Skip to content
ReadinessNavigator

RED · Delegated Regulation (EU) 2022/30 · EN 18031

The cybersecurity the Radio Equipment Directive now makes mandatory

Since 1 August 2025, internet-connected radio equipment must meet the cybersecurity requirements of Article 3.3 (d), (e) and (f) of the Radio Equipment Directive before it can be CE-marked. The harmonised standard EN 18031 turns those three objectives into concrete security mechanisms — and much of the hardware it reaches is the same connected hardware the CRA already covers, so the sensible move is to evidence both from one body of work.

Why RED cybersecurity, now

A directive requirement with a hard date and a presumption of conformity

RED cybersecurity is not new law, but it became enforceable on 1 August 2025. From that date, radio equipment that connects to the internet — or processes personal data or virtual money — cannot be placed on the EU market unless it meets the applicable Article 3.3 objectives. For now this sits alongside the CRA — both can apply to the same product at once — but the arrangement is time-limited: Commission Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30 from 11 December 2027, the date the CRA becomes fully applicable, so the CRA takes over these cybersecurity requirements. Equipment placed on the market before then stays subject to the 2022/30 requirements; the RED itself continues to apply — only its cybersecurity route hands over to the CRA.

Meeting the harmonised standard EN 18031 gives a presumption of conformity with the RED cybersecurity requirements — the practical route most manufacturers take. EN 18031 comes in three parts (‑1 network protection, ‑2 personal data, ‑3 anti-fraud), each expressed as security mechanisms with decision trees that tell you which apply to your equipment.

EN 18031 carries notes in the Official Journal restricting the presumption of conformity in specific cases. This assessment scores your mechanism coverage against the standard; where a restriction may apply, it flags that the notified-body route, not self-assessment, is the safe path.

The three Article 3.3 objectives

What RED cybersecurity actually requires

RED delegates three cybersecurity objectives to connected radio equipment. Which ones apply depends on what your equipment does — network protection is near-universal, while the personal-data and anti-fraud objectives switch on with the relevant capability.

  • Art. 3.3 (d)

    Network protection

    The equipment must not harm the network or its functioning, and must protect itself against attacks that misuse network resources. Applies to essentially all internet-connected radio equipment — this is the objective that reaches the widest.

  • Art. 3.3 (e)

    Protection of personal data and privacy

    Where the equipment processes personal data or user traffic, it must safeguard the confidentiality and integrity of that data. Switches on for equipment handling personal data — the assessment asks this up front.

  • Art. 3.3 (f)

    Protection against fraud

    Where the equipment enables transfer of money or virtual value, it must protect against fraudulent use. Switches on for payment, wallet, and comparable value-transfer capability.

What EN 18031 scores against

Seven security mechanism families

EN 18031 expresses the three objectives as concrete security mechanisms. This assessment groups them into seven families and scores your implementation of each, so a percentage readiness score resolves into specific, fixable gaps rather than an abstract verdict.

  • Access control

    Network interfaces and services are protected so only authorised entities can reach them — the backbone of the (d) network-protection objective.

  • Authentication

    Users and connecting entities prove who they are, with no exploitable default credentials and adequate protection against brute-force attempts.

  • Secure update

    Software and firmware update over an authenticated, integrity-protected channel, so a device can be fixed after a vulnerability is found — the mechanism CRA vulnerability handling also depends on.

  • Secure storage

    Security parameters, keys, and personal data at rest are protected against reading or tampering by an attacker with access to the device.

  • Secure communication

    Data in transit — especially personal data under the (e) objective — is confidentiality- and integrity-protected across the network.

  • Resilience and logging

    The equipment resists resource-exhaustion attacks and records security-relevant events, so misuse of network resources can be detected and survived.

  • Cryptography and key management

    The cryptographic primitives and key lifecycle underpinning every other mechanism are sound — appropriate algorithms, proper key generation, storage, and renewal.

One evidence set, two frameworks

Most of your CRA work already answers EN 18031

Open the Cyber Resilience Act hub

The CRA and RED cybersecurity reach much of the same connected hardware, and they ask for overlapping evidence. Secure update, authentication with no default passwords, secure storage of keys, vulnerability handling — the artefacts that satisfy CRA Annex I Part I map directly onto EN 18031 mechanism families.

This assessment marks, family by family, where CRA evidence carries over to EN 18031 and where RED asks for something CRA does not. If you have already run the CRA readiness assessment, you will recognise most of what RED needs — the point is to close the remaining RED-specific gaps rather than start a second compliance project from scratch.

Get in touch

Work out what the Radio Equipment Directive expects on cybersecurity

The RED cybersecurity requirements (Article 3.3 d/e/f) apply to most connected radio products. Tell us what the product is and how it connects, and we will map which articles apply and what EN 18031 conformity would involve.

We reply within two working days.

Full contact details
consulting@readinessnavigator.com
Book a 30-minute call

Opens our scheduling page in a new tab — pick a slot that suits you.

Useful in a first message

  • What the product is, and how it connects — Wi-Fi, Bluetooth, cellular, or another radio.
  • Whether it handles personal data, payments, or child-accessible features, which decide 3.3 e and f.
  • Any date you are working towards — the requirements already apply to new placements on the market.

Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.