EN 18031 standard: mandatory cybersecurity for IoT devices and radio equipment

By Kike Gandia · Co-Founder & CEO, OSCP

The EN 18031 standard (adopted in Spain as UNE-EN 18031) establishes mandatory cybersecurity requirements for radio equipment and IoT devices placed on the European Union market. Since 1 August 2025, any manufacturer placing on the EU market devices with network connectivity — routers, IP cameras, wearables, IoT sensors, connected appliances, medical or industrial devices — must demonstrate conformity with this standard under the Radio Equipment Directive (RED 2014/53/EU).

What EN 18031 is and where it comes from

EN 18031 is a European harmonised standard published in three parts: EN 18031-1 (general security requirements for radio equipment connected to the Internet), EN 18031-2 (equipment that processes personal data) and EN 18031-3 (equipment with child-related functionality). Its origin lies in Commission Delegated Regulation (EU) 2022/30, which activated the cybersecurity requirements of Article 3(3)(d)(e)(f) of the Radio Equipment Directive.

Who EN 18031 applies to

It applies to manufacturers, importers and distributors placing on the EU market any radio equipment that: connects to the Internet (directly or indirectly), can transmit or receive voice data, or can transfer money, monetary value or virtual currency. The most common product types affected are: home and enterprise routers, connected IP cameras and video surveillance systems, wearables (smartwatches, activity bands), smart home appliances, industrial and health IoT devices, connected toys and baby monitors, and any device with Wi-Fi, Bluetooth, Zigbee or similar connectivity.

Main technical requirements of EN 18031

The standard requires devices to comply with: (1) Credential management: prohibition of universal default passwords; each device must have unique credentials or force a change on first use. (2) Security updates: secure and authenticated firmware update mechanism. (3) Data management: personal data is transmitted only when necessary; communications must be encrypted. (4) Protection against unauthorised access: authentication and access control mechanisms. (5) Minimal attack surface: services and ports not required must be disabled by default. (6) Resilience against attacks: the device must continue to function with graceful degradation under attack attempts.

Compliance deadlines and consequences of non-compliance

The conformity deadline is 1 August 2025. From that date, products that do not meet the cybersecurity requirements of the Radio Equipment Directive may not be legally placed on the EU market. Consequences of non-compliance include: withdrawal of the product from the market, prohibition on marketing in the EU, administrative penalties under each Member State's national legislation, and civil liability if the product causes harm due to security vulnerabilities.

Differences between EN 18031 and the Cyber Resilience Act (CRA)

Although they overlap for some products, there are important differences. EN 18031 applies exclusively to radio equipment (with wireless connectivity) under the RED Directive and has been mandatory since August 2025. The Cyber Resilience Act (CRA) has a broader scope: it applies to all products with digital elements (including software), whether they use wireless communication or not, and will be fully applicable in December 2027. Some products may fall under both regulations simultaneously. Your compliance strategy must consider both to avoid duplicated work.

How to prepare your company for EN 18031 compliance

The compliance process has four phases: (1) Product classification: determine whether the device falls within the scope of the standard and which part applies (18031-1, -2, -3). (2) Technical gap analysis: assess the firmware, update process, credential management and communications against the Annex I requirements. (3) Control implementation: remediate identified gaps (unique credentials, TLS encryption, secure update mechanism, OS hardening). (4) Conformity assessment: self-assessment if the product follows harmonised standards; third-party assessment if there is doubt or the product is high-criticality.

FAQ

Is compliance with EN 18031 voluntary or mandatory?

It is mandatory for affected products since 1 August 2025. The standard is 'harmonised' under the RED Directive, which means complying with it grants a presumption of conformity with the Directive's legal requirements. Non-compliant products cannot be placed on the EU market.

How do I demonstrate that my device complies with EN 18031?

There are two routes: (1) Self-assessment: the manufacturer drafts the EU declaration of conformity based on the harmonised standard, without third-party involvement (valid for most Default products). (2) Assessment by a notified body (NoBo): mandatory if the manufacturer does not follow the harmonised standard or if the product belongs to higher-risk categories. In both cases, the technical file must be maintained and available to market surveillance authorities.

Is penetration testing part of the EN 18031 compliance process?

Yes. Penetration testing of IoT devices and hardware is the most effective tool to verify that the controls required by EN 18031 work in practice: that credentials are not reusable, that the update mechanism is not exploitable, that communications are genuinely encrypted and that there are no backdoors. A gap analysis without real technical testing can miss implementation flaws that an experienced IoT auditor would detect within hours.

Related service

IoT and hardware penetration testing

Related content

Sources

Assess my IoT device for EN 18031 compliance