1. Essential Requirement for Global Regulatory Compliance and CE RED Certification Readiness
Manufacturers are required to satisfy the cybersecurity requirements specified in Article 3.3 (d), (e), and (f) of the Radio Equipment Directive (RED) in accordance with the harmonized standards EN 18031-1, EN 18031-2, and EN 18031-3. Cybersecurity testing based on the EN 18031-1, EN 18031-2, and EN 18031-3 harmonized standards is mandatory for obtaining CE RED certification, representing a critical regulatory shift that all manufacturers aiming to enter the European market must address.2. Advancement of Product Security Quality
Cybersecurity testing enables a practical enhancement of product security by analyzing security vulnerabilities for each product based on international standards.3. Enhanced Personal Data Protection and Increased Consumer Trust
Personal data protection regulations are strengthening worldwide, as consumers increasingly view functionality and security as core factors when choosing IoT products. Products validated through cybersecurity testing not only gain a competitive edge in marketing but also play a decisive role in building trust with global buyers and consumers.- EN18031(applies to wireless devices that use the internet)
Wireless Gateway Devices
(IoT hubs, smart routers, etc.)
Wireless Electronic Devices
(laptops, smartphones, etc.)
Wireless Wearable Devices
(smartwatches, smart glasses, fitness bands, etc.)
Wireless Devices
that Store or Transmit Collected
Personal or Sensitive Data via Mobile Apps or Servers
(home CCTV systems, etc.)
Wireless Payment and
Authentication Devices
(card readers, wireless crypto wallets, etc.)
Industrial IoT Wireless Devices
(automation, monitoring, etc.)
Wireless Devices for Children
(toys, drones, etc.)
Wireless Home Appliances
(smart refrigerators, smart ovens,
smart TVs, etc.)
- ETSI EN 303 645(applies to both wired and wireless devices that use the internet)
Wired and Wireless Communication Devices
Devices That Process Personal and Sensitive Information
Wearable Devices
Smart Home Appliances
IoT Toys and Devices for Children
Wireless Payment and Authentication Equipment
IoT Hubs and Gateway Devices
| Category | EN 18031-1, EN 18031-2, EN 18031-3 | ETSI EN 303 645 | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Target | All wireless equipment that communicates over the internet and falls under the cybersecurity requirements specified in Article 3.3 (d), (e), and (f). | All Consumer IoT Products | ||||||||||||||
| Mandatory Requirement | Mandatory Implementation for CE RED Certification | Certification Guidelines | ||||||||||||||
| Content | Developed under EU policy to prevent security incidents involving internet-connected wireless devices distributed within Europe, this technical standard is based on security and network requirements and includes additional personal data and financial-related requirements according to product characteristics. | Defines the minimum security requirements and privacy protection principles that must be ensured, providing manufacturers and developers with clear security guidelines for design, development, and lifecycle management. | ||||||||||||||
| Test Execution |
Testing of All Applicable Requirements within the Relevant Standard for the Product
|
The framework consists of 15 requirements for both documentation and products,
comprising mandatory and recommended detailed requirements.
Testing is conducted based on the selected requirements according to implemented functionalities and predefined conditions.
|
||||||||||||||
| Standards by Target Device |
|
|
||||||||||||||
| Category | EN 18031-1, EN 18031-2, EN 18031-3 | ETSI EN 303 645 |
|---|---|---|
| Product | Two units of the product with the same model and identical specifications are required. | |
| Required Documents | Firmware / Software Information Product Function Description Technical Specifications User Manual Security Mechanism Implementation Document (Functions & Data) Update Mechanism Implementation Document Protocol Implementation Document Risk Management and Assessment Report Test Plan and Results (Optional) | |
| Duration |
Test clauses and test items vary depending on the applicable standard. Estimated duration: 2 to 4 weeks. |
Varies depending on the functions, complexity, and scope of the items implemented in the product. Estimated duration: 2 to 4 weeks. |
※ ※ The duration is calculated based on the test start date after all required documents have been submitted.
Application
Registration
Required documents for submission and preparation are provided during the in-person meeting after registration.
Agreement
Review of submitted materials followed by agreement on the applicable standards and test scope.
Contract Execution
Issuance of quotations based on standards and scope, followed by contract signing.
Test Execution
Testing is performed for each requirement based on the product and submitted documents.
Issuance of Test Report
Post-Management Process
Follow-up actions after the testing process, including additional tests requested by the Notified Body.
*Post-management applies only to tests under EN 18031-1, EN 18031-2, and EN 18031-3.