← Back to insights

EN 18031, the RED Cybersecurity Rules, or the Cyber Resilience Act: What Does Each Product-Security Claim Mean?

Separate RED legal scope, the restricted EN 18031 presumption-of-conformity route and CRA lifecycle duties before accepting an “EU cyber compliant” product claim.

One EU product-security claim separates RED legal scope, EN 18031 evidence and CRA lifecycle duties
  1. 01RED answers which radio-equipment requirements apply
  2. 02EN 18031 answers how specified RED requirements may be evidenced
  3. 03The CRA answers a different product-lifecycle question
#EN 18031#Radio Equipment Directive#Cyber Resilience Act#Product Security

Signals to watch

  • A named connected product and software version are attached to an EU cybersecurity claim
  • The claim distinguishes RED essential requirements from an EN 18031 test or declaration and from CRA lifecycle duties
  • A conformity assessment, market launch, vulnerability-reporting or customer decision has an owner and date

EN 18031, the Radio Equipment Directive cybersecurity rules and the Cyber Resilience Act are not three competing certificates. RED establishes legal requirements for specified radio equipment; EN 18031 is one restricted harmonised-standard route to presume conformity with particular RED requirements; the CRA creates separate cybersecurity and lifecycle duties for products with digital elements. An “EU cyber compliant” claim must name which statement it means.

This is the source-routing problem facing a connected-product security analyst in authorized manufacturer, test-lab and product-compliance Telegram groups. The useful Signal is a product/version claim entering a launch or supplier decision without its legal scope and evidence object. Seeing it a day late can let the wrong declaration enter a customer file. Treating every EN 18031 test as CRA proof can be worse than having no shorthand at all.

The following are illustrative claim fragments, not real products or test results:

“EN 18031 passed, so the device is EU cyber compliant.”

“RED is done. CRA report also covered.”

Neither sentence names product functions, radio category, standard part, test scope, published restriction, conformity route, software version, CRA role or applicable date.

RED answers which radio-equipment requirements apply

The Radio Equipment Directive, Directive 2014/53/EU, contains essential requirements. Delegated Regulation (EU) 2022/30 makes Article 3(3)(d), (e) and (f) apply to specified classes or categories from 1 August 2025.

In simplified terms, those provisions address protection of networks and against service misuse, protection of personal data and privacy for specified equipment, and protection against fraud for specified internet-connected radio equipment processing virtual money or monetary value. Scope depends on the product’s radio and internet functions and the delegated act’s classes, categories and exclusions.

The evidence object is the manufacturer’s conformity assessment, technical documentation, EU declaration of conformity and associated testing—not a bare statement that a product contains Wi-Fi or Bluetooth.

EN 18031 answers how specified RED requirements may be evidenced

Implementing Decision (EU) 2025/138 cites:

  • EN 18031-1:2024 for common security requirements for internet-connected radio equipment under RED Article 3(3)(d);
  • EN 18031-2:2024 for radio equipment processing personal, traffic or location data, including specified childcare, toy and wearable radio equipment, under Article 3(3)(e); and
  • EN 18031-3:2024 for internet-connected radio equipment processing virtual money or monetary value under Article 3(3)(f).

Compliance with a cited harmonised standard can confer a presumption of conformity with the corresponding legal requirement. That presumption is not unlimited.

The Decision publishes the EN 18031 references with restrictions. “Rationale” and “guidance” sections do not confer the presumption. The notices also restrict the presumption for specified password choices, access-control implementations and secure-update criteria. An analyst therefore needs the applied clauses, product implementation and restrictions—not only a lab cover page saying “EN 18031.”

The CRA answers a different product-lifecycle question

The Cyber Resilience Act, Regulation (EU) 2024/2847, covers products with digital elements made available on the Union market, subject to its definitions and exclusions. It sets essential cybersecurity requirements and obligations for manufacturers and other economic operators across design, development, production, vulnerability handling and support.

The dates differ from RED. The CRA applies generally from 11 December 2027. Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. Chapter IV provisions on conformity-assessment bodies apply from 11 June 2026.

An EN 18031 report can contain relevant technical evidence, but it does not decide CRA product classification, support period, vulnerability-handling process, software bill of materials, reporting workflow or conformity route. SBOM means software bill of materials, an inventory of software components.

