iotpentest

EN 18031: the restrictions that decide your conformity route

Updated 8 min read

A harmonised standard is a shortcut: apply it and you are presumed to conform. The EN 18031 series was cited in the Official Journal with that shortcut partly blocked. Understanding exactly where it is blocked is the highest-value hour a product team can spend on this regime.

What a harmonised standard actually buys you

European product law rarely tells a manufacturer how to build something. It sets essential requirements and then leaves the technical detail to standards bodies. When the Commission is satisfied that a standard expresses an essential requirement properly, it cites the standard in the Official Journal, and a product built to that standard is presumed to conform to the requirement it supports.

The presumption is not a formality. Under Article 17 of Directive 2014/53/EU it is what allows a manufacturer to use internal production control for the Article 3(3) essential requirements: a self-declaration route, with no third party in the loop. Lose the presumption and the same product must go through EU-type examination followed by conformity to type, or full quality assurance. Both involve a notified body, both take months, and both cost real money.

So the citation is worth reading in detail, including the column most people skip.

The three parts and what each supports

Commission Implementing Decision (EU) 2025/138 of 28 January 2025 amended Implementing Decision (EU) 2022/2191 to add three harmonised standards supporting the cybersecurity requirements activated by Delegated Regulation (EU) 2022/30.

The EN 18031 series as cited in the Official Journal
StandardScopeSupports
EN 18031-1:2024Internet connected radio equipmentArticle 3(3)(d): no harm to the network, no misuse of network resources
EN 18031-2:2024Radio equipment processing data: internet connected, childcare, toys and wearable radio equipmentArticle 3(3)(e): safeguards for personal data and privacy
EN 18031-3:2024Internet connected radio equipment processing virtual money or monetary valueArticle 3(3)(f): protection from fraud
Titles as given in the Annex to Commission Implementing Decision (EU) 2025/138.

A single product can be caught by more than one part. A connected toy that talks to a cloud service is inside Part 1 because it reaches the internet and inside Part 2 because it is a toy that processes data. A hardware wallet with Wi-Fi is inside all three.

The restrictions, quoted

Every one of the three citations carries restrictions. They are the operative text, not commentary, and they are short enough to quote.

Rationale and guidance sections

All three parts carry the same first restriction: the sections named “rationale” and “guidance” in the harmonised standard do not confer a presumption of conformity with the essential requirement concerned. In other words, the normative requirements of the standard are the part that counts. The explanatory material around them, which is where a great deal of the practical interpretation lives, does not carry the presumption with it.

The password restriction

All three parts also carry a restriction that turns on a single behaviour. In the wording used for EN 18031-1:

This harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password.Annex to Commission Implementing Decision (EU) 2025/138

The same restriction appears against EN 18031-2 for point (e) and against EN 18031-3 for point (f). The trigger is the same in all three: an implementation of those clauses under which the user can end up with no password at all.

Parental access control

EN 18031-2 carries a third restriction. For the classes or categories of radio equipment covered by its clauses 6.1.3, 6.1.4, 6.1.5 or 6.1.6, the standard does not confer a presumption of conformity with point (e) if, by applying clauses 6.1.3.4.2, 6.1.4.4.2, 6.1.5.4.2 and 6.1.6.4.2, parental or guardian access control is not ensured. This is the child-facing branch: childcare equipment, toys and products intended for children.

Monetary value assessment criteria

EN 18031-3 carries a third restriction of its own: as regards the assessment criteria set out in its clause 6.3.2.4, the standard does not confer a presumption of conformity with point (f). Products moving money or virtual currency therefore have a specific area where the shortcut is simply unavailable.

What the password restriction looks like in a real product

Product teams almost never set out to ship a passwordless device. The restriction bites through paths that were added for good reasons and never revisited.

  • A skippable onboarding step. The setup wizard offers to set a password and also offers “remind me later”, which becomes “never”.
  • A local access point with an open web interface. Provisioning mode is protected by physical proximity rather than by a credential, and provisioning mode never times out.
  • A secondary interface that inherits nothing. The app enforces a password, and the on-device configuration page does not.
  • A factory reset that clears the credential. After reset the device returns to a state where a user can operate it without setting one, and the reset is reachable from a button on the outside of the case.
  • A service or installer account. A documented maintenance path that works without a per-device credential, kept because field technicians asked for it.

Each of these is cheap to find and cheap to fix while firmware is still in development. Each of them is expensive to find during a conformity assessment, because by then the fix requires a new firmware build, a new test cycle and often a new submission.

Testing a product against EN 18031

The standards themselves are paywalled, so what follows describes the shape of the work rather than the clause text. A competent assessment against the series has three layers.

