EN 18031 Compliance Services

Turn the EN 18031 standards family into product-specific scope, requirements, risk decisions, evidence tasks and review-ready documentation for your connected radio product.

Prepare for RED Cybersecurity Assessment with EN 18031

EN 18031 is not a flat checklist. Applying it requires product-specific information about assets, interfaces, entities, data, and security mechanisms, together with documented decision-tree paths and supporting justifications. Cyberexpert brings that information into one structured readiness workflow.

  • Gap analysis and risk assessment

  • EN 18031 evidence preparation

  • Expert review and testing services

  • Who Cyberexpert supports

  • How the EN 18031 process works

Start your free EN 18031 scoping assessment

What We Help You Achieve

  • Identify which part or parts of the EN 18031 family are relevant to your RED cybersecurity scope.

  • Build a product-specific asset inventory covering the relevant security, network, privacy, and financial assets.

  • Connect interfaces, entities, functions and data flows to product risks and applicable requirements.

  • Record selected decision-tree paths and supporting justifications.

  • Prepare the required product information, evidence references and technical documentation inputs.

  • Maintain traceability as product architecture, firmware and supporting evidence change.

EN 18031-1 network protection

Assess how the product protects networks and network resources from harm, misuse or unacceptable degradation of service, then connect relevant requirements to controls and evidence.

EN 18031-1 network protection
EN 18031-2 privacy and personal data

EN 18031-2 privacy and personal data

Map the personal, traffic and location data processed by the product, app, connected services and relevant interfaces, then document the controls and evidence used to protect that data.

EN 18031-3 fraud protection

Identify whether internet-connected radio equipment enables the transfer of money, monetary value or virtual currency, then determine what fraud-protection requirements and evidence are relevant.

EN 18031-3 fraud protection
Asset and interface mapping

Asset and interface mapping

Document relevant security, network, privacy and financial assets, together with the entities, functions, data and interfaces that can access or expose them.

Risk-based decisions

Use product risks, intended use, architecture, controls, and operating assumptions to support the assessment and evidence strategy.

Risk-based decisions
Requirement traceability

Requirement traceability

Keep the chain visible from product features to asset, risk, requirement, control, evidence, and justification.

Understand the EN 18031 Restrictions and Conformity Route

Rationale and guidance sections

These sections are informative and do not themselves create a presumption of conformity.

Password requirements

No presumption where users can avoid setting a password under restricted clauses.

Parental or guardian access control

Required for relevant toy & childcare radio equipment under EN 18031-2.

Secure updates under EN 18031-3

Clause 6.3.2.4: no presumption for fraud protection; third-party assessment mandatory.

Start your free EN18031 scoping assessment

Expert Review and Testing for EN 18031 Evidence Readiness

EN 18031 evidence work often stalls because product, firmware, cloud, supplier, QA and compliance information is managed separately. Cyberexpert gives these teams a shared structure before expert review or testing begins.

  • Software and firmware vulnerability assessment Identify relevant vulnerabilities, outdated components, and exposed software risks where these affect the product assessment.

  • Interface and exposed-service review Review relevant network, physical, logical and debug interfaces, together with remote-access and connected-service paths.

  • Secure update review Assess applicable update controls, including authenticity, integrity, and supporting evidence. Consider rollback and logging where they are relevant to the product and applicable requirements.

  • EN 18031 information and justification review Review the product-specific information required by EN 18031, selected decision-tree paths, supporting justifications and linked evidence before conformity assessment.

  • Component and supplier evidence review Connect relevant supplier documentation and component information, including SBOM or HBOM inputs where they support the product-specific assessment.

  • Specialist hardware security review Add specialist evaluation where physical interfaces, storage or the product’s attack surface make it relevant.



Who We Support with EN 18031 Readiness

  • IoT and connected product manufacturers

For manufacturers managing cybersecurity scope across devices, companion apps, backend services, data flows, and firmware updates.

  • Wireless module integrators and combined equipment manufacturers

For teams determining where supplier evidence can be reused and where product-level assessment is still required.

