2026 CE‑RED EN 18031 New Rules|Mandatory Deadlines and Compliance Myths

2026-08-13

For wireless hardware exporters to the EU, EN 18031 cybersecurity assessment is now unavoidable. The standard took effect on 1 August 2025 – by 2026 it's been in place for over a year – yet many manufacturers still don't understand the details. Online interpretations are fragmented – and many present draft content as final rules – misleading companies. This article, based on current July 2026 requirements, clarifies the most widespread misconceptions.


1. Mandatory Timeline – Key Points

1.1EN 18031 – unified implementation

From 1 August 2025, any wireless connected device first placed on the EU market must meet EN 18031. The rumoured "two‑phase" implementation does not exist – the so‑called "2024 new vehicles first, 2026 all vehicles" is false. The criterion is simply date of market placement – not vehicle vs. consumer product.

Key distinction: the compliance boundary is market placement datenot production date. Goods already in the EU distribution channel and placed on the market before 1 August 2025 – can continue to be sold. Products placed on the market after 1 August 2025 – must complete EN 18031 assessment. No buffer for new products – all compliance must be complete before formal sale.

1.2 2026 – platform reviews and market surveillance

From 15 December 2025, Amazon EU began routine document checks. Wireless IoT hardware, wearables, and connected‑vehicle peripherals – without complete EN 18031 assessment materials – are delisted. In 2026, Temu and SHEIN also tightened backend standards – EN 18031 assessment documents are now a mandatory verification item.

In Q1 2026, Germany's BNetzA, the Netherlands' RDI, and Sweden's PTS conducted joint special inspections – focusing on cross‑border wireless smart hardware – especially unbranded products lacking security assessment. Surveillance data is shared across the EU market‑surveillance system – if one country finds non‑compliance, others increase checks on similar products.

1.3 Don't confuse UN R155 and EN 18031 timelines

Many teams confuse the two:

·UN R155: vehicle‑level – new vehicle types from July 2022 – all production vehicles from July 2024.

·EN 18031: wireless terminals – from August 2025.

They are independent – different scopes. UN R155 covers vehicle safety systems – EN 18031 covers wireless communication terminals. They cannot substitute for each other – OEM and wireless module projects should progress independently.


  2. Limitation Clauses – Determine Your Certification Path

2.1 Devices with account/password login

This traps many manufacturers. If the device allows blank‑password login and does not force first‑boot password change – self‑declaration is not allowed – a Notified Body (NB) assessment is required.

Only devices that force first‑boot password change and permanently disable blank‑login can use self‑assessment. Devices using hardware keys or Bluetooth pairing – with no account/password system – are not subject to this clause.

Review focus: factory default configuration – not just hardware capability. Many assume hardware supporting passwords is sufficient – but reviewers check default settings and manual descriptions.

2.2 Children's toys and monitoring devices

EN 18031-2 specifically covers children's toys and monitoring terminals. If the product cannot fully implement parental‑control clauses 6.1.3–6.1.5 – NB assessment is required. Even with full implementation, regulators recommend NB for high‑risk categories – reducing post‑market non‑compliance risk.

Children's categories are a long‑term EU enforcement focus – safety assessment materials must include test screenshots and complete verification evidence – not just a one‑line conclusion. Rejection rates for these categories remain high.

2.3 Financial payment terminals

Very limited flexibility. Connected POS terminals and payment terminals – cannot rely solely on OTA security updates to meet anti‑fraud and transaction‑traceability requirements – NB assessment is required in most cases – self‑declaration applies very rarely. Financial terminals have higher key protection, transaction security, and tamper‑proof requirements – documentation depth is greater – allocate sufficient time.

2.4 Standard annexes – interpretation traps

Annexes and explanatory notes are reference only. The only legally valid basis for compliance is the main normative clauses. When doing gap analysis or NB review – annex content cannot be cited as compliance evidence. Many companies have tried using annex wording in discussions – only to be told to re‑work the gap analysis against the main clauses – extending timelines unnecessarily.


  3. Test and Assessment Coverage

3.1 Three parts – different product categories

·EN 18031-1: general connected devices.

·EN 18031-2: children's products and monitoring devices.

·EN 18031-3: financial payment terminals.

