- Services
- Industries
- Automotive
- Battery
- Building inspection
- Fire alarms system testing
- Household appliances
- Installation materials
- Industrial machinery
- IT & audio video
- Laboratory, test & measurement
- Lighting equipment
- Maritime, oil & gas
- Medical & healthcare equipment
- Military & aerospace product testing
- Wireless & telecom
- Resources
- About
- Blog
- Events
February 2, 2025
Cybersecurity in Europe - EN 18031 is now a harmonized standard
Written by: Geir Hørthe
On January 30, 2025, the European Commission officially listed the EN 18031 series in the Official Journal (OJ) of the European Union under the Radio Equipment Directive (RED). This marks a significant development for manufacturers of radio equipment, as these standards address cybersecurity requirements that will become mandatory from August 1, 2025.
Background on EN 18031 and the RED Cybersecurity Requirements
The Radio Equipment Directive requires that radio equipment sold within the EU must meet essential requirements related to safety, electromagnetic compatibility, and efficient spectrum use. In 2022, the Commission introduced also cybersecurity requirements under Article 3(3):
- Article 3(3)(d): Protection against network harm and service degradation
- Article 3(3)(e): Safeguards for personal data and user privacy
- Article 3(3)(f): Measures to prevent fraud in radio equipment handling virtual currency
OJ Listing and Its Restrictions
With the listing of EN 18031 in the OJ, manufacturers can now use these standards to claim presumption of conformity with RED’s cybersecurity requirements. However, this listing comes with certain restrictions, which must be carefully considered when implementing compliance strategies. These restrictions relate to:
- The sections “rationale” and “guidance”
- Use of password
- Parental or guardian access control
- Transfer of monetary value
Implications for Manufacturers
As the cybersecurity requirements of the RED are mandatory from August 1, 2025, manufacturers must act promptly to align their products with the new requirements. Key steps include:
- Review the RED scope: Does your product come into the scope of the cybersecurity requirements of RED? A Notified Body like Nemko may assist determining the relevance for your product.
- Review the EN 18031 Series: Understand how these standards apply to your products and any restrictions affecting their use.
- Conduct a Compliance Gap Analysis: Assess your current cybersecurity measures against EN 18031 requirements.
- Engage with a Notified Body: Both because the EN 18031 is a new standard (published only in August 2024) and the restrictions on EN 18031, consulting with a Notified Body remains important to ensure full compliance and is a requirement if having solutions alternative to the letter of the standard.
- Prepare for Market Readiness: Implement necessary changes in design, testing, and documentation to meet the August 2025 deadline. A RED Notified Body certificate will be a good way to demonstrate compliance in the market.
Conclusion
The listing of the EN 18031 series in the Official Journal provides much-needed clarity for manufacturers navigating RED’s cybersecurity requirements. However, the accompanying restrictions highlight the need for careful evaluation and expert guidance. As a Notified Body, we are here to support manufacturers in interpreting these requirements, conducting assessments, and ensuring their products meet all regulatory obligations before the compliance deadline.
For further guidance or to discuss your product’s certification process, contact us today.
Book a free online meeting with one from our cybersecurity team.
If you want to read more about what Nemko does to secure your everyday cyber life - see our cyber security pages.
Tags:
Cyber security
Geir Hørthe
Geir Hørthe is responsible for the Nemko cyber security initiative. He has worked at Nemko for more than 30 years, in the capacity of test services, lab manager of safety, ATEX and medical departments. He has also been Managing Director at the Nemko office in London for two years. After he returned to Norway, he held...
Other posts you might be interested in
Uncovering 28,000 New Vulnerabilities: The Importance of Vulnerability Scans
November 10, 2023
//
Cyber security
The Dark Side of QR Codes: Risks and How to Stay Safe
November 2, 2023
//
Cyber security
Balancing In-House & External IT Security: The Hybrid Approach
November 20, 2024
//
Cyber security