RED cybersecurity and EN 18031 — scope and assessment overview
An overview of RED cybersecurity scope, EN 18031 OJ restrictions, available assessment routes and evidence. Check the licensed standard for the actual test method.
By CenitiaUpdated
For devices first placed under the 2022/30 regime, identify which Article 3(3)(d), (e) or (f) requirement is activated and whether an exclusion applies. Regulation 2026/339 repeals 2022/30 from 11 December 2027; it does not repeal RED or erase the obligations attached to products placed earlier.
Essential requirements and exclusions
Article 3(1)(a) covers health/safety objectives of LVD without its voltage limits; 3(1)(b) covers EMC; 3(2) covers spectrum. RED Article 1(4) excludes standalone LVD application and EMC Article 2 excludes RED radio equipment. Other applicable acts such as RoHS remain separately assessed. Delegated Regulation 2022/30 activates selected 3(3)(d)-(f) requirements from 1 August 2025 after 2023/2444; its Article 2(1) excludes MDR/IVDR devices from those three cybersecurity requirements, not from all RED duties. Regulation 2026/339 repeals 2022/30 from 11 December 2027; RED itself continues.
Conformity assessment
For Article 3(1) requirements, Article 17(2) permits A, B+C or H. For Article 3(2)/(3), Article 17(3) permits A, B+C or H where applicable OJ-listed harmonised standards are fully applied; absent/partially applied standards, Article 17(4) requires B+C or H. Check exact editions, scope and OJ restrictions. EN 18031 citations under 2025/138 carry limitations; neither EN 18031 nor ETSI EN 303 645 automatically gives CRA presumption of conformity.
Evidence to keep with the product
Record the intended purpose, responsible economic operator, target market, first placing date and exact hardware/firmware configuration. For each applicable requirement, link the actual test or assessment record, dated standard/specification, scope and reviewer decision. Proposed controls and supplier marketing statements are not evidence that the final configuration has passed an assessment.
Separate an open question from a completed assessment. A report outside the laboratory's relevant scope, a different firmware build or an unverified exemption needs a reasoned decision before it supports a declaration. Keep original evidence and the issued declaration alongside any AI-assisted working draft.
Using Cenitia for this work
Cenitia assists with a limited regulatory catalogue and draft documents. The manufacturer must confirm applicability, actual applied specifications and completed assessment procedures. AI scores are quality signals, not a probability of conformity. Source monitoring raises a review prompt when validated source text changes; it does not automatically verify amendments, update the corpus or monitor every national rule and OJ standard edition. Public QR verification records issuance, not product certification.
Review status
This guide was substantively corrected by Cenitia on 2 October 2026 using the primary references below. It is an editorial summary, not an authoritative legal quotation or an independently signed expert opinion. Product-specific and licensed-standard questions remain subject to a real technical review.
Primary references
FAQ
Frequently asked questions
Does an AI draft or QR verification prove conformity?
No. The manufacturer must establish scope and satisfy applicable requirements using actual evidence. QR verification records issuance, not product certification.
What information must be checked for this product?
Confirm intended use, role, market/date, final configuration, dated specifications, assessment route and evidence scope. Record unresolved questions and a real reviewer decision.
Continue reading
Related guides
tutorial
How to Verify CE Documents from an Electronics Supplier
Check product identity, declarations, test reports and supplier gaps before accepting CE evidence for an electronics order.
5 min read
reference
ETSI EN 303 645 — the 13 consumer IoT controls explained
The 13 high-level provisions of ETSI EN 303 645 v2.1.1 (June 2020) and v3.1.3 (September 2024) explained, with the TS 103 701 conformance assessment mapping.
13 min read
reference
RED Annex IV path: when radio equipment needs a Notified Body
RED Annex IV path — when radio equipment requires Notified Body full quality assurance (Module H), versus Module A self-assessment under Article 17(2).
10 min read
comparison
RED and CRA overlap for connected radio products: 2025-2027 transition
RED cybersecurity and CRA scope for connected radio products: OJ coverage, assessment conditions, legacy transitions and the 2027 delegated-act repeal.
4 min read
Put this into practice
Free tools & references
- Do I need a Notified Body?Find out, per regulation, whether a Notified Body is required.Open tool →
- EU Directive SelectorDescribe your product and find which EU directives and regulations apply.Open tool →
New to the terminology? Browse the compliance glossary — plain-English, citation-backed definitions of every term above.