EU Certification | EN 18031 RED Cybersecurity
EU Certification | EN 18031 RED Cybersecurity
On January 12, 2022, the EU Official Gazette published Delegated Act (EU) 2022/30, which enforces the RED Directive Articles 3.3(d), (e) and (f) for relevant products and will be enforced on August 1, 2025. The bill directly affects radio equipment manufacturers, certification bodies and compliance processes. The following is a key point analysis.
Standard core requirements and scope of application:
EN 18031 is divided into three parts, corresponding to different security goals:
EN 18031-1 (Network Protection)
Requires devices to avoid damage to the network and prevent resource abuse (such as DDoS attacks).
Assessment content: access control, security updates, resilience mechanisms, network monitoring, etc.
EN 18031-2 (Privacy Protection)
Protect user personal data, applicable to children's toys, wearable devices, etc.
Evaluation content: data encryption, logging, user notification mechanism, etc.
EN 18031-3 (Fraud Prevention)
Prevent fraud related to financial transactions.
Evaluation content: device startup integrity, financial transaction security verification, etc.
Implementation time:
In May 2024, the EU officially released the final draft of the cybersecurity standard EN 18031 series of standards and widely solicited opinions from member states. The standard was officially approved on August 1, 2024.
However, after the release, the EN 18031 series of standards still need to obtain final approval from the EU and be included in the Official Journal of the European Union (OJ) before they can officially become coordinated standards that meet the requirements of the RED Directive.
Notes:
1. If the information confirmation and rectification time is extended, the certification cycle will be postponed, and it is recommended to reserve rectification time.
2. More than 80% of the products on the market will involve rectification, so it is recommended to reserve rectification time in the certification cycle, and it is recommended to conduct a preliminary investigation six months to one year in advance.
3. Because different products involve different test contents and different product design plans, it is recommended to conduct a preliminary test for each type of product in advance, and import the test requirements into the product development stage after understanding the detailed requirements of this type of product, so as to avoid a large number of rectifications during certification.
Questions and answers:
Q: Which products need to comply?
A: For models that have not been shipped, products shipped after the mandatory date (2025-08-01) must complete the test and obtain the certificate as required.
For models that have been shipped and need to be shipped after the mandatory date (2025-08-01), complete the test and obtain the certificate as required.
Send Inquiry to This Supplier
You May Also Like
-
U.S. Energy Star CertificationNegotiableMOQ: 1 Acre
-
Australian RCM CertificationNegotiableMOQ: 1 Acre
-
Australian SAA CertificationNegotiableMOQ: 1 Acre
-
China Compulsory Certification(CCC)NegotiableMOQ: 1 Acre
-
South Korea KC CertificationUS$ 80MOQ: 1 Acre
-
Wireless Products Exported to Korea With KCC CertificationUS$ 10 - 20MOQ: 1 Combo
-
South African NRCS CertificationUS$ 10MOQ: 1 Combo
-
Uganda COC CertificationUS$ 10MOQ: 1 Combo
-
Lithium Battery UN38.3 Safety Transportation ReportNegotiableMOQ: 1 Combo
-
Energy Storage Power Supply UL2743 Certification Test in the United StatesNegotiableMOQ: 1 Combo