Under the EU Radio Equipment Directive 2014/53/EU, Article 3(3) points (d), (e) and (f) govern network security, privacy and fraud prevention. The obligation has applied to radio equipment placed on the EU market since 1 August 2025.
The trigger logic uses three rulers: internet-connectable pulls in at least (d); processing personal, traffic or location data adds (e); locally storing, processing or settling monetary value or virtual currency adds (f). Note that "can transfer money" does not by itself trigger — an ordinary barcode scanner only reads codes and does not settle value locally, so it may not hit (f).
(d) maps to EN 18031-1, covering network-asset protection: the device must not damage the network, must not serve as an attack springboard, and must not open ports it should not. Internet-connected radio equipment basically all falls in this scope.
(e) maps to EN 18031-2, covering privacy assets. Wearables, cameras, child-care devices and Bluetooth earbuds with a companion app that process personal data need access control, encryption and privacy-protection mechanisms.
(f) maps to EN 18031-3, covering financial assets. Devices that locally store, process or settle monetary value — payment terminals, models that support transfers — need anti-fraud capability, with logging and software-integrity verification counting.
Some clauses in the standards carry limitation conditions. Trigger any one and the corresponding standard loses its coordinated status: the manufacturer cannot self-declare and must bring in a notified body. Miss this at the front end and discover later that self-declaration is unavailable, and the budget often breaks at exactly that moment.
The first is passwords. The limitation targets "allows the user to set and use no password at all" — a blank-password login. A factory default password itself does not trigger, as long as the user is forced to change the default at first boot. The change is small, but it must be decided at the design stage. (Also disable generic default passwords.)
The second is parental control on children's devices. For child-care and toy categories covered by EN 18031-2, failing to secure parental or guardian access control per clauses 6.1.3 to 6.1.6 loses coordination.
The third is security updates on financial devices. Clause 6.3.2.4 lists four types — digital signature, secure communication, access control and other — and any single one is insufficient; that judges non-compliance.
Medical devices under MDR are fully exempt from all three of 3.3(d)(e)(f), following their own compliance path. Devices under (EU) 2019/2144 road traffic, (EU) 2018/1139 aviation and (EU) 2019/520 electronic tolling are exempt only from (e) and (f); point (d), network protection, has no other regulation covering it and most still must be met.
Vehicle terminals depend on how they are sold. OEM fitment riding with the whole vehicle follows UNECE R155, where (e) and (f) are covered by the vehicle regulation — but (d) still must be met. Aftermarket 4G modules, head units and wireless GPS, sold and circulating as standalone products, cannot escape the full (d)(e)(f).
Security architecture description, threat modeling, compliance evidence for each control measure, vulnerability-scan and functional-test records, and user-facing security guidance. These get genuinely reviewed, and whether the documents are complete changes the review speed substantially.
Beyond testing, several things matter equally. Encryption strength, secure boot, signature verification with anti-rollback, log retention and data minimization should go through a gap analysis before the lab, cheaper than fixing while testing. On communication encryption, TLS 1.0, 1.1 and all SSL versions are disabled; TLS 1.2 or 1.3 is allowed, with 1.3 preferred as common practice — the standard does not mandate it, and keeping 1.2 for compatibility is fine.
EN 18031 is a product-level requirement for the radio equipment itself. The horizontal Network Resilience Act is a separate track landing later; each governs its own, so do not treat one as the whole.
This standard is also not the only route. A company can take another technical path for equivalent proof, but an equivalent path earns no presumption of conformity, the technical-argument bar is very high and review risk is large — a body may not accept it. Most projects simply choose EN 18031 to avoid arguing with the reviewer.
Run a gap assessment first, pulling out the high-frequency issues — password policy, update mechanism, access control — for remediation before formal testing, avoiding a mid-test judgement that flips you into notified-body review.
For connected-car, IoT and multi-country export products, BlueAsia's one-stop testing and certification merges cybersecurity assessment with RF and EMC testing into one schedule, with unified document archiving and corrections tracked together.
Write the password requirement into the spec at the requirements stage: no blank-password login at factory, force a default-password change at first boot, disable generic default passwords.
Design the security-update mechanism early. Signature verification with anti-rollback is the hinge for whether you can avoid several of the limitation conditions later.
Do not treat cybersecurity as one question on the test checklist. It is design work; patching it after the sample exists means reworking the architecture, and the cost and schedule are not in the same league.
Contact: King Email: king.guo@cblueasia.comAddress: Building C, Hongjingda Industrial Park, No. 107 Beihuan Road, Shiyan Street, Bao'an District, Shenzhen, China BlueAsia delivers more than service!
Related News