EN 18031 Under RED: Where Presumption of Conformity Is Limited

  News     |      2026-09-01 14:38

EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 are cited as harmonised standards supporting the cybersecurity-related essential requirements of the Radio Equipment Directive (RED). Their citation, however, includes formal limitations. Commission Implementing Decision (EU) 2025/138 makes clear that selected informative sections, assessment criteria and product configurations do not provide presumption of conformity.

As checked on 1 September 2026, EUR-Lex identifies 11 December 2025 as the current consolidated version of Commission Implementing Decision (EU) 2022/2191. The act remains in force and the three EN 18031 entries still carry their limitations. A technical file therefore needs more than a standard number: it should connect the product functions, clauses applied, implementation choices and evidence to the relevant RED requirement.

What presumption of conformity does—and does not—mean

Harmonised standards are a voluntary technical route under the RED. Correct use of a cited standard can provide presumption of conformity only for the essential requirements and technical areas that the cited provisions actually cover. It does not automatically address every RED requirement, every product risk or other EU product legislation.

Where an Official Journal notice limits a citation, the identified section, criterion or implementation cannot by itself deliver that presumption. The manufacturer still needs a product-specific risk assessment, suitable verification evidence and the applicable conformity-assessment procedure.

How the three parts map to RED requirements

  • EN 18031-1:2024 supports Article 3(3)(d) for internet-connected radio equipment and the protection of networks from harm or misuse.
  • EN 18031-2:2024 supports Article 3(3)(e) for relevant internet-connected equipment processing personal, traffic or location data, as well as qualifying childcare, toy and wearable radio equipment.
  • EN 18031-3:2024 supports Article 3(3)(f) for internet-connected radio equipment that enables transfers of money, monetary value or virtual currency.

Actual scope depends on the radio functions, internet communication path, data processing, payment capability and intended use of each product. Coordination or exclusions under Delegated Regulation 2022/30 and other applicable sector legislation must also be checked.

Four limitations that deserve a separate review

  1. Informative content. The “rationale” and “guidance” sections of all three standards do not confer presumption of conformity. They can explain the approach but cannot replace normative specifications and verification evidence.
  2. No-password implementations. For each of the three standards, applying clauses 6.2.5.1 and 6.2.5.2 in a way that allows a user not to set or use any password does not provide presumption for the corresponding essential requirement. Authentication design, default states, user choices and compensating controls need a focused review.
  3. Parental or guardian access control. For specified categories addressed by clauses 6.1.3 to 6.1.6 of EN 18031-2, the assessment criteria identified in the notice do not provide presumption if parental or guardian access control is not ensured.
  4. Secure-update assessment. The assessment criteria in clause 6.3.2.4 of EN 18031-3 do not confer presumption for Article 3(3)(f). Products handling monetary value or virtual currency require evidence proportionate to their update and fraud risks.

A limitation is not an automatic finding of non-compliance

The Official Journal notice limits the legal effect of relying on particular content in a harmonised standard. It does not declare every affected product non-compliant, nor does it withdraw EN 18031 as a whole. Conformity still turns on the product architecture, risk assessment, test results, technical documentation and the conformity-assessment procedure actually used.

Manufacturers should therefore avoid both extremes: “EN 18031 is invalid” and “an EN 18031 report guarantees compliance.” For each affected choice, record how the essential requirement is addressed, what additional evidence is needed and whether the selected conformity route creates specific third-party involvement requirements.

A practical evidence checklist

  1. Build a scope matrix by model. Record whether Articles 3(3)(d), (e) and (f) apply and why, based on connectivity, data, child-use, wearable and payment functions.
  2. Map standards to clauses and configurations. Identify the EN 18031 part, clauses, criteria, deviations and software version actually used rather than citing the standard only at document level.
  3. Review authentication paths. Capture factory defaults, first-time setup, password or alternative mechanisms, recovery and user instructions. Flag any configuration that permits no password at all.
  4. Verify access control. For relevant childcare, toy and wearable equipment, explain how a parent or guardian obtains, retains and recovers the necessary control.
  5. Strengthen update evidence. For equipment handling financial assets, document update authenticity and integrity, failure recovery, privilege control, vulnerability handling and version traceability.
  6. Freeze the regulatory reference. Keep the citation date, the applicable harmonised-standard list and its limitations in the technical file, then review changes as the product evolves.

How Qianxin can support readiness work

For a defined product, market and written scope, Qianxin can help identify applicable RED requirements and standard versions, map EN 18031 clauses to product functions, prepare testing and technical-documentation checklists, and review consistency across authentication, access-control, update and supply-chain records. Product classification, the final conformity decision, the applicable assessment procedure and notified-body involvement remain subject to the actual project.

This article provides general compliance information only. It is not product-specific legal advice or a final conformity assessment. Standards remain subject to their applicable copyright terms; this article describes public EU legislation and Official Journal notices without reproducing the standard text. Testing, reporting, certification and issuing activities depend on the project, relevant laboratory scope and written engagement.

Official Sources