Some products cover multiple parts – e.g., a children's smartwatch with payment functionality – must complete both -1 and -2.

3.2 Core assessment areas

·Cryptography: TLS protocol version, key length, RNG quality.

·Access control: default passwords, privilege levels, session management.

·Software security: firmware upgrade logic, signature verification, secure boot chain.

·Privacy: data collection scope, transmission encryption, local storage protection.

Penetration testing is core – covering network attack surfaces, local hardware interfaces, and wireless protocol attack surfaces – with vulnerability scanning and manual re‑testing. The final test report must clearly list vulnerability risk levels and remediation plans.

3.3 Documentation workload often exceeds testing

Testing time is relatively manageable – documentation is the biggest time sink. Mandatory documents:

·TARA threat analysis and risk assessment report.

·Security architecture description.

·Cryptographic design documentation.

·Supply‑chain security statement.

·Long‑term vulnerability management plan.

Documentation must match the actual product. Common example: document claims AES‑256 hardware encryption – but the product only uses software simulation – rejected.


  4. Certification Path Selection

4.1 Self‑declaration vs. NB assessment – boundary

·Financial payment wireless terminals: generally require NB‑issued EU‑Type Examination reports.

·Ordinary aftermarket T‑Boxes and dashcams: generally allow manufacturer self‑declaration (DoC).

There is no "whole‑vehicle mandatory NB" requirement – vehicles themselves are not covered by EN 18031. There is no vague "high‑risk connected devices mandatory NB" – the boundary is clear: financial‑payment category. Don't be misled by third‑party marketing – assess your product category first.

4.2 NB review fees reference

·Financial terminals: €5,000–12,000 typically.

·Most aftermarket vehicle products: no NB involvement – only lab test fees – no additional NB charges.

Fees vary by document review depth and included free remediation rounds. Before signing, confirm how many free review rounds are included.

3. CSMS is not EN 18031

CSMS is a UN R155 whole‑vehicle requirement – only for whole‑vehicle type approval. EN 18031 wireless compliance does not require a full CSMS – only product‑level TARA reports. Some agencies confuse the two to inflate budgets – adding at least six months unnecessarily.


  5. CRA Integration and Transition

5.1 CRA key dates

·11 June 2026: CRA operator obligations take effect.

·11 September 2026: vulnerability and security incident reporting take effect.

·11 December 2027: CRA full implementation – RED cybersecurity provisions will be phased out – EN 18031 will gradually be withdrawn – final details to be confirmed by EU Official Journal.

During the transition (until December 2027), EN 18031 assessment is sufficient for market access. Don't delay launches waiting for CRA – the two systems run in parallel.

5.2 Document reuse and mutual recognition

Currently, no legislation allows CRA compliance to substitute for EN 18031. Mutual recognition is still in draft discussion – not legally binding. However, EN 18031 materials (security architecture, penetration test reports) can be reused for CRA preparation.

CRA scope is broader than EN 18031 – covering wired hardware, software platforms, and cloud services. Passing EN 18031 does not automatically satisfy all CRA clauses. For smart‑home gateways and IoT controllers – prepare EN 18031 documentation with CRA in mind – saving work later.

5.3 Non‑compliance risks

·Customs detention, platform delisting, mandatory recalls.

·Maximum fines: up to 4% of global annual revenue – same level as GDPR.

·Importers and distributors also bear joint liability.

In 2026, offline automotive retail channels and cross‑border platforms generally require pre‑supplied test reports – non‑compliance leads to contract termination. EU market‑surveillance information sharing means if one member state finds issues – others increase checks on similar goods.

5.4 Practical planning advice

·Start security architecture design early – don't wait until testing.

·Before hardware finalisation – conduct security design reviews.

·At concept design – start drafting the TARA report.

·Hardware‑level changes later are exponentially more expensive.

Before formal submission, do an internal gap analysis against EN 18031 main clauses – fix non‑conformities in advance. Consider pre‑testing to reduce formal‑stage rework. Run document and test teams in parallel – update TARA and security documents during testing – don't wait until all tests are complete.

EN 18031 is a hard market‑access threshold – no opt‑out. Implement it early to align with product launch timelines.


For 2026 CE‑RED EN 18031, contact BlueAsia at 13534225140 (King) or email king.guo@cblueasia.com.