Product Assurance Learning

Home / Guides

Guide

RED Cybersecurity and EN 18031: What Radio Makers Must Do

Since 1 August 2025, Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive (RED) requires many internet-connected radio products to protect the network, personal data and users against fraud. The harmonised standards for these requirements are the EN 18031 series, but their citations in the Official Journal carry restrictions. Whether you can self-declare under module A or need a notified body depends on how those restrictions affect your product.

7 min readUpdated 3 October 2026By the VeridEx editorial team

What Delegated Regulation (EU) 2022/30 changes for radio equipment

The Radio Equipment Directive, Directive 2014/53/EU, has always covered three areas: safety, electromagnetic compatibility (EMC) and efficient use of the radio spectrum. Delegated Regulation (EU) 2022/30 adds a fourth area for many connected radio products: cybersecurity. It does this through three essential requirements in Article 3(3) of the directive.

These requirements have applied since 1 August 2025. They apply to each unit placed on the market from that date, because placing on the market happens unit by unit. A model you have sold for years must meet them for every new unit you ship today.

For the products concerned, cybersecurity is now part of what the CE marking declares. In practice this can mean cybersecurity testing, extra technical documentation and, in some cases, a notified body.

Which radio products are affected

Start with the RED itself. It covers any product that intentionally emits or receives radio waves for communication or radiodetermination. That includes Wi-Fi, Bluetooth, mobile networks, RFID and radar. A product that integrates a radio module becomes radio equipment as a whole. A packaging machine or an industrial controller with a built-in Wi-Fi module is therefore radio equipment, and the RED applies to the complete product.

The delegated regulation then targets many internet-connected radio products. A practical first check is simple: if your product has Wi-Fi, Bluetooth or a mobile connection and it talks to the internet, assess the delegated regulation first. Then read its scope provisions word by word, as you would for any EU product law, and record your conclusion in your applicability analysis.

Write down the reason in both directions. If you decide the requirements apply, note which ones. If you decide they do not, note the provision that supports your decision. An authority or a notified body may ask you why.

Article 3(3)(d), (e) and (f) in plain words

The three essential requirements activated by the delegated regulation sit in Article 3(3) of the RED, points (d), (e) and (f). In plain words:

  • Point (d), network protection: the product must protect the network it connects to.
  • Point (e), personal data: the product must protect the personal data of its users.
  • Point (f), fraud: the product must protect against fraud.

Do your applicability analysis point by point. For each of the three points, record whether it applies to your product and why, with the provision of the delegated regulation that supports your answer. The same structure then carries through to your standards list, your test reports and your declaration.

These requirements sit next to the core RED requirements. Safety and EMC, in Article 3(1), still apply in full. So do the radio requirements of Article 3(2). For radio equipment, you cover safety and EMC through the RED itself, so you do not apply the Low Voltage Directive or the EMC Directive separately.

EN 18031 standards and the restrictions in their citation

The harmonised standards for the cybersecurity requirements are the EN 18031 series. As with any harmonised standard, a standard gives presumption of conformity only once its reference is published in the Official Journal of the European Union, and only for the requirements it covers.

The EN 18031 standards were cited with restrictions when first published. A restriction means that part of the standard does not give presumption of conformity. The note attached to the citation explains which clauses are affected. Their citations currently carry restrictions, and the framework is still changing, so you must check the latest position in the Official Journal before you decide anything.

In practice:

  1. Open the Commission's summary list of harmonised standards for the RED, and then the implementing decision in the Official Journal, which is the legal source.
  2. Read the citation itself and its notes, and not only the title of the standard.
  3. Compare each restriction with your product and its features.
  4. Record the full reference, the date you checked it and your conclusion in a dated standards list in your technical file.

Our guide to harmonised standards and presumption of conformity explains how to read the lists, editions and cessation dates.

When module A is enough and when you need a notified body

This is where the restrictions have a direct cost. Under the RED, the choice of conformity assessment procedure depends on harmonised standards:

RequirementsModule A (internal production control)Otherwise
Article 3(1): safety and EMCAlways possibleNot needed
Article 3(2) and 3(3): radio and cybersecurityOnly if harmonised standards covering them are fully applied, and no restriction in their citation matters for your productModule B plus C, or module H, with a notified body

So module A is no longer possible for the cybersecurity requirements in three situations: a restriction in the EN 18031 citation affects your product, you apply the standards only in part, or no harmonised standard covers the requirement. In each case, a notified body must take part for those requirements.

