EN 18031 work can provide useful input for Cyber Resilience Act preparation, but it cannot simply be relabelled as CRA conformity evidence. A product-specific risk assessment and a clear view of the final cited standards remain essential.
Start with the different legal frameworks
The EN 18031 series supports the cybersecurity requirements for specified categories of radio equipment under Article 3(3)(d), (e) and (f) of the Radio Equipment Directive (RED). Its three parts address network protection, protection of personal data and privacy, and protection against fraud.
| Part | RED essential requirement | Main purpose |
|---|---|---|
| EN 18031-1 | Article 3(3)(d) | Protection of networks from harm and misuse of network resources |
| EN 18031-2 | Article 3(3)(e) | Protection of personal data and privacy |
| EN 18031-3 | Article 3(3)(f) | Protection against fraud |
The RED cybersecurity regime introduced by Delegated Regulation (EU) 2022/30 has applied since 1 August 2025. The references to EN 18031 were published with defined limitations, so applying the standards does not create an unlimited presumption of conformity. In particular, rationale and guidance material does not itself confer that presumption, and further limitations apply to specified password, access-control and assessment provisions. Commission Implementing Decision (EU) 2025/138 sets out those references and limitations.
The Cyber Resilience Act (CRA) is broader. Most of its provisions apply from 11 December 2027. Its essential cybersecurity requirements include the elements covered by RED Article 3(3)(d), (e) and (f), but they also include further product-security and vulnerability-handling requirements. CRA recital 30 expressly requires earlier RED standardisation work to be considered, which creates continuity, not legal equivalence. Regulation (EU) 2024/2847 remains the controlling legal text.
Treat EN 18031 records as a gap-analysis input
Existing EN 18031 records can be valuable. They may already document product features, threat considerations, testing, access controls, authentication, communications security, data storage or cryptographic key management. Those records can reduce duplicated effort when preparing a CRA compliance case.
However, the right question is not whether an EN 18031 requirement has a similar name in later CRA standardisation work. The question is whether the evidence supports the relevant CRA requirement for the particular product, its intended purpose and its reasonably foreseeable use.
A practical review should identify:
- the EN 18031 requirements assessed and the evidence retained;
- the product assumptions that supported each conclusion;
- controls that remain relevant under the CRA;
- requirements that go beyond the earlier RED assessment; and
- evidence that must be updated because the product, deployment context or threat picture has changed.
This is a claim-by-claim exercise. Reusing a test report or design record may be appropriate, but simply changing its labels is not enough to establish CRA conformity.
Revisit old non-applicability decisions
EN 18031 assessments often needed to establish whether a mechanism applied to the product. A documented conclusion that a mechanism was not applicable may still be useful background, but it deserves fresh scrutiny under the CRA.
The CRA requires manufacturers to perform and document a cybersecurity risk assessment for the product. That assessment must take account of reasonably foreseeable use and the cybersecurity risks associated with the product. It informs whether, and how, the relevant requirements apply.
Consider an operator panel on a machine. An earlier assessment might have assumed that only authorised staff could physically reach it. If visitors, contractors or other users can reasonably access the area, that assumption may need reconsideration. The issue is not that every panel necessarily needs the same control. It is that the risk assessment must support the conclusion for the actual operating environment.
Reviewing old non-applicability decisions is therefore particularly important where they relied on narrow assumptions about physical access, user roles, connectivity, updates or data flows.
Plan for CRA work that RED did not cover
The CRA contains requirements that go beyond the three RED cybersecurity requirements supported by EN 18031. Annex I includes product-security obligations as well as separate vulnerability-handling requirements.
For planning purposes, teams should expect to examine areas such as:
- minimising data processing to what is necessary for the intended purpose;
- secure default settings and the product's initial configuration;
- management of software components and updates;
- resilience and recovery following incidents;
- protection of data while it is processed; and
- vulnerability identification, handling and remediation.
The exact standardised route for demonstrating conformity will depend on the applicable standards and their scope. The underlying regulatory obligations should nevertheless shape design and assurance work now. Documentation alone cannot compensate for a security control that was never designed, implemented or tested.
Follow CRA standardisation without treating drafts as law
The Commission's CRA standardisation request, known as M/606, covers 41 requested horizontal and product-specific standards. CEN-CENELEC and ETSI accepted the request in April 2025. The programme includes work on generic requirements as well as work for particular product categories. The Commission's overview of CRA standardisation and CEN-CENELEC's notice on M/606 describe that programme.
CEN-CENELEC has described EN 40000-1-4 as developing generic security requirements through a library of controls, objectives and assessment criteria. That makes it useful planning context, but it is not a substitute for the CRA itself and should not be presented as settled, cited conformity evidence while its status remains unfinished. CEN-CENELEC's EN 40000-1-4 event record provides this description.
Under CRA Article 27, a presumption of conformity depends on a reference in the Official Journal and is limited to the requirements covered by the relevant standard or part of a standard. A draft, work item, standardisation request or adopted standard without the necessary Official Journal reference does not by itself confer that presumption.
Check whether product-specific standards matter
A horizontal standard may not be the only relevant route. The CRA standardisation programme also includes product-specific work. The appropriate route depends on the product category, the scope of the eventual standard and any Official Journal reference.
For that reason, avoid assuming in advance that every radio product will use the same horizontal standard, or that a product-specific standard will necessarily replace all other evidence. Instead, maintain a regulation-led compliance case and monitor:
- the final scope of applicable standards;
- their publication and revision status;
- Official Journal references and any limitations attached to them; and
- the relationship between the product's risk assessment and the requirements covered.
This approach is especially important where a product has industrial, operational technology or specialised networking characteristics.
Understand the limited transition for certificates
CRA Article 69 provides a time-limited transition for certain EU-type examination certificates issued under other Union harmonisation legislation. The provision can be relevant to some RED certificates, but its effect depends on the actual certificate, the requirements it covers and the product concerned. It should not be treated as a general transition for every RED declaration of conformity or every EN 18031 assessment.
The sensible next step is to review each certificate and supporting technical file against Article 69 and the CRA requirements it may affect. Product-specific legal and conformity-assessment advice may be needed where the scope is uncertain.
Build a regulation-led compliance case now
Waiting for every standard to be finalised can delay design decisions that take time to implement. The more durable approach is to work from the CRA's product-specific risk assessment and essential requirements, then use standards as they become available and appropriately cited.
Existing EN 18031 work is a strong starting point when it is mapped carefully, challenged where assumptions have changed and supplemented for the wider CRA scope. It is not a shortcut to CRA conformity. The evidence must still show that the product meets the requirements that apply to it.
The standardisation position described here is based on information available in August 2026. It is not legal advice, a conformity assessment or publication approval.