
Cybersecurity requirements under RED Article 3(3)(d), (e) and (f)
As of 1 August 2025, certain categories of radio equipment placed on the European Union market must also comply with the cybersecurity requirements laid down in Article 3(3)(d), (e) and (f) of Directive 2014/53/EU. These requirements were introduced by Commission Delegated Regulation (EU) 2022/30 and are subjected to be tested by the harmonised EN 18031 series of standards.
The additional essential requirements are intended to improve the cybersecurity of connected radio equipment by ensuring that devices:
EN 18031 Cybersecurity Evaluation
The EN 18031 series provides harmonised requirements and assessment methods for demonstrating compliance with the cybersecurity provisions of the Radio Equipment Directive.
Depending on the intended use and functionality of the radio equipment, compliance may be demonstrated through the applicable parts of the standard:
Our experts provide technical assessment and certification services for radio equipment within the scope of these cybersecurity requirements. The evaluation includes the review of the technical documentation, cybersecurity architecture, software security mechanisms, vulnerability management processes, authentication and access control, secure communications, update mechanisms, data protection measures, and other applicable security controls required by the relevant parts of EN 18031.
Certification Services
CerTrust Ltd. supports manufacturers throughout the conformity assessment process for the new RED cybersecurity requirements by offering:
Manufacturers placing applicable radio equipment on the EU market should ensure that cybersecurity has been considered during product design and development and that the necessary evidence is included in the technical documentation to demonstrate compliance with the applicable essential requirements of the Radio Equipment Directive.