Under module B plus C, the notified body examines the design and issues an EU-type examination certificate, and you control production. Because the body acts only in the design phase, its four-digit number does not follow the CE marking. Under module H, the body approves and monitors your quality system, and its number appears next to the CE marking, shown as CE xxxx.

Before you sign a contract, check in NANDO, the Commission's database of notified bodies, that the body is notified under the RED for your module and product. More detail on procedures across laws is in our guide do I need a notified body.

Technical file, declaration and the link with the Cyber Resilience Act

The technical documentation should show how each applicable cybersecurity requirement is met. Typical content includes:

  • your applicability analysis, point by point;
  • the EN 18031 standards applied, with full references and the restrictions you checked;
  • cybersecurity test reports, next to the radio, EMC and safety reports;
  • your own justification for any part a restriction leaves open;
  • the notified body certificate, where one was needed.

Be careful with integrated radio modules. A module with its own reports is a good start, but it does not make the whole product compliant. Assess the product as a whole, and keep each report traceable to the hardware and software revision tested.

The EU Declaration of Conformity lists Directive 2014/53/EU together with Delegated Regulation (EU) 2022/30, plus RoHS and any other law that applies, such as machinery. Under the RED, each unit comes with a copy of the full declaration or a simplified declaration with an internet address.

Finally, plan for change. The Cyber Resilience Act, Regulation (EU) 2024/2847, applies its main obligations from 11 December 2027. For radio products, the cybersecurity requirements of the RED delegated act are expected to give way to the Cyber Resilience Act once it fully applies, and Delegated Regulation (EU) 2022/30 is currently set to be repealed from that date. Check the latest position in the Official Journal. Our guide to Cyber Resilience Act dates sets out what applies when, and the RED cybersecurity course covers the requirements in depth.

Key points

  • Delegated Regulation (EU) 2022/30 has applied since 1 August 2025 to many internet-connected radio products.
  • It activates RED Article 3(3)(d), (e) and (f): network protection, personal data and privacy, and protection from fraud.
  • The EN 18031 harmonised standards are cited with restrictions, so read the citation and check the latest position.
  • If a restriction matters for your product, or you apply the standards in part, module A is not possible for those requirements.
  • The Cyber Resilience Act is expected to take over this role from 11 December 2027.

The free first module of our CE Marking Fundamentals course explains the framework behind these rules: economic operators, placing on the market and the CE marking.

Learn the whole route, step by step

CE Marking Fundamentals takes you from the EU market rules to your first shipment, with templates and quizzes. Module 1 is free.

Frequently asked questions

Do I need a notified body for RED cybersecurity?

Not always. You can use module A for Article 3(3)(d), (e) and (f) if you fully apply EN 18031 standards cited in the Official Journal and no restriction in the citation matters for your product. If a restriction affects your product, or you apply the standards only in part, you need a notified body under module B plus C or module H.

Does a CE marked Wi-Fi module make my product compliant with RED cybersecurity?

No. A product that integrates a radio module becomes radio equipment as a whole, and you must assess the complete product. The module's reports are useful evidence, but integration can change the result, so the assessment and any testing must cover your product.

What is the difference between RED cybersecurity and the Cyber Resilience Act?

Delegated Regulation (EU) 2022/30 adds three cybersecurity requirements to the RED for many internet-connected radio products, and it has applied since 1 August 2025. The Cyber Resilience Act covers products with digital elements more broadly, with main obligations from 11 December 2027. The RED cybersecurity requirements are currently set to give way to the CRA from that date, so check the latest position.

Where do I find the EN 18031 restrictions?

In the citation of the standards in the Official Journal of the European Union, in the notes attached to the reference. The Commission's summary list for the RED brings the citations together, but the Official Journal is the legal source. Read the note itself, not only the title of the standard.

This guide is general training material, not legal advice. EU rules and standard citations change: check the latest texts in the Official Journal of the European Union before you decide.

Related guides

Be first in line

Join the waitlist for launch pricing and a free CE applicability checklist. We will only email you about VeridEx courses.