CMC10 WEBINAR - 1st of July 2024

RED cybersecurity

Cybersecurity requirements under RED Article 3(3)(d), (e) and (f)

As of 1 August 2025, certain categories of radio equipment placed on the European Union market must also comply with the cybersecurity requirements laid down in Article 3(3)(d), (e) and (f) of Directive 2014/53/EU. These requirements were introduced by Commission Delegated Regulation (EU) 2022/30 and are subjected to be tested by the harmonised EN 18031 series of standards.

The additional essential requirements are intended to improve the cybersecurity of connected radio equipment by ensuring that devices:

  • Article 3(3)(d): do not harm the network or its functioning and do not misuse network resources, thereby preventing an unacceptable degradation of service.
  • Article 3(3)(e): incorporate safeguards to protect the personal data and privacy of users and subscribers.
  • Article 3(3)(f): support features that help protect against fraud, where applicable.

EN 18031 Cybersecurity Evaluation

The EN 18031 series provides harmonised requirements and assessment methods for demonstrating compliance with the cybersecurity provisions of the Radio Equipment Directive.

Depending on the intended use and functionality of the radio equipment, compliance may be demonstrated through the applicable parts of the standard:

  • EN 18031-1 – Internet-connected radio equipment
  • EN 18031-2 – Radio equipment processing personal data, traffic data or location data
  • EN 18031-3 – Radio equipment supporting financial transactions or virtual money

Our experts provide technical assessment and certification services for radio equipment within the scope of these cybersecurity requirements. The evaluation includes the review of the technical documentation, cybersecurity architecture, software security mechanisms, vulnerability management processes, authentication and access control, secure communications, update mechanisms, data protection measures, and other applicable security controls required by the relevant parts of EN 18031.

Certification Services

CerTrust Ltd. supports manufacturers throughout the conformity assessment process for the new RED cybersecurity requirements by offering:

  • Assessment against Article 3(3)(d), (e) and (f) of Directive 2014/53/EU.
  • Evaluation according to the applicable parts of the EN 18031 series.
  • EU-Type Examination where the conformity assessment procedure requires the involvement of a Notified Body.

Manufacturers placing applicable radio equipment on the EU market should ensure that cybersecurity has been considered during product design and development and that the necessary evidence is included in the technical documentation to demonstrate compliance with the applicable essential requirements of the Radio Equipment Directive.