EN 18031-1 specifies common security requirements for internet-connected radio equipment. This standard provides technical specifications for radio equipment, which concerns electrical or electronic products that can communicate over the internet, regardless of whether these products communicate directly or via any other equipment.
Vigilance is required from manufacturers to improve the overall resilience against cybersecurity threats caused by the increased connectivity of radio equipment and the growing ability of malicious threat actors to cause harm to users, organizations, and society. The security requirements presented in EN 18031-1 are developed to improve the ability of radio equipment to protect its security assets and network assets against common cybersecurity threats and to mitigate publicly known exploitable vulnerabilities.
It is important to note that to achieve the overall cybersecurity of radio equipment, defence in depth best practices will be needed by both the manufacturer and user. In particular, no single measure will suffice to achieve the given objectives; achieving even a single security objective will usually require a suite of mechanisms and measures.
Throughout EN 18031-1, the guidance material includes lists of examples. These examples given are only indicative possibilities, as other possibilities are not listed, and even using the examples given will not be sufficient unless the mechanisms and measures chosen are implemented in a coordinated fashion.
This standards address key cybersecurity requirements outlined in the Radio Equipment Directive (RED).
Common security requirements for radio equipment series consist of three standards:
EN 18031-1:2024 — Defines common security requirements for internet-connected radio equipment.
EN 18031-2:2024 — Specifies technical requirements for radio equipment processing data, namely Internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment
EN 18031-3:2024 — Outlines cybersecurity requirements Internet connected radio equipment processing virtual money or monetary value.