◉ Introduction to EU EN 18031 Network Security Certification
EN 18031 is a mandatory standard in the European Union for network security, privacy protection, and anti fraud capabilities of radio equipment, and is a supplementary regulation to the European Union Radio Equipment Directive (RED) (EU 2022/30). The purpose is to ensure that networked devices (such as mobile phones, wearable devices, etc.) have the ability to resist network attacks, protect user privacy, and prevent financial fraud, enhancing consumer trust in the product.
The bill requires all radio equipment entering the EU market to comply with the network information security requirements of Article 3 (3) (d), (e), and (f) of the RED Directive, otherwise sales will be prohibited and will be enforced from August 1, 2025.
◉ Scope and requirements of application
01. EN 18031-1: Detection of radio equipment connected to the Internet
- Mobile phones, tablets
- Wi Fi routers and gateways
- Internet connected air conditioners, refrigerators, and other household appliances
- Smart TVs/TV boxes and 3G/4G/5G devices
- All devices with wi-F ì communication capabilities
- Vehicle networking components
- Power converters in energy systems
Security requirements for networking functions: for radio equipment connected to the Internet, it mainly evaluates the security of network assets, including resisting network attacks, preventing network resource abuse and service interruption.
02. EN 18031-2: Networked wireless devices, children's wireless devices, toy wireless devices, wearable wireless devices, etc
- Bluetooth connected phones, headphones, or speakers, including TWS
- Smart watches and other mobile devices
- Intelligent sensors, air purifiers, vacuum cleaners
- Baby monitors and 3G/4G/5G devices
- Vehicle networking components
- GPS tracking device
Data security requirements: For wireless devices that process personal data, particular attention should be paid to privacy protection, requiring devices to have access control, data encryption, and privacy protection mechanisms.
03. EN 18031-3: Radio equipment for processing virtual currency or currency value via Internet connection
- POS machines, ATM machines
- Devices that support any type of transfer
Financial functional security requirements: For devices that handle virtual currency or currency value, it is required to have anti fraud functions such as logging, software integrity verification, etc.
◉ Standard analysis
The EN 18031 series standards are divided into three parts, namely EN 18031-1, EN 18031-2, and EN 18031-3, which correspond to the requirements of Article 3 (3) of the RED Directive (d), (e), and (f), respectively. Some chapters of the EN 18031 series standards are not considered coordinated in some cases, and in the absence of coordination, products must be certified by a designated notified body (NB) before they can be put into the market.
|
RED Directive Terms |
Corresponding to the coordinated standard EN 18031 |
Restrictive conditions |
| Article 3.3 (d): Devices related to network protection; (Internet connected radio equipment) |
EN 18031-1 Common safety requirements for radio equipment - Part 1: Radio equipment connected to the Internet; |
Require users to set and use passwords. If users are allowed not to set passwords, the EN 18031-1/2/3 standards will lose coordination. |
| Article 3.3 (e): Devices for processing personal data, traffic data, or location data; |
EN 18031-2 Common safety requirements for radio equipment - Part 2: Data processing of radio equipment, including networked radio equipment, children's radio equipment, toy radio equipment, and wearable radio equipment; |
It is required to ensure access control for parents or guardians. If incompatible modes such as "autonomous access control" are used, the EN 18031-2 standard will lose coordination. |
| Article 3.3 (f): Radio equipment that enables holders or users to transfer money, monetary value, or virtual currency as defined in Article 2 (d) of EU Directive 2019/713. |
EN 18031-3 Common safety requirements for radio equipment - Part 3: Radio equipment handling virtual currency or currency value via Internet connection. |
Require security updates to be implemented through multiple mechanisms. If a single method (such as digital signature or access control) is used to implement security updates, it will not be sufficient to meet financial security requirements, and the EN 18031-3 standard will lose coordination. |
Be careful:
The requirements of Article 3: Section 3.3 (d), (e), and (f) of the RED Directive do not apply to medical devices and equipment within the scope of MDR regulations.
The requirements of Article 3: Section 3.3 (e) and (f) of the RED Directive do not apply to aviation or road traffic related equipment within the scope of Regulation (EU) 2018/1139, Regulation (EU) 2019/2144, and Directive (EU) 2019/520.
◉ Testing requirements
In order to ensure consistency in testing requirements among the three parallel standards (EN 18031-1/2/3), the new standard introduces the concept of "assets" as the main testing object and classifies "assets" according to different standard testing requirements.
|
Standard |
EN 18031-1 |
EN 18031-2 |
EN 18031-3 |
|
RED Directive related clauses |
3.3.(d) |
3.3.(e) |
3.3.(f) |
|
Security asset |
√ |
√ |
√ |
|
Network asset |
√ |
|
|
|
Privacy asset |
|
√ |
|
|
Financial asset |
|
|
√ |
The test contents of the EN 18031 series standards are shown in the table below, requiring "Conceptual assessment", "Functional completeness assessment", and "Functional sufficiency assessment" to be conducted on these test contents.
|
Standard |
General requirements |
Special requirements |
|
EN 18031-1 |
Access Control Authentication Secure Update Secure Storage Secure Communication Confidential Cryptographic Keys General Equipment Capabilities Cryptographic Best Practice |
For security and network assets: Resilience Network Monitoring Traffic Control |
|
EN 18031-2 |
For security and privacy assets: Parental Control Logging Deletion User Notification External Sensing Capabilities |
|
|
EN 18031-3 |
For safety and financial assets: Logging Equipment Integrity (Secure Boot) |
◉ Assessment scope and certificate type
We need to confirm whether your product meets the network security requirements of RED. RED DA evaluation criteria reference:
1. All radio products that can be connected to the Internet need to consider EN 18031-1.
2. If the radio products (involving personal data/flow data/location data) are also Internet connected devices/baby care devices/children's toys/wearable devices, then EN 18031-2 should be considered.
3. Radio equipment, which can connect to the Internet and involves virtual currency payment, needs to consider EN 18031-3.
Certificate and report types:
1. NB certificate+report;
2. VOC+report;
3. Evaluation report.
◉ Compliance recommendations
EN-18031 network security requirements will be enforced from August 1, 2025, and all products entering the EU market and continuing to be sold before that date must also comply with the new requirements. Manufacturers need to take action as soon as possible to ensure that wireless products comply with these network security standards.
As a professional third-party testing and certification service organization, Jiayu Testing has qualifications such as CMA, CNAS, CBTL, CCC, and has obtained laboratory accreditation from multiple authoritative certification agencies at home and abroad. It is equipped with advanced instruments and equipment, has a skilled professional technical team, rich industry service experience, and strong testing technology capabilities. It is proficient in various regulatory standards. Jiayu Testing can provide customers with one-stop network security testing and certification services for RED DA. If you need to understand the network information security requirements of RED Directive EN 18031 standard or obtain the EU EN 18031 network security certification compliance solution. Welcome to contact usat 400-9269-886 !
Recommended for you
Wechat Public
Account
Hotline
Hotline
Follow
The Public
Follow Us
- Back