EUREP

RED cybersecurity requirements and EN 18031

Stefan Hülsiggensen

9 min read

RED cybersecurity requirements since August 2025: which devices are covered, when a notified body is needed despite EN 18031, and what the CRA changes.

Technician connecting a network cable to a small white wireless energy gateway on a grey test bench

You build a Wi-Fi inverter, a connected toy or a smartwatch outside the EU and want to sell it in Europe. Since 1 August 2025, RED cybersecurity requirements apply to devices like these: Delegated Regulation (EU) 2022/30 activates three essential requirements of the Radio Equipment Directive 2014/53/EU (RED). Here is how to check whether your device is covered, when EN 18031 lets you assess it yourself, and what changes on 11 December 2027.

What the RED cybersecurity requirements are

Article 3(3) RED contains essential requirements that apply only to categories the Commission names in a delegated act. Delegated Regulation (EU) 2022/30 (opens in a new tab) does this for three of them: the device must not harm the network or misuse network resources (point (d)), must protect personal data and privacy (point (e)) and must support protection from fraud (point (f)).

The Delegated Regulation applies directly in every member state from 1 August 2025 (Article 3, as amended by Delegated Regulation (EU) 2023/2444) and covers the whole device, radio and non-radio parts alike (Recital 8).

Which devices are covered, and which are not

Who must meet which requirement (Article 1 of Delegated Regulation (EU) 2022/30; Implementing Decision (EU) 2025/138)
RequirementApplies toHarmonized standard
Network protection, point (d)All internet-connected radio equipmentEN 18031-1:2024
Personal data and privacy, point (e)Internet-connected radio equipment, childcare equipment, radio toys and wearables, if they can process personal data, traffic data or location dataEN 18031-2:2024
Fraud protection, point (f)Internet-connected radio equipment that lets the user transfer money, monetary value or virtual currencyEN 18031-3:2024
Who must meet which requirement (Article 1 of Delegated Regulation (EU) 2022/30; Implementing Decision (EU) 2025/138)

Toys, childcare devices and wearables are the exception to the internet test: a radio toy under Directive 2009/48/EC, a child monitor or a fitness wristband that can process personal data must meet point (e) even without an internet connection (Article 1(2), Recital 12).

Medical and in vitro diagnostic devices (Regulations (EU) 2017/745 and (EU) 2017/746) are exempt from all three requirements, radio equipment under the vehicle type-approval, aviation or road toll rules from points (e) and (f) only (Article 2).

Bluetooth, Zigbee and other local radios

The radio technology does not decide. In its non-binding interpretation (opens in a new tab) of 1 February 2026, ADCO RED, the market surveillance authorities' group for radio equipment, lists Bluetooth headphones, a standalone Zigbee light bulb and a standalone NFC door lock as not internet-connected, but a hotel door lock system using NFC and any radio product with a LAN port as internet-connected.

If you conclude that your device is not internet-connected, ADCO RED expects your risk assessment to show that it cannot communicate with the internet or be accessed from it. Record this in the technical documentation.

EN 18031 and its restrictions: when a notified body is needed

Implementing Decision (EU) 2025/138 (opens in a new tab), published in the Official Journal on 30 January 2025, listed EN 18031-1, -2 and -3:2024 as harmonized standards with restrictions. Applying them gives a presumption of conformity (Article 16 RED), except:

  • Passwords: in all three parts, if the user is allowed not to set and use any password (clauses 6.2.5.1 and 6.2.5.2).
  • Parental control: in EN 18031-2, for radio toys and childcare equipment, if parental or guardian access control is not ensured.
  • Secure updates for payments: in EN 18031-3, the assessment criteria of clause 6.3.2.4, in every case.
  • Informative text: the sections named rationale and guidance never count.

Under Article 17 RED, module A (internal production control, Annex II) is enough only with the listed standards applied in full. Otherwise, including with a restricted option, a notified body must be involved: EU-type examination (Annex III) or full quality assurance (Annex IV), Article 17(4). The Commission's guidance on EN 18031 (opens in a new tab) confirms this and states that a third-party assessment is mandatory wherever clause 6.3.2.4 applies.

What to do, step by step

  1. Classify each model against Articles 1 and 2 of the Delegated Regulation and write down why.
  2. Apply EN 18031-1, -2 or -3 in full and outside the restrictions to use module A; otherwise involve a notified body under Annex III or IV.
  3. Update the EU declaration of conformity with the standards and any notified body certificate (Annex VI RED); keep it with the technical documentation for 10 years (Article 10(4)).
  4. Secure your EU economic operator and put its name and postal address on the product, packaging, parcel or an accompanying document (Article 4(1) and (4) of Regulation (EU) 2019/1020).

Practical example: a Wi-Fi hybrid inverter from Asia

An Asian maker of residential hybrid inverters, a typical renewable energy product, builds a Wi-Fi module into each unit. The inverter sends production data to the owner's cloud account, which holds name and installation address; installers commission it through a local web interface.

