How Long Does CE-RED EN 18031 Certification Take? From Sample Submission to Certificate

2026-08-27

EN 18031 Is Not a Standalone Certificate

Many people assume EN 18031 can be certified on its own. It cannot. It is a supporting compliance standard under the CE-RED Directive, written specifically to meet the radio-equipment cybersecurity requirements in RED Article 3.3(d)(e)(f). All test data and reports are folded into the complete CE technical file, and the manufacturer issues the Declaration of Conformity (DoC) itself to complete compliance. That is why the timeline cannot be split out — it must be calculated together with the full RED certification process.

From 1 August 2025, newly placed EU radio equipment must enforce this standard, under official documents (EU) 2022/30 and (EU) 2025/138. The new rules bind only new products; stock produced before the cutover can still be sold and distributed normally and will not be forced off the shelves. Most ordinary radio equipment can follow Module A self-declaration without a notified body; only high-risk categories need a notified body to review and issue.

1. How Long Does CE-RED EN 18031 Certification Take?

Phase 1: Documentation and threat modelling (1–4 weeks)

How fast the whole project moves depends entirely on early document preparation. You need a risk assessment, a security-architecture description, and the device data-flow diagram ready up front. Document parameters must match the actual sample configuration exactly. Any inconsistency — for example, the documents claim high-grade encryption but the device ships with a weaker setup — is a direct fail and forces a full rework. Companies with mature documentation can finish in one or two weeks; those building from scratch typically need about a month.

Besides paper documents, the debugging sample must be prepared early. Network penetration testing needs access to debug interfaces and system permissions. If you only provide a locked-down mass-production unit, the lab cannot run the debugging work and the test simply cannot proceed. Many industry delays stall right here on late sample preparation, wasting weeks for no reason.

Phase 2: Sample submission and lab testing (2–6 weeks)

Lab testing is the most time-consuming part of the whole certification. EN 18031 splits into three blocks:

·18031-1 (general network security) is mandatory for all connected devices.

·18031-2 applies to devices that handle user privacy data.

·18031-3 applies only to products with payment functions.

A simple connected sensor takes 2–3 weeks; routers and cameras take 3–4 weeks; complex devices such as POS payment terminals need 4–6 weeks of testing. Always send a debug sample plus a production sample — a locked mass-production unit alone cannot complete the full test suite.

There is no need to blindly run the entire test set; match it to product functions. An ordinary smart-home device that does not collect privacy data does not need 18031-2; a product with no payment or transfer function does not need 18031-3. Targeted testing saves substantial cost and time. The firmware under test need not be the final mass-production version — a pre-mass-production candidate is fine, as long as the core security logic is unchanged, which does not affect the final result.

Phase 3: Remediation (highly uncertain)

The most common failures in the test phase are basic issues: weak passwords, unnecessary open ports, and system-configuration vulnerabilities. Minor configuration problems can be fixed in a few days; if they reach the protocol layer or require a security-architecture change, optimisation often takes weeks. There is no shortcut in cybersecurity compliance — even high-risk products going through a notified body cannot pass with unremediated vulnerabilities.

OTA firmware update is a key check item and a frequent industry failure point. A firmware-update interface lacking signature verification or tamper protection fails outright. Most companies' remediation pain centres on OTA; building a secure closed loop into the product design early is far easier than patching firmware and documents later.

Phase 4: Documentation and DoC (within 1 week)

Once all test items pass, you consolidate the complete CE technical file and issue the manufacturer's official Declaration of Conformity. With documents prepared up front, all wrap-up work finishes within a week. RED technical files must be kept for ten years from the product's market launch and be ready for any EU market spot check; when the product iterates or the hardware is revised, the corresponding technical file must be updated and archived in step.

Phase 5: Notified-body involvement (high-risk only, +2–4 weeks)

If the product falls under a high-risk category in RED Annex IV, or triggers a coordination-limiting clause in EN 18031, a notified body must step in to review, adding 2–4 weeks overall. Children's smart devices, medical wearables, and financial payment terminals generally need this notified-body review path.

Be clear: the notified body only performs conformity assessment; it does not waive device security vulnerabilities. The notified-body review standard and remediation requirements are identical to the self-declaration path — there is no way to bypass testing or simplify compliance by using a notified body.

  2. Reference Timeline by Product Type

A connected Bluetooth earphone can complete compliance in 4–5 weeks if the process goes smoothly, with a normal cycle of about 6 weeks. Routers and smart cameras run 6–10 weeks; complex industrial connected equipment can reach 10–14 weeks. We advise starting certification 6–9 months ahead, avoiding the year-end lab booking peak, locking the test slot early, and aligning with your R&D iteration pace.

Also keep RED and CRA separate. RED is the EU pre-market access requirement, fully mandatory since August 2025; the CRA governs product cybersecurity across the full lifecycle and lands in December 2027. The two regulations are independent and must be complied with separately — do not conflate them.


BlueAsia provides end-to-end wireless and multi-country certification and can coordinate EN 18031 together with your RED RF and EMC work, so you plan security in early rather than patch it late.

Contact: King Email:king.guo@cblueasia.com Address: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!