The restricted behaviours, first

Take a production unit out of a retail box, factory reset it, and run the entire onboarding flow as a customer would, on every interface the product offers: the app, the local web page, the soft access point, any physical control panel. Record whether any path reaches a working device with no password set. Do the same for the child-facing access control where the product is a toy, a childcare device or a product intended for children. This is an afternoon of work and it decides the conformity route.

The normative requirements, second

The rest of the standard covers the familiar ground of connected-device security: authentication, secure communication, secure storage of security parameters, update mechanisms, logging and the handling of user data. These are tested the way any device is tested, across the board, the firmware, the radio links, the application and the service. The note on the hardware attack surface covers the board-level half of that work.

The documentation, third

A presumption of conformity is claimed in a file, not in a product. The file has to show which parts of the standard were applied, to which functions of the device, and with what result. Where a clause was not applied, the file needs a reason. Where a restriction applies, the file needs to say so and to explain what route was taken instead.

How this relates to ETSI EN 303 645

Teams that already built a product to ETSI EN 303 645 often assume the RED file is handled. It is not, and the reason is procedural rather than technical.

Only standards cited in the Official Journal confer a presumption of conformity. For the RED cybersecurity requirements, the cited standards are EN 18031-1, EN 18031-2 and EN 18031-3, listed in Implementing Decision (EU) 2025/138. EN 303 645 is not among them, so however good the engineering behind it, it produces no presumption under the Radio Equipment Directive.

That does not make it irrelevant. EN 303 645, now at V3.1.3 dated September 2024, remains the clearest public baseline for consumer IoT, with thirteen provision areas in clause 5 running from no universal default passwords through to input validation. It appears constantly in procurement questionnaires. And it is named in law elsewhere: the United Kingdom’s Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, in force since 29 April 2024, define ETSI EN 303 645 as V2.1.1 of 19 June 2020 and use it in the conditions for deemed compliance in their Schedule 2.

The practical position is that a product engineered to EN 303 645 will usually satisfy much of what EN 18031 asks for, because the underlying controls overlap heavily. What it will not have is the mapping. A RED file needs to show which EN 18031 clauses were applied to which functions, with what result, and whether any restriction applies. That mapping is work, and it is work nobody can do without a copy of the standards.

If the presumption falls away

Losing the presumption is not the end of the process. It changes the route, and the route change is manageable if it is planned rather than discovered.

  1. Establish precisely which requirement is affected. The restrictions are per requirement, so a product can keep the presumption for point (d) and lose it for point (e).
  2. Decide whether the design can change. Making a password mandatory on every path is often a smaller change than an EU-type examination, and it improves the product.
  3. If the design cannot change, select a route under Article 17: module B plus C, or module H. Talk to the notified body early, because their evidence expectations shape the test plan.
  4. Commission testing that produces the evidence the notified body will ask for: identified revisions, reproducible steps, and each finding tied to the essential requirement rather than to a generic severity rating.
  5. Keep the technical documentation aligned with the shipped build. A file that describes a firmware version you no longer ship is a finding in itself.

From 11 December 2027 this whole structure moves to the Cyber Resilience Act, where the same logic reappears in Article 32: partial application of harmonised standards pushes an important product out of internal control and into module B or module H. The CRA note sets out how that works and which products it catches.

The lesson transfers cleanly. Under both regimes, the standards coverage of your product is what decides whether a third party has to look at it, and the cheapest time to find out is now.

Sources

  1. Commission Implementing Decision (EU) 2025/138 of 28 January 2025 amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the essential requirements of Directive 2014/53/EU that relate to cybersecurity EUR-Lex · 2025 The Annex carries the standard titles and the restriction wording quoted above.
  2. Directive 2014/53/EU, Article 17: conformity assessment procedures EUR-Lex · 2014
  3. Commission Delegated Regulation (EU) 2022/30 supplementing Directive 2014/53/EU EUR-Lex · 2022
  4. Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 32: conformity assessment procedures EUR-Lex · 2024

Follow-up

Questions this raises

Where can I read EN 18031?
The standards are sold by the national standardisation bodies of CEN and CENELEC members; they are not published free of charge. The restriction wording, however, is public: it appears in the Annex to Commission Implementing Decision (EU) 2025/138 on EUR-Lex, which is where the quotations in this note come from.
Does the password restriction apply if only one interface allows a passwordless path?
The restriction is written in terms of whether the user is allowed not to set and use any password when clauses 6.2.5.1 and 6.2.5.2 are applied. A path that leaves a working device without a credential is the behaviour the restriction describes, whichever interface it is reached through, which is why testing has to cover every onboarding route rather than the primary one.
Do the restrictions mean the standards are useless?
No. Applying them still gives a presumption of conformity for everything outside the restricted areas, and they remain the clearest available statement of what the three essential requirements mean in practice. The restrictions narrow the shortcut; they do not remove it.