Reference
Bench notes
Long-form, sourced notes on how connected devices are tested and which EU obligation each finding lands against. Written for the people who have to sign the declaration of conformity.
In reading order
-
The RED cybersecurity requirements: who is caught, and until when
Article 3(3)(d), (e) and (f) of the Radio Equipment Directive have bound wireless products since 1 August 2025. Who they catch, what they demand, and why the repeal in December 2027 changes less than it looks.
Read the note -
EN 18031: the restrictions that decide your conformity route
Three harmonised standards were cited for the RED cybersecurity requirements, and all three arrived with restrictions. One of them turns a single onboarding decision into the difference between self-declaration and a notified body.
Read the note -
What the Cyber Resilience Act actually asks you to test
Annex I is a list of thirteen product properties and eight process duties, and one of those duties is regular security testing. Here is what each of them means for a device, and which route your product takes through conformity assessment.
Read the note -
The hardware attack surface: what happens on the bench
Debug headers, unpopulated pads, flash chips and radios. What a tester actually does to a board, what “disabled in software” has to mean in practice, and how to design the surface down before the unit ships.
Read the note