Home RED RED Cyber — EN 18031 standards and conformity routes, deep dive

RED Cyber — EN 18031 standards and conformity routes, deep dive

Last updated on Jun 03, 2026

In one paragraph

The Radio Equipment Directive (RED) cybersecurity delegated act activates Article 3(3)(d), (e), (f). The EN 18031 series of harmonised standards translates these requirements into testable specifications. This article walks the series, the conformity routes, and the evidence NexCyber tracks per route.

The three articles activated

  • Article 3(3)(d) — network protection. The equipment does not harm the network and is robust against network attacks.
  • Article 3(3)(e) — personal data and privacy. The equipment safeguards stored or transmitted personal data.
  • Article 3(3)(f) — fraud protection. The equipment protects against monetary fraud where it enables monetary transactions.

Different product categories trigger different combinations.

The EN 18031 series

EN 18031 is a three-part harmonised standard:

  • EN 18031-1 — common security requirements for internet-connected radio equipment (covers Article 3(3)(d)).
  • EN 18031-2 — security requirements for processing personal data, location data, or traffic data (covers Article 3(3)(e)).
  • EN 18031-3 — security requirements for radio equipment allowing the user to transfer money, monetary value, or virtual currency (covers Article 3(3)(f)).

Conformity to the relevant parts grants presumption of conformity with the RED essential requirements activated by the delegated act.

Conformity routes

A manufacturer can choose between several routes for assessing conformity:

  • Module A — Internal production control. Manufacturer's self-declaration based on internal control. Allowed when the manufacturer applies harmonised standards in full.
  • Module B + C — EU-type examination plus conformity to type based on internal production control. Notified body involvement at type level.
  • Module H — Full quality assurance. Notified body involvement on the manufacturer's quality system.

The choice depends on whether harmonised standards are applied in full, whether the product is in scope of further mandatory routes, and on the manufacturer's quality-system maturity.

How NexCyber tracks conformity evidence per route

Module A

Evidence we expect:

  • Technical documentation that demonstrates application of EN 18031 in full.
  • Test reports (typically from in-house or accredited labs).
  • Manufacturer's signed declaration of conformity.
  • Annexes: SBOM, vulnerability handling policy, change management records.

Module B + C

Evidence we expect:

  • Notified body type-examination certificate.
  • Type-test reports.
  • Production control records demonstrating conformity to the approved type.
  • Surveillance reports if applicable.

Module H

Evidence we expect:

  • Quality system certificate from a notified body.
  • Quality system documentation (procedures, audit reports, management review records).
  • Sample production records showing the QMS in action.

NexCyber stores the artefacts in the evidence workspace, links them to the obligation, and shows the confidence per item.

Where RED Cyber meets CRA

For most connected radio products, CRA also applies. The overlap is significant: technical documentation, SBOM, vulnerability handling, security update policy. NexCyber detects the overlap and maps a single evidence item across both regulations.

A practical sequence:

  1. Confirm RED Cyber applicability in the scope review.
  2. Pick a conformity route.
  3. Reuse the technical file and SBOM across RED Cyber and CRA.
  4. Track notified body involvement where the route requires it.

Manufacturer responsibilities

Even with the most favourable route, the manufacturer retains responsibilities:

  • Initial conformity assessment before placing on the market.
  • Continued conformity through the lifecycle.
  • Vulnerability handling, security updates, end-of-support communication.
  • Cooperation with market surveillance authorities.

NexCyber surfaces each responsibility in the assessment.

Importers and distributors

Importers and distributors also carry obligations: verifying the manufacturer's documentation, ensuring marking, refraining from placing non-conforming products on the market. NexCyber supports importer / distributor workspaces with the same evidence model.

Post-market obligations

  • Monitoring for issues with the product.
  • Vulnerability disclosure channel.
  • Remediation through security updates.
  • Reporting actively exploited vulnerabilities and severe incidents where required.

NexCyber tracks the post-market plan and the field metrics.

What RED Cyber via NexCyber does NOT do

  • It does not perform the harmonised-standard tests. Test labs do.
  • It does not issue CE marking decisions. Manufacturers and notified bodies do.
  • It does not interpret borderline category questions; it flags them for human regulatory triage.

Common pitfalls

  • Applying EN 18031 partially and claiming Module A.
  • Stale SBOM that no longer matches the firmware shipped.
  • Notified body involvement booked too late for the release schedule.
  • No documented vulnerability handling channel at end of support.

Related articles

  • RED Cyber basics — wider picture.
  • CRA — Vulnerability handling, coordinated disclosure, and post-market obligations — overlap.
  • Preparing an SBOM (CycloneDX or SPDX).

Next step

Open the RED Cyber assessment, confirm the article(s) activated, choose your conformity route, and start attaching the route-specific evidence.