[Free tools](/free-tools)/[European Union](/free-tools/eu)/EN 18031 cybersecurity checker

🇪🇺Free tool · EU

# Does EN 18031 apply to your radio product?

Answer six questions about your product and see which parts of the RED cybersecurity rules apply, which EN 18031 standards cover them, and whether you can self-declare.

Does the product contain a radio (Wi-Fi, Bluetooth, cellular, LoRa, NFC, etc.)?

YesNo

CheckFree · no sign-up · result you can share

## How this works

Since 1 August 2025, radio equipment placed on the EU market must meet three cybersecurity requirements of the Radio Equipment Directive: Article 3(3)(d) protects networks, 3(3)(e) protects personal data and privacy, and 3(3)(f) protects against fraud. Which of them apply depends on what the product does, not on how it's marketed.

Each requirement has a matching harmonised standard: EN 18031-1, EN 18031-2 and EN 18031-3. Applying the relevant parts in full lets most manufacturers self-declare. The main exception is a product that can be used without the user setting a password, where the standards' citation is restricted and a notified body is usually needed.

## Questions

### Does EN 18031 apply to a Bluetooth product with no internet connection?

Usually not. Requirements (d) and (f) need an internet connection. Requirement (e) can still apply without one if the product is a toy, childcare equipment or a wearable that processes personal data.

### Is a product that connects through a phone app internet-connected?

Yes. The Delegated Regulation covers equipment that communicates over the internet directly or via any other equipment, which includes a phone, hub or gateway.

### When did these rules start?

They apply to products placed on the EU market from 1 August 2025. The date was moved from 1 August 2024 by Delegated Regulation (EU) 2023/2444.

### What happens when the Cyber Resilience Act applies?

The CRA applies to products with digital elements from 11 December 2027, with vulnerability reporting obligations from 11 September 2026. Plan your security work so it serves both.

## Related guides

*   [CE RED Testing: Radio Equipment Testing Standards](/guides/ce-red-testing)
*   [RED Article 3(3) Delegated Regulation: Cybersecurity Requirements for Radio Equipment](/guides/eu-radio-equipment-directive-cybersecurity)
*   [RED Cybersecurity Delegated Act (EU) 2022/30: What Connected Product Makers Must Know](/guides/red-cybersecurity-delegated-act)

Regulatory information based on your answers and the sources listed, not legal advice. Krono is not a notified body, test lab or law firm; you remain responsible for your product's compliance.