EN 18031, the RED Cybersecurity Rules, or the Cyber Resilience Act: What Does Each Product-Security Claim Mean?
Separate RED legal scope, the restricted EN 18031 presumption-of-conformity route and CRA lifecycle duties before accepting an “EU cyber compliant” product claim.

- 01RED answers which radio-equipment requirements apply
- 02EN 18031 answers how specified RED requirements may be evidenced
- 03The CRA answers a different product-lifecycle question
Signals to watch
- A named connected product and software version are attached to an EU cybersecurity claim
- The claim distinguishes RED essential requirements from an EN 18031 test or declaration and from CRA lifecycle duties
- A conformity assessment, market launch, vulnerability-reporting or customer decision has an owner and date
EN 18031, the Radio Equipment Directive cybersecurity rules and the Cyber Resilience Act are not three competing certificates. RED establishes legal requirements for specified radio equipment; EN 18031 is one restricted harmonised-standard route to presume conformity with particular RED requirements; the CRA creates separate cybersecurity and lifecycle duties for products with digital elements. An “EU cyber compliant” claim must name which statement it means.
This is the source-routing problem facing a connected-product security analyst in authorized manufacturer, test-lab and product-compliance Telegram groups. The useful Signal is a product/version claim entering a launch or supplier decision without its legal scope and evidence object. Seeing it a day late can let the wrong declaration enter a customer file. Treating every EN 18031 test as CRA proof can be worse than having no shorthand at all.
The following are illustrative claim fragments, not real products or test results:
“EN 18031 passed, so the device is EU cyber compliant.”
“RED is done. CRA report also covered.”
Neither sentence names product functions, radio category, standard part, test scope, published restriction, conformity route, software version, CRA role or applicable date.
RED answers which radio-equipment requirements apply
The Radio Equipment Directive, Directive 2014/53/EU, contains essential requirements. Delegated Regulation (EU) 2022/30 makes Article 3(3)(d), (e) and (f) apply to specified classes or categories from 1 August 2025.
In simplified terms, those provisions address protection of networks and against service misuse, protection of personal data and privacy for specified equipment, and protection against fraud for specified internet-connected radio equipment processing virtual money or monetary value. Scope depends on the product’s radio and internet functions and the delegated act’s classes, categories and exclusions.
The evidence object is the manufacturer’s conformity assessment, technical documentation, EU declaration of conformity and associated testing—not a bare statement that a product contains Wi-Fi or Bluetooth.
EN 18031 answers how specified RED requirements may be evidenced
Implementing Decision (EU) 2025/138 cites:
- EN 18031-1:2024 for common security requirements for internet-connected radio equipment under RED Article 3(3)(d);
- EN 18031-2:2024 for radio equipment processing personal, traffic or location data, including specified childcare, toy and wearable radio equipment, under Article 3(3)(e); and
- EN 18031-3:2024 for internet-connected radio equipment processing virtual money or monetary value under Article 3(3)(f).
Compliance with a cited harmonised standard can confer a presumption of conformity with the corresponding legal requirement. That presumption is not unlimited.
The Decision publishes the EN 18031 references with restrictions. “Rationale” and “guidance” sections do not confer the presumption. The notices also restrict the presumption for specified password choices, access-control implementations and secure-update criteria. An analyst therefore needs the applied clauses, product implementation and restrictions—not only a lab cover page saying “EN 18031.”
The CRA answers a different product-lifecycle question
The Cyber Resilience Act, Regulation (EU) 2024/2847, covers products with digital elements made available on the Union market, subject to its definitions and exclusions. It sets essential cybersecurity requirements and obligations for manufacturers and other economic operators across design, development, production, vulnerability handling and support.
The dates differ from RED. The CRA applies generally from 11 December 2027. Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026. Chapter IV provisions on conformity-assessment bodies apply from 11 June 2026.
An EN 18031 report can contain relevant technical evidence, but it does not decide CRA product classification, support period, vulnerability-handling process, software bill of materials, reporting workflow or conformity route. SBOM means software bill of materials, an inventory of software components.