Use the same five questions for every claim

QuestionRED cybersecurityEN 18031CRA
What is it?EU radio-equipment legal requirementsHarmonised technical standards cited for specified RED requirementsEU regulation for products with digital elements
First scope factRadio equipment class, connectivity and data/payment functionApplicable part and clauses for that productProduct with digital elements, economic-operator role and exclusions
Evidence objectTechnical documentation, assessment and declarationTest/assessment against applicable clauses plus restrictionsLifecycle technical documentation, conformity route and operational records
Key dateApplicable from 1 Aug 2025Citation decision published in 2025; use current OJ statusReporting 11 Sep 2026; general application 11 Dec 2027
Cannot prove aloneCRA conformity or all product cybersecurityLegal scope, unrestricted presumption or CRA complianceRED radio scope or EN 18031 test result

The table routes evidence; it does not replace a product-specific legal assessment.

One product can need both routes without reusing one conclusion

An internet-connected radio product can be radio equipment under RED and a product with digital elements under the CRA. That overlap does not make one assessment file a universal answer.

Build a requirement cross-reference for the exact model and software version. One column names the RED essential requirement and applicable EN 18031 clauses and notices. A second column names the CRA requirement, economic-operator duty, evidence owner and application date. Link shared technical artifacts—such as authentication tests or update design—without copying the RED conclusion into the CRA status field.

Version control matters. A lab report may describe firmware tested before a later vulnerability-handling process or security update was introduced. Record model, hardware revision, firmware/software version, test date, applicable standard edition and the declaration or lifecycle record that consumes the evidence. A product name without that version boundary cannot support a current launch claim.

Rewrite “EU cyber compliant” into a verifiable sentence

A useful note looks like this:

For product model and software version X, the manufacturer applies EN 18031-1:2024 to the specified RED Article 3(3)(d) requirements, with the Implementing Decision restrictions reviewed; the EU declaration and technical file remain to be checked. CRA scope, Article 14 reporting readiness and 2027 conformity are separate and unverified.

That statement names a product, standard part, legal requirement, restriction and unknown. If the group cannot supply those fields, the claim stays in source review.

For CRA reporting operations, use the CRA workflow article. The WCAG, EN 301 549 and VPAT article shows a different law-standard-procurement distinction. If the evidence is only a screenshot, recover it with the official-source ladder.

TOP Prospect can connect incomplete fragments from groups the user deliberately connects and may access, preserve source and time, remove obvious duplicates and rank the claim for human review. It cannot inspect a product, validate a standard test, determine legal scope, issue a declaration or report a CRA vulnerability. The pricing page describes the discovery boundary.

Choose the record by the sentence being claimed: RED for the applicable radio-equipment requirement, EN 18031 for the bounded standards evidence, and CRA for the product-lifecycle obligation. Do not ask one document to prove all three.

Frequently asked questions

Is EN 18031 an EU law?

No. EN 18031 is a family of harmonised European standards cited for specified RED cybersecurity essential requirements. Applying an applicable cited standard can provide a presumption of conformity within its coverage and published restrictions.

When did the RED cybersecurity requirements begin to apply?

Delegated Regulation (EU) 2022/30 applies from 1 August 2025 to the specified classes and categories of radio equipment under RED Article 3(3)(d), (e) and (f).

Does EN 18031 compliance prove CRA compliance?

No. The CRA is a separate regulation for products with digital elements and includes manufacturer duties across the product lifecycle. RED evidence may be relevant technical evidence but does not by itself establish CRA scope or conformity.

When do the main CRA dates apply?

Regulation (EU) 2024/2847 applies generally from 11 December 2027. Article 14 vulnerability and severe-incident reporting applies from 11 September 2026, while Chapter IV provisions on conformity-assessment bodies apply from 11 June 2026.

Sources and further reading

RESEARCH & DEFINITIONS

How a Signal worth attention is found

See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

Open the methodology and core definitions

START WITH ONE MONITORED GROUP

Try the workflow free for seven days.

Open the product, connect one authorized group, and describe the Signal you want to find. If you need help choosing the scope, ask us on Telegram.

Back to homepage