Free service hotline
net04@gtggroup.com
TEL: 0769-85075888-6618
13925591357
Fax: 0769-85075898
Mail: net04@gtggroup.com
ADD: Huacan Industrial Park, No. 2 Keji 8th Road, Songshan Lake Park, Dongguan City, Guangdong Province
EN18031 Certification is the mandatory cybersecurity certification standard for radio equipment in the European Union. Since August 1, 2025, it has been formally incorporated into the Radio Equipment Directive (RED) harmonized standards system. This standard covers three core areas: network attack protection, personal data privacy, and financial transaction security. It serves as an essential "technical passport" for products entering the EU market.
The EN18031 series of standards was developed jointly by the European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC), and was officially included in the Radio Equipment Directive (RED) harmonized standards through EU Decision (EU) 2025/138. This standard is the world's first regulation to incorporate cybersecurity into mandatory CE marking certification, meaning wireless devices must meet cybersecurity requirements to obtain CE marking for the EU market.
The standards system is divided into three sub-standards, corresponding to different security dimensions:

According to EN18031 standard requirements, certification testing focuses on the following core security mechanisms:
Verifies whether the device implements hierarchical access control, ensuring that users with different permission levels can only access functions and data corresponding to their roles. Testing includes: clear permission hierarchy, restricted guest access, independent administrator accounts, and secondary verification for sensitive operations.
Verifies whether the device adopts strong identity authentication strategies, prohibiting the use of generic default passwords such as "admin/admin". Testing requirements include: mandatory password change upon first use, password complexity meeting length and character type requirements, recommended support for Multi-Factor Authentication (MFA), and effective login failure lockout mechanisms.
Verifies whether the device supports secure firmware update mechanisms. Standard requirements include: update packages must be verified through digital signatures, anti-rollback design (prohibiting downgrade to vulnerable versions), update process must maintain data integrity, and manufacturers must provide at least 2 years of security update support commitment.
Verifies the security of sensitive data during device storage. Core testing points include: sensitive data (such as location information, identity information, payment information) must be stored with AES-256 encryption, key management must comply with security specifications, sensitive areas must have tamper-proof physical protection, and encryption chips must have corresponding qualification certifications.

The EN18031 certification process is divided into three main stages, with different certification paths for different risk level devices:
Timeline Factors: Product complexity (connected devices require testing of 14 security mechanisms), documentation preparation efficiency, number of testing rounds (rework after failed first tests adds 1-2 months), and whether financial transaction functions are involved. It is recommended that companies start certification preparation 6 months in advance.

According to EU Decision (EU) 2025/138, certification materials must strictly match product risk levels:
EN 18031-1 Applicable Devices – Required: Cybersecurity risk assessment report, TLS 1.3 encryption protocol implementation description, security update strategy documentation.
EN 18031-2 Applicable Devices – Must additionally submit: Data Processing Impact Assessment (DPIA), parental control function description, sensitive data AES-256 encryption storage proof.
EN 18031-3 Applicable Devices – Must supplement: Hardware encryption chip qualification proof, tamper-proof transaction log design documentation, transaction traceability record 7-year retention proof.
Common basic documentation for all devices includes: Product technical specification, hardware/software Bill of Materials (BOM), vulnerability scan records. Non-EU companies also need to provide EU Authorized Representative (EC-REP) appointment documents.
Practical Advice: High-risk devices require third-party conformity assessment, with additional factory production security control documentation. It is recommended to select laboratories with both CNAS and EU recognition qualifications, which can reuse existing RF/EMC test data to shorten the overall timeline.
Q1: What is the relationship between EN18031 and CE-RED?
EN18031 is part of the CE-RED (Radio Equipment Directive) harmonized standards. After obtaining the EN18031 test report, companies need to integrate it with other test reports (RF, EMC, SAR, etc.) to form the technical documentation for CE marking certification.
Q2: Do Bluetooth speakers require EN18031 certification?
If Bluetooth speakers do not have cloud connectivity functions, do not store user data, and do not involve financial transactions, they can be classified as low-risk devices and follow the Self-Declaration route. However, if they have voice assistants, cloud synchronization, or other internet connectivity functions, they must meet EN 18031-1 requirements.
Q3: What are the main causes of certification failure?
Common failure reasons include: failure to disable default passwords or insufficient weak password policy, lack of digital signature verification for security update mechanisms, sensitive data not stored with AES-256 encryption, children's device parental control functions that can be bypassed, and financial devices lacking hardware encryption chips or unqualified certifications. Pre-testing before formal submission is recommended to identify and rectify issues in advance.
Q4: What are the certificate validity and maintenance requirements?
CE-RED certificates are valid for 5 years, but high-risk devices require annual surveillance audits by the Notified Body, with submission of security update implementation records. Failure to complete annual audits will result in suspension of certificate validity. Companies must continuously ensure products meet standard requirements during the 5-year certificate validity period.

EN18031 certification, as the EU's first mandatory cybersecurity standard for radio equipment, signifies a significant increase in compliance thresholds for wireless products entering the EU market. This standard not only requires products to have basic security functions but also emphasizes continuous security update capabilities and user data protection mechanisms.
For companies planning to export wireless products to the EU market, recommendations include: Start certification preparation early and determine the applicable sub-standard based on product functionality; Conduct security design reviews in advance to avoid fundamental design flaws leading to significant rework; Choose professional laboratories with CNAS and EU Notified Body qualifications to effectively shorten certification timelines; Establish continuous security update mechanisms to ensure products remain compliant throughout the 5-year certificate validity period.
EN18031 certification serves as the "technical passport" for products entering the EU market. Although the certification process involves technical documentation preparation, testing, and rectification, with assistance from professional organizations, companies can successfully complete compliance certification and gain broader development space in the EU market.
This article is AI-assisted generated for reference only and does not constitute any certification commitments or legal advice. Please refer to the latest official regulations for specific requirements.
Email: net04@gtggroup.com
Website: https://www.gtggroup.cn