Prepare for RED Cybersecurity Assessment with EN 18031
EN 18031 is not a flat checklist. Applying it requires product-specific information about assets, interfaces, entities, data, and security mechanisms, together with documented decision-tree paths and supporting justifications. Cyberexpert brings that information into one structured readiness workflow.
Gap analysis and risk assessment
EN 18031 evidence preparation
Expert review and testing services
Who Cyberexpert supports
How the EN 18031 process works
What We Help You Achieve
Identify which part or parts of the EN 18031 family are relevant to your RED cybersecurity scope.
Build a product-specific asset inventory covering the relevant security, network, privacy, and financial assets.
Connect interfaces, entities, functions and data flows to product risks and applicable requirements.
Record selected decision-tree paths and supporting justifications.
Prepare the required product information, evidence references and technical documentation inputs.
Maintain traceability as product architecture, firmware and supporting evidence change.
EN 18031-1 network protection
Assess how the product protects networks and network resources from harm, misuse or unacceptable degradation of service, then connect relevant requirements to controls and evidence.


EN 18031-2 privacy and personal data
Map the personal, traffic and location data processed by the product, app, connected services and relevant interfaces, then document the controls and evidence used to protect that data.
EN 18031-3 fraud protection
Identify whether internet-connected radio equipment enables the transfer of money, monetary value or virtual currency, then determine what fraud-protection requirements and evidence are relevant.


Asset and interface mapping
Document relevant security, network, privacy and financial assets, together with the entities, functions, data and interfaces that can access or expose them.
Risk-based decisions
Use product risks, intended use, architecture, controls, and operating assumptions to support the assessment and evidence strategy.


Requirement traceability
Keep the chain visible from product features to asset, risk, requirement, control, evidence, and justification.
Understand the EN 18031 Restrictions and Conformity Route
Rationale and guidance sections
These sections are informative and do not themselves create a presumption of conformity.
Password requirements
No presumption where users can avoid setting a password under restricted clauses.
Parental or guardian access control
Required for relevant toy & childcare radio equipment under EN 18031-2.
Secure updates under EN 18031-3
Clause 6.3.2.4: no presumption for fraud protection; third-party assessment mandatory.
Expert Review and Testing for EN 18031 Evidence Readiness
EN 18031 evidence work often stalls because product, firmware, cloud, supplier, QA and compliance information is managed separately. Cyberexpert gives these teams a shared structure before expert review or testing begins.
Software and firmware vulnerability assessment Identify relevant vulnerabilities, outdated components, and exposed software risks where these affect the product assessment.
Interface and exposed-service review Review relevant network, physical, logical and debug interfaces, together with remote-access and connected-service paths.
Secure update review Assess applicable update controls, including authenticity, integrity, and supporting evidence. Consider rollback and logging where they are relevant to the product and applicable requirements.
EN 18031 information and justification review Review the product-specific information required by EN 18031, selected decision-tree paths, supporting justifications and linked evidence before conformity assessment.
Component and supplier evidence review Connect relevant supplier documentation and component information, including SBOM or HBOM inputs where they support the product-specific assessment.
Specialist hardware security review Add specialist evaluation where physical interfaces, storage or the product’s attack surface make it relevant.

