Radio Equipment Directive. Cybersecurity. CE Conformity – Consulting on EN 18031
Since 1 August 2025, the cybersecurity requirements of the Radio Equipment Directive (RED Delegated Act, Regulation (EU) 2022/30) have been mandatory. uwuWARE supports manufacturers, importers and distributors in classifying their products, implementing EN 18031, and building the technical documentation for CE marking.
Scoping and gap analysis: does your product fall under the RED-DA?
Implementation of security mechanisms per EN 18031
Technical documentation, decision trees and conformity evidence
Preparation for the Cyber Resilience Act and EN 40000
RED-DA Consulting for Manufacturers of Connected Radio Equipment
Delegated Regulation (EU) 2022/30 activates the cybersecurity requirements of Article 3(3)(d), (e) and (f) of the Radio Equipment Directive 2014/53/EU. They have applied since 1 August 2025 to all affected devices newly placed on the market.
For manufacturers this means: no robust conformity evidence, no CE marking; no CE marking, no access to the EU market. Non-compliant products risk sales stops, recalls, fines and reputational damage.
uwuWARE is an IT service provider focused on secure, maintainable infrastructure and software development. Our clients come predominantly from the public sector and healthcare — environments where verifiability, documentation quality and regulatory robustness make the difference. We guide you through this process: from the question of whether your product is affected at all, through the technical implementation of the security mechanisms, to audit-ready documentation.
We combine regulatory understanding with technical implementation expertise: we don't just explain what the standard requires, we work with your development team on the concrete implementation.
Which Products Are Affected?
Covered is radio equipment that can communicate with the internet directly or indirectly. Indirect connectivity in particular — for example via a gateway, a bridge or a smartphone app — is frequently underestimated in practice.
- Consumer electronics: smartphones, tablets, wearables, wireless headsets
- IoT & smart home: thermostats, cameras, smart locks, connected household appliances
- Networking: Wi-Fi routers, access points, mesh systems, Zigbee and Bluetooth hubs
- Industry & building technology: connected sensors, fire detectors, access-control systems
- Medical and health products: fitness and vital-data trackers
- Payment devices: mPOS terminals, contactless card readers, NFC transaction devices
Exemptions include, among others, radio equipment without internet connectivity, purely military devices, products under sector-specific frameworks, and medical devices within the scope of the EU medical device regulations.
The harmonised EN 18031 series of standards is the most practical route to demonstrating conformity. The standards work with security mechanisms (including access control, authentication, secure updates, secure storage, secure communication, resilience and cryptography) and with decision trees that determine, for each product individually, which requirement applies. This is exactly where most mistakes happen — and where our consulting comes in.
Presumption of Conformity — but with Limitations
With Implementing Decision (EU) 2025/138, EN 18031 was listed as a harmonised standard. Those who apply it in full can, in principle, assess via Module A (internal production control) without a Notified Body.
However, the presumption of conformity does not apply without limitation. It is lost, among other cases, when a device allows no password to be set at all, in certain access-control constellations for children's toys (EN 18031-2), and for individual test criteria for secure updates in EN 18031-3. The Rationale and Guidance sections of the standards also do not carry a presumption of conformity.
If your product falls into one of these constellations, a Notified Body must be involved. We assess this question early in the project, before it becomes a time and cost risk.
Market Surveillance Is Already Happening
Since 1 August 2025, market surveillance also checks the cyber requirements. In Germany, the Federal Network Agency (Bundesnetzagentur) is responsible; suspected cases can be reported by any natural or legal person — explicitly including competitors, associations and testing bodies. Proceedings are usually not communicated publicly. Hearing nothing does not mean you are not being checked.
From RED-DA to the Cyber Resilience Act
With Delegated Regulation (EU) 2026/339, the Commission has decided to repeal Regulation 2022/30 as of 11 December 2027 — the day the Cyber Resilience Act applies in full.
- Until 10 December 2027: the RED-DA remains fully applicable, with evidence via EN 18031.
- From 11 December 2027: radio equipment with digital elements falls under the CRA (Annex I, future EN 40000).
- Existing products: devices placed on the market between 1 August 2025 and 10 December 2027 remain measurable against the RED-DA thereafter.
The good news: EN 40000 builds conceptually on EN 18031. Anyone working cleanly to EN 18031 today will reuse a large part of the technical evidence for CRA conformity later. That is why we plan your project with both frameworks in mind from the outset.
Our Services in Detail
- Applicability assessment: clarifying whether and via which path your product falls within scope
- Gap analysis: comparing hardware and firmware against the applicable mechanisms of EN 18031
- Threat analysis: structured review using STRIDE, capturing assets and interfaces
- Technical implementation: consulting on secure update, secure boot, key management, cryptography, and hardening of services and interfaces
- Documentation: decision trees, evidence, technical files, input to the EU Declaration of Conformity
- Preparation for test lab or Notified Body: you enter testing with complete documentation, not open issues
- CRA readiness: assessing which measures are reusable for EN 40000
Process
- Free initial consultation. Product, interfaces, timeline, market access — we assess your starting position.
- Scoping & gap analysis. We determine the applicable parts of the standard and the relevant mechanisms and document the gaps.
- Implementation. Together with your development team, we close the technical and documentation gaps.
- Evidence. You receive audit-ready technical documentation as the basis for CE marking and market surveillance.
Frequently Asked Questions
Does the RED-DA also apply to existing products?
The decisive factor is the point of placing on the market. Radio equipment placed on the market before 1 August 2025 remains subject to the previous requirements, as long as it is not placed on the market again.
Do I necessarily need a Notified Body?
Not if EN 18031 is applied in full and none of the known limitations of the presumption of conformity apply. If the standard is only applied in part, a Notified Body is required.
My device only reaches the internet through an app. Am I affected?
Very likely yes. Radio equipment that communicates with the internet indirectly via another device is also covered.
Is RED-DA compliance still worth it if the CRA takes over in 2027?
Yes. The RED-DA applies without limitation until 10 December 2027, existing products remain testable beyond that, and the work feeds into CRA conformity.
Does uwuWARE carry out the conformity assessment itself?
We advise, analyze and prepare the evidence. For accredited testing and certification, we work together with test labs and Notified Bodies.