Aug 12, 2026

What is EN 18031? The cybersecurity requirements behind your CE marking

Since 1 August 2025, wirelessly connected devices must meet cybersecurity requirements for CE marking. What EN 18031 demands and what to do about it now.

What is EN 18031? The cybersecurity requirements behind your CE marking

Since August 2025, a CE marking also demands cybersecurity

If you make or sell a device with WiFi, Bluetooth, 4G or LoRa inside, something fundamental changed on 1 August 2025: cybersecurity became a legal requirement for the CE marking. A tracker, a smart sensor, a machine with a modem in it: without demonstrable security, the product is no longer allowed onto the European market.

The legal route is as dry as it is important. The Radio Equipment Directive (RED, 2014/53/EU) already contained dormant articles on network protection, privacy and fraud. Delegated regulation (EU) 2022/30 activated those articles, and since 1 August 2025 they are mandatory. The series of standards you use to demonstrate compliance is called EN 18031.

The three parts of EN 18031

EN 18031 consists of three parts, each covering one article of the RED:

  • EN 18031-1, network protection: the device must not harm or misuse the network. Think secure access, a protected update mechanism and protection against takeover.
  • EN 18031-2, privacy: devices that process personal data must protect it, from encrypted communication to access control.
  • EN 18031-3, fraud protection: devices that handle payments or monetary value must prevent fraud.

For most industrial products, part 1 always applies and part 2 applies as soon as personal data is involved. Part 3 mainly matters for payment functions.

Which devices does this apply to?

In short: radio equipment that can communicate with the internet, directly or through another device. That is a broad category, and industrial products are squarely in it:

  • IoT sensors and trackers with 4G/5G, LoRaWAN, WiFi or Bluetooth.
  • Gateways and edge devices that forward machine data.
  • Machines and installations with a built-in wireless module.
  • Consumer devices, wearables and connected toys.

Wired-only equipment falls outside the RED. But beware: one wireless module in the design, and the entire device has to comply.

What does the standard actually demand from a device?

The standard text is extensive (and sold through the standards bodies, such as NEN), but in practice the requirements come down to a recognizable list:

  • Secure access: no default passwords, no open ports nobody uses.
  • Encrypted communication between device and cloud.
  • A protected update mechanism: updates must be possible and signed.
  • Secure boot, so the device won't start foreign firmware.
  • A documented risk assessment: which threats exist, and what does the design do about them?

Anyone who has seen a security review of an IoT product will recognize the list. The difference is that this is no longer best practice, it is a condition for market access.

Self-assessment or a notified body?

On 28 January 2025, the three parts of EN 18031 were published as harmonised standards in the Official Journal of the EU, with restrictions. That distinction decides your route:

  • If you apply the standard in full and the restrictions don't touch your product, the presumption of conformity holds and you may declare conformity yourself, without an external party.
  • If a restriction does touch your product, a notified body has to assess the device before it can go to market.

The best-known restriction concerns passwords: if the user can put the device into service without setting a password where one belongs, the presumption of conformity falls away. Exactly the kind of detail you want to catch at the design stage, not at the test lab.

What does this mean for existing products?

There is no transition period anymore: whatever is placed on the market since 1 August 2025 has to comply. For existing products there are three scenarios, in ascending order of impact:

  1. The device largely complies and a firmware update closes the gaps (update mechanism, password policy, turning encryption on).
  2. The hardware can handle it, but the firmware needs to be rebuilt, for instance because secure boot and signed updates are missing.
  3. The hardware itself lacks the foundation (no secure element, no suitable microcontroller): then a redesign is the honest conclusion.

Which scenario applies follows from an assessment of the existing design. That is days of work, not months, and it prevents investing in a product that can no longer be sold.

IoT circuit board designed by Meshnex with a cellular modem

And the Cyber Resilience Act is next

EN 18031 is the first wave, not the last. The Cyber Resilience Act (CRA) entered into force at the end of 2024 and touches nearly every product with digital elements on the European market, wireless or not:

  • From 11 September 2026, reporting of actively exploited vulnerabilities and severe incidents becomes mandatory.
  • From 11 December 2027, the full obligations apply: security by design, a maintained software inventory (SBOM) and security updates across the expected product lifetime.

The practical consequence for hardware: a device without a secure, signed update mechanism will soon be unsellable. Whoever designs a product now is designing for both regimes at once.

Security starts at the schematic, not at the test lab

Secure boot needs a microcontroller that supports it. Encryption needs processing power and sometimes a secure element. A signed update mechanism needs memory headroom and a well-designed bootloader. These are hardware choices, and they are cheap on the schematic and expensive afterwards.

Meshnex designs and builds hardware and firmware in-house, with the requirements of EN 18031 and the CRA built in from the first schematic line. See how we approach that in custom hardware & PCB development, or get in touch if you want to know where your product stands: from a quick scan of an existing design to a new, certifiable device.

Back to Blog