What is EN 18031?
EN 18031 is a European series of three harmonised standards that manufacturers use to demonstrate that wireless equipment meets the cybersecurity requirements of the Radio Equipment Directive (RED, 2014/53/EU), which have been mandatory since 1 August 2025. Those requirements were activated by Delegated Regulation (EU) 2022/30. Anything with Wifi, Bluetooth, LTE-M, LoRaWAN or another radio interface that can communicate with the internet is in scope: from smart sensors and IIoT gateways to wireless HMI panels.
ποΈ When do the RED cybersecurity requirements apply?
| Date | Milestone |
|---|---|
| 12 January 2022 | Delegated Regulation (EU) 2022/30 published |
| 28 January 2025 | EN 18031-1, -2 and -3 cited in the Official Journal (with restrictions) |
| 1 August 2025 | Requirements mandatory for new radio equipment on the EU market |
| 11 December 2027 | 2022/30 is repealed; the Cyber Resilience Act takes over |
π§ What parts does EN 18031 consist of?
| Standard | RED article | Subject |
|---|---|---|
| EN 18031-1 | 3(3)(d) | Network protection: equipment must not harm or misuse the network |
| EN 18031-2 | 3(3)(e) | Protection of personal data and privacy (GDPR) |
| EN 18031-3 | 3(3)(f) | Protection against fraud in payments or money transfers |
Each part works with security mechanisms such as authentication, secure storage, encrypted communication, logging, secure updates and resilience against denial of service. For each mechanism the standard provides a decision tree: is it needed, and if so, is the implementation adequate?
β οΈ What restrictions apply?
The European Commission published the standards with restrictions. The best-known point: the standards allow a user to set no password at all. Manufacturers who use that option get no presumption of conformity for that part and must have the assessment carried out by a notified body. In practice this means: no default passwords and no devices without a password.
π What does this mean for OT and industry?
- Wireless field devices β WirelessHART gateways, IO-Link Wireless masters and LoRaWAN sensors with an internet connection
- Remote service modems β 4G routers for remote maintenance of machines
- Machines with built-in radio β the machine builder must be able to show that the radio module meets EN 18031
For asset owners the standard is a useful purchasing criterion: ask about EN 18031 conformity when buying new wireless equipment, and combine it with the supplier assessment from IEC 62443-2-4.
π How does EN 18031 relate to the CRA and IEC 62443?
| RED + EN 18031 | Cyber Resilience Act | IEC 62443 | |
|---|---|---|---|
| Scope | Internet-connected radio equipment | All products with digital elements | Industrial automation (IACS) |
| Status | Mandatory since 01-08-2025 | Fully mandatory from 11-12-2027 | Voluntary standard |
| Lifecycle | At market placement | Including vulnerability handling and updates | Development, integration and operation |
If you already develop according to IEC 62443-4-1 and IEC 62443-4-2, you cover a large part of the EN 18031 mechanisms.
π οΈ How do you demonstrate conformity with EN 18031?
- Define the scope β can the device communicate with the internet via a radio interface, directly or through a gateway? Does it process personal data or monetary transactions?
- Select the relevant parts β part 1 almost always applies; part 2 for personal data; part 3 for payment functions
- Map the assets β which network, security and privacy functions and which sensitive parameters does the device have?
- Walk through the decision trees for each security mechanism and document why a mechanism is or is not needed
- Test and substantiate β technical documentation, test results and the rationale per requirement
- Choose the route β self-assessment when applying the standard in full without the restricted options, otherwise via a notified body
| Situation | Conformity route |
|---|---|
| Standard fully applied, no βno passwordβ option | Self-assessment (module A) |
| Standard applied partially or with restricted options | Notified body (module B+C or H) |
| No harmonised standard used | Notified body |
β Frequently asked questions
Which devices does EN 18031 apply to?
EN 18031 applies to radio equipment that can communicate with the internet, directly or through other equipment, and to equipment that processes personal data or financial transactions. Examples include Wi-Fi and Bluetooth devices, smart sensors, IIoT gateways, 4G routers, wearables and toys with radio.
Is EN 18031 mandatory?
The cybersecurity requirements of the Radio Equipment Directive have been mandatory since 1 August 2025. The EN 18031 standard itself is voluntary, but applying it in full gives a presumption of conformity. In practice EN 18031 is therefore the standard route to meeting the requirements.
What happens to EN 18031 when the Cyber Resilience Act applies?
On 11 December 2027 Delegated Regulation (EU) 2022/30 is repealed and the cybersecurity requirements for radio equipment move to the Cyber Resilience Act. Equipment placed on the market between 1 August 2025 and 11 December 2027 must continue to meet the RED requirements. Many EN 18031 measures also help with the CRA.
What are the restrictions on EN 18031?
The European Commission published EN 18031 with restrictions. The main point is that the standards allow a user not to set a password. Manufacturers who use that option get no presumption of conformity and must involve a notified body. Some options around parental controls and payment functions are restricted too.
Does EN 18031 apply to industrial machinery?
EN 18031 applies to the radio equipment inside a machine, such as a built-in Wi-Fi, Bluetooth or 4G module that can communicate with the internet. The machine builder must be able to show that this radio module meets the requirements, for example with a declaration of conformity from the module supplier.
π In summary
EN 18031 is the harmonised standard for the cybersecurity requirements of the Radio Equipment Directive, which have applied to all internet-connected wireless equipment since 1 August 2025. The requirements are a stepping stone towards the Cyber Resilience Act, which replaces them on 11 December 2027.
