Self-assessment under RED Module A means the manufacturer takes responsibility for conformity and supports it with evidence. It does not mean an informal security checklist is enough, or that every connected device can use this route.
Establish scope and the permitted route
Delegated Regulation 2022/30 activates RED cybersecurity requirements for defined radio-equipment categories from 1 August 2025. Match the product to Article 3(3)(d), (e) and/or (f), then select EN 18031-1, -2 and/or -3 where applicable. A non-radio product is not brought into RED merely because it contains software.
Under RED Article 17, the internal-production-control route for Articles 3(2) and 3(3) depends on the relevant harmonised standards being applied as required. Otherwise the prescribed EU-type examination/conformity-to-type or full-quality-assurance route is needed. Validate this before signing the declaration.
Read the Official Journal restrictions
The 2025/138 citations include restrictions. In particular, allowing a user not to set and use any password under the cited clauses removes the relevant presumption of conformity. Other notices concern parental/guardian access controls and certain monetary-value assessments. The “rationale” and “guidance” sections do not themselves confer presumption of conformity.
This is not a universal prohibition of every passwordless authentication design. It is a restriction on relying on the cited standard for presumption of conformity in that situation. Evaluate the actual design and permitted assessment route, and check the current Official Journal references.
Build an evidence matrix
Use the complete applicable standard, including applicability decisions and assessment criteria. The engineering themes below are examples for planning evidence, not a substitute for every normative clause. Record product version, assets, interfaces, rationale, test procedure, results and unresolved issues.
AUM authentication
Document authentication methods, credential provisioning, first use, recovery and reset. Verify that unauthorised access is prevented under the applicable criteria and that the design’s authentication choices do not invalidate the presumed-conformity route.
SUM secure updates
Document how update authenticity and integrity are verified. Test altered packages, interrupted installation and recovery. Explain verification-key storage and authorised key changes. A named signing algorithm alone does not prove the implementation.
SSM secure storage
Identify credentials, keys and sensitive data and their storage/access paths. Justify protection against relevant threats with implementation evidence. A secure element or TrustZone may help; neither is a universally required component for every product.
ACM access control
Inventory debug, local, network and service interfaces. Test permissions, account roles and maintenance paths, including factory and reset states. Check that production configuration matches the documented controls.
SCM secure communications
Specify peer authentication, confidentiality/integrity where applicable and credential validation. Test invalid certificates, expired credentials and protocol failure paths. “We use TLS” is not a test report.
RLM resilience
Test relevant network/resource-exhaustion scenarios and safe recovery. Document rate limits and resource handling where chosen, and measure rather than asserting immunity to denial of service.
Complete the conformity evidence
Resolve gaps, check integration with RF, EMC and safety evidence, and select the legal route based on actual coverage. Maintain the technical file and declaration with applicable legislation and references. Control subsequent hardware and software changes.
EN 18031 evidence can also inform CRA risk analysis, but RED assessment and CRA conformity are distinct obligations. CE roadmap · CRA checklist · Review your assessment plan
Frequently asked questions
Can every connected device use RED Module A?
No. RED applies to radio equipment, and the internal-control route for Article 3(2)/(3) depends on application of the relevant harmonised standards as required. Otherwise the prescribed third-party route applies.
Is EN 18031 itself mandatory?
Using a harmonised standard is a voluntary route. The applicable RED essential requirements are mandatory, and an alternative route still needs sufficient evidence and the permitted conformity procedure.
Does meeting six security themes prove EN 18031 conformity?
No. The themes are engineering prompts. Assess the complete applicable standard, applicability decisions, assessment criteria and Official Journal restrictions.
Does the password notice ban all passwordless products?
It restricts the presumption of conformity under the cited standard in the stated situation. Assess the design and legal route rather than treating it as a universal ban on all passwordless methods.
Primary sources
Technical and regulatory references checked on 1 October 2026.
Related guides inEU Compliance & CE Marking
Explore all →EU Electronics Compliance: CE, CRA & RED
A product-specific CE roadmap for electronics: applicable legislation, evidence, assessment routes, RED cybersecurity and CRA responsibilities.
EU CRA Hardware Compliance Checklist
A risk-based CRA checklist for hardware: scope, product category, security requirements, SBOM, support period, reporting and conformity evidence.
CRA Vulnerability Reporting: Step-by-Step Guide
CRA Article 14 reporting in force since 11 September 2026: scope, 24/72-hour awareness deadlines, final reports, SRP and operational preparation.
RED Delegated Act & EN 18031: Hardware Requirements
How the RED Delegated Act and EN 18031 define mandatory cybersecurity for radio equipment from August 2025 — with gaps that cannot be fixed in firmware.
EU Hardware Legislation 2026: Complete Guide
Which EU rules apply to your hardware? Distinguish CRA, RED, AI Act, ESPR and NIS2 scope, application dates and product-specific obligations.