Who We Support with EN 18031 Readiness
IoT and connected product manufacturers
For manufacturers managing cybersecurity scope across devices, companion apps, backend services, data flows, and firmware updates.
Wireless module integrators and combined equipment manufacturers
For teams determining where supplier evidence can be reused and where product-level assessment is still required.
Telecom and radio equipment manufacturers
For manufacturers managing radio functions, network interfaces, remote access, update mechanisms, and technical documentation.
Compliance, product security, engineering and QA teams
For cross-functional teams that need one shared workflow for requirements, decisions, risks, and evidence.
How the EN 18031 Readiness Process Works
Product scoping
Radio functions, interfaces, data, users, deployment & connected services.
Applicability & risk assessment
Relevant RED 3(3) & EN 18031 parts, then a product-specific risk assessment.
Requirements & evidence planning
Map requirements to controls, docs, supplier inputs & evidence owners.
Remediation planning
Identify missing controls, documentation, justifications & test evidence.
Why Choose Cyberexpert for EN 18031 Readiness
Structured self-assessment
Start with guided product scoping, keep assessment decisions consistent, and give stakeholders a shared product model.
AI-assisted documentation
Draft requirement explanations, E.Info content and evidence notes faster while keeping product context visible and manufacturer review in control.
QIMA and CCLab pathway
Add expert review or testing when the assessment requires specialist judgment, independent evidence or a formal conformity pathway.
Find Out Which EN 18031 Parts Apply to Your Product
Start your free Cyberexpert scoping assessment to clarify the relevant RED cybersecurity areas, product boundaries and next readiness steps.
EN 18031 Compliance Questions
What is EN 18031?
EN 18031 is a family of three harmonized European standards supporting the RED cybersecurity requirements under Article 3(3)(d), (e), and (f). The standards address internet-connected radio equipment, equipment processing personal, traffic or location data, and internet-connected equipment processing virtual money or monetary value. Their references were published in the Official Journal with restrictions.
How does Cyberexpert help with EN 18031 compliance?
Cyberexpert guides manufacturers through product scoping, risk assessment, requirements mapping and evidence preparation. It connects product information, assets, interfaces, decision-tree paths, controls and supporting evidence in one structured workflow.
What does the free EN 18031 assessment include?
The free assessment helps you describe your product, clarify its RED cybersecurity scope and identify which EN 18031 parts may be relevant. It provides an initial view of the product boundaries, risks and next readiness steps.
Do all EN 18031 requirements apply to every product?
No. The relevant EN 18031 part or parts depend on the product’s RED scope, connectivity, functions and data processing. Within the applicable standards, assets, interfaces, security mechanisms and decision-tree criteria determine which requirements and evidence need to be addressed.
How does Cyberexpert help prepare E.Info and E.Just?
Cyberexpert helps structure the product information required for the assessment, including relevant assets, interfaces, security mechanisms and selected decision-tree paths. It also supports the preparation of justifications explaining why particular decision-tree decisions were made.
What outputs can Cyberexpert help prepare?
Depending on the selected plan and assessment stage, Cyberexpert can help prepare structured product information, risk assessment outputs, requirements mappings, decision-tree justifications, evidence references and technical documentation inputs.
Can QIMA or CCLab review my EN 18031 assessment?
Yes. Cyberexpert can be used for structured self-assessment and readiness work with CCLab expert review and testing added when the product risk, evidence or conformity route requires specialist support.
Can Cyberexpert replace a RED Notified Body assessment?
No. Cyberexpert supports product scoping, self-assessment and documentation preparation, but it does not replace the manufacturer’s legal responsibility or a RED Notified Body assessment where one is required.
How long does EN 18031 readiness take?
Timing depends on product complexity, architecture and evidence availability. Initial Cyberexpert scoping and requirements generation can take approximately one hour, while completing controls, evidence, testing and technical documentation usually requires additional work.
Will EN 18031 remain relevant after the Cyber Resilience Act applies?
The RED cybersecurity requirements activated through Delegated Regulation (EU) 2022/30 remain applicable until 10 December 2027. That regulation is repealed from 11 December 2027, when the Cyber Resilience Act becomes fully applicable. EN 18031 work can still provide useful technical foundations, but it does not automatically demonstrate CRA compliance.
Keep Building Your RED and EN 18031 Knowledge
EN 18031 compliance services:Translate standard family into product-specific requirements and evidence.
How Cyberexpert works: See the guided journey from product scoping to requirements mapping.
RED cybersecurity compliance: Scope RED Article 3(3) requirements and prepare for assessment.