RED cybersecurity check for the example inverter
QuestionResultBasis
Radio equipment?Yes, as combined equipment with a built-in Wi-Fi moduleADCO RED, case 6
Point (d)?Yes, it reaches the cloud through the owner's routerArticle 1(1)
Point (e)?Yes, it transmits data linked to an identifiable ownerArticle 1(2)(a)
Point (f)?No, it has no payment functionArticle 1(3)
RED cybersecurity check for the example inverter

The web interface works without a password if the installer sets none, so EN 18031 gives no presumption. Instead of involving a notified body, the maker changes the firmware to require a password at commissioning and applies EN 18031-1 and -2 in full under module A.

A radio toy is different: a Bluetooth robot that records the child's voice falls under point (e) with or without internet, and EN 18031-2 gives a presumption only with parental or guardian access control.

From 11 December 2027: the Cyber Resilience Act takes over

The Cyber Resilience Act (opens in a new tab) (Regulation (EU) 2024/2847, CRA) covers products with digital elements that connect to a device or network (Article 2(1)), and its essential requirements include all elements of points (d), (e) and (f) RED. Delegated Regulation (EU) 2026/339 (opens in a new tab), published on 29 April 2026, therefore repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, when the CRA applies in full (Article 71(2) CRA). Placing on the market counts per unit:

  • Placed on the market from 1 August 2025 to 10 December 2027: RED requirements; authorities can still check these units after the repeal (Recital 5 of Delegated Regulation (EU) 2026/339).
  • Placed on the market from 11 December 2027: CRA requirements; earlier units only if substantially modified from that date (Article 69(2) CRA).
  • From 11 September 2026: manufacturers must report actively exploited vulnerabilities and severe security incidents, with an early warning within 24 hours, also for products placed on the market before 11 December 2027 (Articles 14, 69(3) and 71(2) CRA).

EU-type examination certificates on cybersecurity issued under other EU legislation, such as the RED, remain valid until 11 June 2028 unless they expire earlier (Article 69(1) CRA).

Common mistakes with RED cybersecurity

  • Relying on a certified radio module. The requirements cover the finished device (Recital 8).
  • Keeping a skip-password option with module A. The restriction removes the presumption.
  • Forgetting toys and wearables without internet. Point (e) applies anyway.
  • Waiting for the CRA. Units placed on the market until 10 December 2027 stay under the RED rules.

Conclusion: classify per device and fix the restrictions early

The RED cybersecurity requirements turn on three questions: does the device reach the internet, can it process personal data (toys, childcare devices and wearables even offline), and can it move money? Answer them per model and design out the EN 18031 restrictions. Our wireless devices page covers the other RED duties.

Under Article 11 RED, an Authorized Representative acts under a written mandate; the design and manufacturing obligations and drawing up the technical documentation stay with you. As your EU Authorized Representative, Representa keeps the declaration and technical documentation for 10 years, handles authority inquiries and provides its name and address, within the agreed scope and mandate (see the role of an economic operator). Our CE marking support identifies the applicable standards, coordinates testing and reviews your technical documentation; we are not a notified body, and you remain the manufacturer. The CRA also allows an authorized representative (Article 18).

Frequently asked questions

Does EN 18031 apply to Bluetooth devices?

The underlying RED requirements apply only if the device can communicate over the internet, directly or via other equipment, or if it is a radio toy, childcare device or wearable that can process personal, traffic or location data. ADCO RED lists plain Bluetooth headphones as not internet-connected, but as wearables they fall under Article 3(3)(e) RED if they can process such data.

Do I need a notified body for RED cybersecurity?

Not if you apply EN 18031-1, -2 or -3 in full and your device is not affected by the restrictions in Implementing Decision (EU) 2025/138. If users can skip setting a password, a toy or childcare device lacks parental or guardian access control, or clause 6.3.2.4 of EN 18031-3 applies, a notified body must be involved under Annex III or IV (Article 17(4) RED).

Do the RED cybersecurity rules apply to units already on the market?

Only units placed on the market from 1 August 2025, the date set by Delegated Regulation (EU) 2023/2444. Placing on the market counts per unit, not per model: new units of an older model must comply, units placed on the market before that date need not.

When does the Cyber Resilience Act replace the RED cybersecurity rules?

On 11 December 2027. Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30 with effect from that date, when Regulation (EU) 2024/2847 applies in full. Units placed on the market before then remain subject to RED market surveillance. CRA reporting duties apply from 11 September 2026.

Are connected toys and children's wearables treated differently under the CRA?

Yes. From 11 December 2027, internet-connected toys with social interactive or location tracking features, wearables intended for children and baby monitoring systems are important products of class I (Annex III to Regulation (EU) 2024/2847). Without harmonized standards, common specifications or certification schemes applied in full, they need a notified body (Article 32(2)).

More insights

Apply this to your product

Talk to our team: we identify which of these requirements apply to you.