This European Commission decision, dated 28 January 2025, updates a previous ruling (Implementing Decision (EU) 2022/2191). The core purpose is to incorporate references to new harmonised standards related to cybersecurity for specific categories of radio equipment, as mandated by Directive 2014/53/EU and detailed further in Delegated Regulation (EU) 2022/30. Under Directive 2014/53/EU, radio equipment complying with harmonised standards published in the Official Journal is generally presumed to meet the essential requirements outlined in Article 3 of that directive.
Following a formal request from the Commission (Implementing Decision C(2022)5637), the European standardisation bodies, CEN and Cenelec, developed three specific cybersecurity standards. These are EN 18031-1:2024, addressing network harm protection for internet-connected radio equipment (supporting Article 3(3)(d) of the Directive); EN 18031-2:2024, focusing on personal data and privacy protection for internet-connected devices, childcare equipment, toys, and wearables (supporting Article 3(3)(e)); and EN 18031-3:2024, concerning protection against fraud for internet-connected equipment processing monetary value (supporting Article 3(3)(f)).
Upon assessment by the Commission in collaboration with CEN and Cenelec, several issues were identified with these newly drafted standards. Firstly, all three standards include sections labelled 'rationale' and 'guidance'. These sections provide justification or examples but do not contain technical specifications and thus cannot be used to claim conformity. The 'guidance' sections also inappropriately reference national standards.
Secondly, specific clauses (6.2.5.1 and 6.2.5.2) common to all three standards present a critical flaw: they permit manufacturers to allow end-users to opt out of setting or using any password. The Commission concluded that this option fails to adequately mitigate authentication risks and therefore cannot ensure compliance with the essential security requirements (d), (e), and (f).
Thirdly, concerning EN 18031-2 (clauses 6.1.3-6.1.6), certain described access control mechanisms for toy and childcare equipment might not sufficiently ensure parental or guardian control, which is deemed necessary to meet requirement (e).
Finally, regarding EN 18031-3 (clause 6.3.2.4), the assessment criteria for ensuring secure updates were found lacking. The methods outlined, individually, are considered insufficient for the secure handling of financial assets, failing to meet requirement (f).
Consequently, while the references to standards EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 are published, they will carry specific restrictions reflecting these identified shortcomings, as indicated below:
| Reference of the standard | |
EN 18031-1:2024 Common security requirements for radio equipment – Part 1: internet connected radio equipment Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. | |
EN 18031-2:2024 Common security requirements for radio equipment – Part 2: radio equipment processing data, namely internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU if, by applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. Notice 3: For the classes or categories of radio equipment covered by clause 6.1.3, 6.1.4, 6.1.5 or 6.1.6 of this harmonised standard, this harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU if, by applying its clauses 6.1.3.4.2, 6.1.4.4.2, 6.1.5.4.2 and 6.1.6.4.2, parental or guardian access control is not ensured. | |
EN 18031-3:2024 Common security requirements for radio equipment – Part 3: internet connected radio equipment processing virtual money or monetary value Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. Notice 3: As regards the assessment criteria set out in clause 6.3.2.4 of this harmonised standard, this harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU.’ |
Common security requirements for radio equipment - Part 1: Internet connected radio equipment
60.60 Standard published
Common security requirements for radio equipment - Part 2: radio equipment processing data, namely Internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment
60.60 Standard published
Common security requirements for radio equipment - Part 3: Internet connected radio equipment processing virtual money or monetary value
60.60 Standard published