  • Telecom and radio equipment manufacturers

For manufacturers managing radio functions, network interfaces, remote access, update mechanisms, and technical documentation.

  • Compliance, product security, engineering and QA teams

For cross-functional teams that need one shared workflow for requirements, decisions, risks, and evidence.

How the EN 18031 Readiness Process Works

Product scoping

Radio functions, interfaces, data, users, deployment & connected services.

Applicability & risk assessment

Relevant RED 3(3) & EN 18031 parts, then a product-specific risk assessment.

Requirements & evidence planning

Map requirements to controls, docs, supplier inputs & evidence owners.

Remediation planning

Identify missing controls, documentation, justifications & test evidence.

Why Choose Cyberexpert for EN 18031 Readiness

Structured self-assessment

Start with guided product scoping, keep assessment decisions consistent, and give stakeholders a shared product model.

AI-assisted documentation

Draft requirement explanations, E.Info content and evidence notes faster while keeping product context visible and manufacturer review in control.

QIMA and CCLab pathway

Add expert review or testing when the assessment requires specialist judgment, independent evidence or a formal conformity pathway.

Find Out Which EN 18031 Parts Apply to Your Product

Start your free Cyberexpert scoping assessment to clarify the relevant RED cybersecurity areas, product boundaries and next readiness steps.

Start your free EN18031 scoping

EN 18031 Compliance Questions

  • What is EN 18031?

EN 18031 is a family of three harmonized European standards supporting the RED cybersecurity requirements under Article 3(3)(d), (e), and (f). The standards address internet-connected radio equipment, equipment processing personal, traffic or location data, and internet-connected equipment processing virtual money or monetary value. Their references were published in the Official Journal with restrictions.

  • How does Cyberexpert help with EN 18031 compliance?

Cyberexpert guides manufacturers through product scoping, risk assessment, requirements mapping and evidence preparation. It connects product information, assets, interfaces, decision-tree paths, controls and supporting evidence in one structured workflow.

  • What does the free EN 18031 assessment include?

The free assessment helps you describe your product, clarify its RED cybersecurity scope and identify which EN 18031 parts may be relevant. It provides an initial view of the product boundaries, risks and next readiness steps.

  • Do all EN 18031 requirements apply to every product?

No. The relevant EN 18031 part or parts depend on the product’s RED scope, connectivity, functions and data processing. Within the applicable standards, assets, interfaces, security mechanisms and decision-tree criteria determine which requirements and evidence need to be addressed.

  • How does Cyberexpert help prepare E.Info and E.Just?

Cyberexpert helps structure the product information required for the assessment, including relevant assets, interfaces, security mechanisms and selected decision-tree paths. It also supports the preparation of justifications explaining why particular decision-tree decisions were made.

  • What outputs can Cyberexpert help prepare?

Depending on the selected plan and assessment stage, Cyberexpert can help prepare structured product information, risk assessment outputs, requirements mappings, decision-tree justifications, evidence references and technical documentation inputs.

  • Can QIMA or CCLab review my EN 18031 assessment?

Yes. Cyberexpert can be used for structured self-assessment and readiness work with CCLab expert review and testing added when the product risk, evidence or conformity route requires specialist support.

  • Can Cyberexpert replace a RED Notified Body assessment?

No. Cyberexpert supports product scoping, self-assessment and documentation preparation, but it does not replace the manufacturer’s legal responsibility or a RED Notified Body assessment where one is required.

  • How long does EN 18031 readiness take?

Timing depends on product complexity, architecture and evidence availability. Initial Cyberexpert scoping and requirements generation can take approximately one hour, while completing controls, evidence, testing and technical documentation usually requires additional work.

  • Will EN 18031 remain relevant after the Cyber Resilience Act applies?

The RED cybersecurity requirements activated through Delegated Regulation (EU) 2022/30 remain applicable until 10 December 2027. That regulation is repealed from 11 December 2027, when the Cyber Resilience Act becomes fully applicable. EN 18031 work can still provide useful technical foundations, but it does not automatically demonstrate CRA compliance.

Visit Cyberexpert

Keep Building Your RED and EN 18031 Knowledge