Use the same five questions for every claim
| Question | RED cybersecurity | EN 18031 | CRA |
|---|---|---|---|
| What is it? | EU radio-equipment legal requirements | Harmonised technical standards cited for specified RED requirements | EU regulation for products with digital elements |
| First scope fact | Radio equipment class, connectivity and data/payment function | Applicable part and clauses for that product | Product with digital elements, economic-operator role and exclusions |
| Evidence object | Technical documentation, assessment and declaration | Test/assessment against applicable clauses plus restrictions | Lifecycle technical documentation, conformity route and operational records |
| Key date | Applicable from 1 Aug 2025 | Citation decision published in 2025; use current OJ status | Reporting 11 Sep 2026; general application 11 Dec 2027 |
| Cannot prove alone | CRA conformity or all product cybersecurity | Legal scope, unrestricted presumption or CRA compliance | RED radio scope or EN 18031 test result |
The table routes evidence; it does not replace a product-specific legal assessment.
One product can need both routes without reusing one conclusion
An internet-connected radio product can be radio equipment under RED and a product with digital elements under the CRA. That overlap does not make one assessment file a universal answer.
Build a requirement cross-reference for the exact model and software version. One column names the RED essential requirement and applicable EN 18031 clauses and notices. A second column names the CRA requirement, economic-operator duty, evidence owner and application date. Link shared technical artifacts—such as authentication tests or update design—without copying the RED conclusion into the CRA status field.
Version control matters. A lab report may describe firmware tested before a later vulnerability-handling process or security update was introduced. Record model, hardware revision, firmware/software version, test date, applicable standard edition and the declaration or lifecycle record that consumes the evidence. A product name without that version boundary cannot support a current launch claim.
Rewrite “EU cyber compliant” into a verifiable sentence
A useful note looks like this:
For product model and software version X, the manufacturer applies EN 18031-1:2024 to the specified RED Article 3(3)(d) requirements, with the Implementing Decision restrictions reviewed; the EU declaration and technical file remain to be checked. CRA scope, Article 14 reporting readiness and 2027 conformity are separate and unverified.
That statement names a product, standard part, legal requirement, restriction and unknown. If the group cannot supply those fields, the claim stays in source review.
For CRA reporting operations, use the CRA workflow article. The WCAG, EN 301 549 and VPAT article shows a different law-standard-procurement distinction. If the evidence is only a screenshot, recover it with the official-source ladder.
TOP Prospect can connect incomplete fragments from groups the user deliberately connects and may access, preserve source and time, remove obvious duplicates and rank the claim for human review. It cannot inspect a product, validate a standard test, determine legal scope, issue a declaration or report a CRA vulnerability. The pricing page describes the discovery boundary.
Choose the record by the sentence being claimed: RED for the applicable radio-equipment requirement, EN 18031 for the bounded standards evidence, and CRA for the product-lifecycle obligation. Do not ask one document to prove all three.
Frequently asked questions
Is EN 18031 an EU law?
No. EN 18031 is a family of harmonised European standards cited for specified RED cybersecurity essential requirements. Applying an applicable cited standard can provide a presumption of conformity within its coverage and published restrictions.
When did the RED cybersecurity requirements begin to apply?
Delegated Regulation (EU) 2022/30 applies from 1 August 2025 to the specified classes and categories of radio equipment under RED Article 3(3)(d), (e) and (f).
Does EN 18031 compliance prove CRA compliance?
No. The CRA is a separate regulation for products with digital elements and includes manufacturer duties across the product lifecycle. RED evidence may be relevant technical evidence but does not by itself establish CRA scope or conformity.
When do the main CRA dates apply?
Regulation (EU) 2024/2847 applies generally from 11 December 2027. Article 14 vulnerability and severe-incident reporting applies from 11 September 2026, while Chapter IV provisions on conformity-assessment bodies apply from 11 June 2026.
Sources and further reading
How a Signal worth attention is found
See how Top Prospect finds and organizes Signals worth checking, keeps the original Telegram context, removes duplicates, and helps you decide what to review first. You decide whether to follow up and what to do next.

