Guides · Updated 29 July 2026

EN 18031 vs the CRA: what you actually have to do twice

EN 18031 is already in force for covered radio equipment. The CRA does not turn it into a shortcut. Here is what evidence carries over, what legal work does not, and what changes in December 2027.

The short answer

EN 18031-1, -2 and -3 can give covered radio equipment a presumption of conformity with the RED cybersecurity requirements. They do not give a presumption of conformity with the Cyber Resilience Act. Reuse the product model, test evidence and implemented controls, but make a separate CRA scope and classification decision, map the evidence to CRA Annex I, complete the CRA risk assessment, meet the CRA vulnerability-handling and support duties, and make the CRA conformity statement. The RED cybersecurity delegated act applies to covered equipment placed on the EU market from 1 August 2025 through 10 December 2027. It is repealed when the CRA applies in full on 11 December 2027, but RED market surveillance remains possible for products placed during that window.

The date that matters today is 1 August 2025

Commission Delegated Regulation (EU) 2022/30 made three Radio Equipment Directive cybersecurity requirements apply to defined classes of radio equipment from 1 August 2025. The date was set by Delegated Regulation (EU) 2023/2444. A covered product placed on the EU market now needs that RED conformity work. Waiting for the CRA does not cure the gap.

The three EN 18031 parts follow the three RED requirements. EN 18031-1 covers internet-connected radio equipment and Article 3(3)(d), protection of the network and its functioning. EN 18031-2 covers specified radio equipment that processes personal, traffic or location data and Article 3(3)(e), privacy and personal-data protection. EN 18031-3 covers internet-connected radio equipment that processes virtual money or monetary value and Article 3(3)(f), protection from fraud. One product can need more than one part.

Wi-Fi or Bluetooth does not make every product subject to all three parts. Start with the classes in Delegated Regulation (EU) 2022/30, the data the product processes and whether it handles virtual money or monetary value.

What EN 18031 gives you, and what it does not

Commission Implementing Decision (EU) 2025/138 published the three standards with restrictions. Applying the cited parts can give a presumption of conformity with the matching RED requirement. That presumption belongs to Directive 2014/53/EU. It does not cross over to Regulation (EU) 2024/2847.

The restrictions matter. The sections called “rationale” and “guidance” do not confer a presumption of conformity. A product that lets the user avoid setting and using any password loses the presumption for the cited password clauses. Part 2 also carries a parental or guardian access-control restriction for the listed childcare, toy and wearable classes. Part 3 carries an extra restriction for its financial-asset assessment criterion.

So an EN 18031 test report is evidence, not a CRA certificate. Keep it. Reuse it. Do not rename the legal conclusion at the top of it.

The work you can reuse

Use one evidence base. The product description, architecture, interfaces, data flows, threat analysis, implemented safeguards, test records, known limitations and change history do not become different facts because the law changes. A control tested for EN 18031 may also answer a CRA Annex I requirement. Point the CRA matrix at the same test record instead of running the same test for the sake of a second folder.

The same is true of fixes. If the RED assessment finds a weak default credential flow, an exposed service or a broken update path, fix the product once. Keep one signed result from the fixed build. Then cite that result from each legal mapping it supports.

The work you still have to do for the CRA

  • Scope and classification. RED asks whether the product is radio equipment in one of the classes activated by Delegated Regulation (EU) 2022/30. The CRA asks whether it is a product with digital elements in Article 2 scope, then whether its core functionality puts it in Annex III or Annex IV.
  • Requirements mapping. EN 18031 supports three RED cybersecurity requirements. The CRA has the product requirements in Annex I Part I and the vulnerability-handling requirements in Annex I Part II. Map the evidence to those requirements and write a reason for every requirement marked not applicable.
  • Cybersecurity risk assessment. Article 13(2) to 13(4) requires a documented CRA assessment covering the product lifecycle and placing that assessment in the Annex VII technical documentation.
  • Conformity route. Under the CRA, a default product can use module A. Annex III and Annex IV products follow the stricter Article 32 routes. The RED route and the CRA route are separate decisions even when the same notified body and test evidence are used.
  • Lifecycle duties. The CRA adds vulnerability handling, an SBOM covering at least the top-level dependencies, a coordinated vulnerability disclosure policy, security-update duties and a support period. Passing EN 18031 does not create those records.
  • Article 14 reporting. From 11 September 2026, the CRA reporting duty applies to all products in CRA scope, including products placed on the market before 11 December 2027. RED conformity does not replace the 24-hour, 72-hour and final-report workflow.

One file is fine. One legal conclusion is not

You do not need two copies of every diagram and test. Keep a common evidence set and separate traceability tables for RED and the CRA. Each row should name the legal requirement, the control, the evidence record, the result and any gap. That shows where one record supports both laws without claiming the laws ask the same question.

The EU declaration can also be one combined document where the product is subject to more than one Union act. It still has to identify each act and the standards or other specifications used for each conformity claim. A line that names EN 18031 under the RED does not declare conformity with the CRA.

The bridge ends on 11 December 2027

Delegated Regulation (EU) 2026/339 repeals Delegated Regulation (EU) 2022/30 from 11 December 2027, the date the CRA applies in full. The Commission did this to stop the same radio equipment being subject at the same time to the RED cybersecurity requirements and the CRA requirements.

That repeal does not erase the past. The same act says RED market surveillance and control continue for covered radio equipment placed on the Union market between 1 August 2025 and 10 December 2027. Keep the EN 18031 file for those products. Do not replace it with a later CRA file.

The shortest workable plan

  • Record which of RED Article 3(3)(d), (e) and (f) applies and which EN 18031 part supports it.
  • Close every restriction attached to the standard reference in Decision (EU) 2025/138, or use a conformity route that does not rely on that presumption.
  • Freeze the product description, evidence index and test records as the common evidence base.
  • Run the separate CRA scope and core-functionality classification.
  • Map the common evidence to CRA Annex I, add the missing lifecycle records and choose the Article 32 route.
  • Put Article 14 reporting into operation before 11 September 2026.
  • Retain the RED file for every unit placed through 10 December 2027, then use the CRA route for products placed from 11 December 2027.

Questions people actually ask

Does EN 18031 make my product compliant with the CRA?

No. The references published by Decision (EU) 2025/138 give a restricted presumption of conformity with RED Article 3(3)(d), (e) or (f). They do not give a presumption of conformity with the CRA. The test evidence may still support individual CRA Annex I requirements.

Do I need all three parts of EN 18031?

Not automatically. Part 1 supports the network-protection requirement for internet-connected radio equipment. Part 2 supports privacy and personal-data protection for the classes and data named in Delegated Regulation (EU) 2022/30. Part 3 supports fraud protection for internet-connected radio equipment that processes virtual money or monetary value. A product can fall under more than one.

Can I use one technical file and one EU declaration?

You can keep one common evidence set and may use one combined EU declaration. The file must keep separate traceability to each act, and the declaration must identify every applicable act and the standards or specifications used for each conformity claim.

What happens to EN 18031 on 11 December 2027?

Delegated Regulation (EU) 2026/339 repeals the RED cybersecurity delegated act on that date, when the CRA applies in full. RED market surveillance still applies to covered products placed on the market from 1 August 2025 through 10 December 2027, so retain those files.

Does CRA Article 14 apply before the rest of the CRA?

Yes. Article 71 makes Article 14 apply from 11 September 2026, and Article 69(3) applies it to all products in CRA scope placed on the market before 11 December 2027.