking an obligation that already applies today. Anyone developing an internet-connected device today and waiting for "CRA 2027" has already missed the deadline that actually matters.
What Happens Next: The Bridge to the CRA
Delegated Regulation (EU) 2022/30, the legal basis for EN 18031, will be phased out in favour of the CRA. On 16 February 2026, the European Commission adopted a Delegated Regulation repealing the RED Delegated Regulation with effect from 11 December 2027. Until that date, Delegated Regulation (EU) 2022/30 remains in force, and EN 18031 continues to be the relevant path for demonstrating RED-related cybersecurity compliance.
For manufacturers, this means: products placed on the market before 11 December 2027 can still be assessed and documented under EN 18031. After that date, the CRA takes over the corresponding requirements for products with digital elements.
EN 18031, the CRA, and NIS2 Compared
| EN 18031 / RED | Cyber Resilience Act (CRA) | NIS2 | |
| Legal basis | Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive | Regulation (EU) 2024/2847 | Directive, transposed nationally |
| In force since | 1 August 2025, no transition period | In force since 10 December 2024; reporting obligations from 11 September 2026; full application from 11 December 2027 | Varies by member state; EU-wide transposition deadline has already passed |
| Who is affected? | Manufacturers of internet-connected radio equipment | Manufacturers, importers, and distributors of products with digital elements | Certain essential and important entities |
| What is the focus? | Network protection, protection of personal data, fraud protection | Secure-by-design, vulnerability management, technical documentation | Organisational cyber resilience, risk management, reporting processes |
| How is conformity demonstrated? | Applying EN 18031-1/-2/-3 establishes a presumption of conformity | Technical documentation, conformity assessment based on risk class | Appropriate security measures and demonstrable resilience |
| What happens afterwards? | Superseded by CRA requirements from 11 December 2027 | Becomes the binding framework for digital products | Runs in parallel, independent of product lifecycle |
EN 18031 is therefore not a substitute for the CRA or NIS2. It is the current technical answer to a specific part of the picture that the CRA will eventually absorb in full.
What Manufacturers Need to Demonstrate
The three parts of the standard translate into concrete technical mechanisms a device must implement:
- No reusable default passwords. Devices must not ship with factory-set credentials that are identical across every unit. A device that allows a user to skip setting or using a password fails to meet the network-protection requirement.
- Secure firmware update mechanisms. Updates must be authenticated and protected against tampering during installation.
- Protected storage of sensitive data. Personal data, credentials, and cryptographic material must be adequately secured.
These three mechanisms are not just conformity-assessment checkboxes. They are also the points where an audit or market-surveillance check most quickly reveals whether a product was genuinely developed and manufactured in a compliant way — and how reliably that evidence is documented across the supply chain.
The Connection to the Component Supply Chain
A device can be designed cleanly and still leave its conformity assessment exposed if the firmware actually loaded onto the physical component isn't traceably documented. For the requirements under EN 18031-1, it becomes relevant who loaded which firmware version onto which component, when, and how that handover was protected against tampering.
With btv SEEL®, btv can support technical evidence from the programming stage onward: through documented firmware transfers, traceable component assignment, and tamper-protected process documentation. Responsibility for the final product and its conformity assessment under RED or EN 18031 remains with the manufacturer.
What This Means for Different Industries
EN 18031 extends well beyond classic consumer electronics. It is especially relevant for:
- Telecommunications and networking: Routers, modems, and gateways fall directly under the network-protection requirement.
- Industrial automation: Connected sensors, controllers, and data-acquisition units with indirect internet connectivity are covered through the intermediary-device clause, even when they don't look like typical “internet devices.”
- Smart home and consumer IoT: From connected household appliances to security systems, this is where the scope is most directly visible.
- Payment terminals and financial technology: For devices enabling monetary transfers, fraud protection under EN 18031-3 also applies.
What Matters Now
The electronics-industry crisis of 2025 was not a single event. It made visible how strongly production capability depends on supply-chain transparency, component quality, and documented processes. Companies that organise these topics only once a shortage hits are reacting. Companies that structure them earlier retain options.