📡 EN 18031-1 / -2 / -3
The harmonised standards for the cybersecurity articles of the Radio Equipment Directive, covering network protection, personal data protection and fraud prevention.
Book a free consultation →EN 18031 is the harmonised standard for the cybersecurity articles 3.3(d)(e)(f) of the Radio Equipment Directive (RED), mandatory for products with radio since 1 Aug 2025. Its three parts cover network protection (-1), personal data protection (-2) and fraud prevention (-3).
We help write and review the IXIT, run the conceptual assessment and functional testing, and reach verdicts along the decision tree — including well-justified "not applicable" cases, which are often what decides pass or fail.
Products with radio can't get CE or be placed on the market without passing 3.3(d)(e)(f).
Most verdicts hinge on how thoroughly the IXIT and non-applicability justifications are written.
EN 18031 evidence carries over heavily to EN 303 645 / CNS 16190.
Clarify the product type, target markets and applicable clauses, and define the tests and documents needed.
Map the product's current state to the standard's requirements and produce a gap analysis.
Run the test plan and process audit; add penetration testing and fuzzing where needed.
Consolidate results and evidence, map each item to a clause, and form an auditable record.
Deliver the report and improvement recommendations; for markets that require filing, help prepare the submission.
Tell us the product type and target markets and we will come back with the applicable clauses, test scope and timeline.