Skip to content
Inovasense
EN 18031RED Delegated ActSelf-AssessmentCE MarkingCybersecurityIoT SecurityModule ADeclaration of Conformity

EN 18031 Compliance: What "Self-Assessment" Actually Means for Connected Hardware

4 min read
EN 18031 Compliance: What "Self-Assessment" Actually Means for Connected Hardware

Self-assessment under RED Module A means the manufacturer takes responsibility for conformity and supports it with evidence. It does not mean an informal security checklist is enough, or that every connected device can use this route.

Establish scope and the permitted route

Delegated Regulation 2022/30 activates RED cybersecurity requirements for defined radio-equipment categories from 1 August 2025. Match the product to Article 3(3)(d), (e) and/or (f), then select EN 18031-1, -2 and/or -3 where applicable. A non-radio product is not brought into RED merely because it contains software.

Under RED Article 17, the internal-production-control route for Articles 3(2) and 3(3) depends on the relevant harmonised standards being applied as required. Otherwise the prescribed EU-type examination/conformity-to-type or full-quality-assurance route is needed. Validate this before signing the declaration.

Read the Official Journal restrictions

The 2025/138 citations include restrictions. In particular, allowing a user not to set and use any password under the cited clauses removes the relevant presumption of conformity. Other notices concern parental/guardian access controls and certain monetary-value assessments. The “rationale” and “guidance” sections do not themselves confer presumption of conformity.

This is not a universal prohibition of every passwordless authentication design. It is a restriction on relying on the cited standard for presumption of conformity in that situation. Evaluate the actual design and permitted assessment route, and check the current Official Journal references.

Build an evidence matrix

Use the complete applicable standard, including applicability decisions and assessment criteria. The engineering themes below are examples for planning evidence, not a substitute for every normative clause. Record product version, assets, interfaces, rationale, test procedure, results and unresolved issues.

AUM authentication

Document authentication methods, credential provisioning, first use, recovery and reset. Verify that unauthorised access is prevented under the applicable criteria and that the design’s authentication choices do not invalidate the presumed-conformity route.

SUM secure updates

Document how update authenticity and integrity are verified. Test altered packages, interrupted installation and recovery. Explain verification-key storage and authorised key changes. A named signing algorithm alone does not prove the implementation.

SSM secure storage

Identify credentials, keys and sensitive data and their storage/access paths. Justify protection against relevant threats with implementation evidence. A secure element or TrustZone may help; neither is a universally required component for every product.

ACM access control

Inventory debug, local, network and service interfaces. Test permissions, account roles and maintenance paths, including factory and reset states. Check that production configuration matches the documented controls.

SCM secure communications

Specify peer authentication, confidentiality/integrity where applicable and credential validation. Test invalid certificates, expired credentials and protocol failure paths. “We use TLS” is not a test report.

RLM resilience

Test relevant network/resource-exhaustion scenarios and safe recovery. Document rate limits and resource handling where chosen, and measure rather than asserting immunity to denial of service.

Complete the conformity evidence

Resolve gaps, check integration with RF, EMC and safety evidence, and select the legal route based on actual coverage. Maintain the technical file and declaration with applicable legislation and references. Control subsequent hardware and software changes.

EN 18031 evidence can also inform CRA risk analysis, but RED assessment and CRA conformity are distinct obligations. CE roadmap · CRA checklist · Review your assessment plan

Frequently asked questions

Can every connected device use RED Module A?

No. RED applies to radio equipment, and the internal-control route for Article 3(2)/(3) depends on application of the relevant harmonised standards as required. Otherwise the prescribed third-party route applies.

Is EN 18031 itself mandatory?

Using a harmonised standard is a voluntary route. The applicable RED essential requirements are mandatory, and an alternative route still needs sufficient evidence and the permitted conformity procedure.

Does meeting six security themes prove EN 18031 conformity?

No. The themes are engineering prompts. Assess the complete applicable standard, applicability decisions, assessment criteria and Official Journal restrictions.

Does the password notice ban all passwordless products?

It restricts the presumption of conformity under the cited standard in the stated situation. Assess the design and legal route rather than treating it as a universal ban on all passwordless methods.

Primary sources

Technical and regulatory references checked on 1 October 2026.

Related guides inEU Compliance & CE Marking

Explore all →