EN 18031 and CRA — what EN 40000-1-4 makes of it

The CRA standard EN 40000-1-4 adopts 14 requirement families from EN 18031 and adds four new ones. This has concrete consequences for manufacturers who already have RED evidence.

To answer the question, you need to know what EN 18031 consists of. It is a three-part European standards series that secures radio equipment and covers the three cybersecurity requirements activated by Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive (RED): protection of the network, protection of personal data and privacy, and protection against fraud.

Part Fundamental requirement under Article 3(3) RED Mechanism families
EN 18031-1 letter d, protection of the network against harm and misuse of network resources ACM, AUM, SUM, SSM, SCM, RLM, NMM, TCM, CCK, GEC, CRY
EN 18031-2 letter e, protection of personal data and privacy families from part 1 without RLM, NMM and TCM, but with LGM, DLM and UNM
EN 18031-3 letter f, protection against fraud subset of the families from part 1 and part 2

Critical for everything that follows is the structure within a family. First comes an applicability requirement that clarifies whether the mechanism applies to this product at all. Only afterwards follow the requirements on adequacy. If applicability was denied and the rationale documented, that family was finished.

Why the CRA collects up EN 18031

Recital 30 of the Cyber Resilience Act states that the CRA’s essential requirements encompass all elements of the three RED requirements and instructs that standardization work from the Commission Implementing Decision C(2022) 5637 be taken into account. The EN 18031 series emerged from that mandate.

CRA standardization is being carried out under a separate Commission standardization request of February 2025, registered as mandate M/606. The EN 40000-1-4 is being developed there as a horizontal standard for the technical requirements. It is currently at draft stage, working status July 2026.

EN 40000-1-4 explicitly references EN 18031: it retains the identifiers from EN 18031 and contains an annex that marks each old requirement as unchanged in name, renamed, merged, removed or new. “Unchanged in name” does not mean substantively unchanged; contents were also adapted to the CRA. We discuss the status of the horizontal standards of the EN 40000 series separately.

What changed in the requirement categories

EN 40000-1-4 defines 18 control families. Fourteen of them come from EN 18031 and four are new. The number of individual requirements grows from 44 to 65.

What happened to the family Families Requirements EN 18031 to EN 40000-1-4
Newly added Data minimization (DTM), monitoring (MON), protection of processed data (SPD), limitation of impact on external systems (LIM) 0 to 11
Adopted and expanded general product characteristics (GEC), updating (SUM), resilience (RLM), logging (LGM), cryptography (CRY) GEC 8 to 14, SUM 3 to 7, RLM 1 to 6, LGM 4 to 6, CRY 1 to 2
Applicability removed access control (ACM), authentication (AUM), communication (SCM), storage (SSM) ACM 6 to 1, AUM 6 to 5, SCM 4 to 3, SSM 3 to 2
Applicability rewritten deletion (DLM), user notification (UNM), network monitoring (NMM), traffic control (TCM) together 5 to 5
Adopted unchanged cryptographic keys (CCK) 3 to 3

Comparison of the 18 technical requirement families: left the number of individual requirements in EN 18031 for the Radio Equipment Directive, right the status in EN 40000-1-4 for the Cyber Resilience Act, grouped by newly added (0 to 11), adopted and expanded (17 to 35), applicability removed (19 to 11), applicability rewritten (5 to 5) and unchanged (3 to 3). From 44 requirements to 65.

The decline in the third group is misleading. No product requirement disappeared there; rather the preliminary question whether the family even applies was removed. Only for access control is there an actual omission: the four requirements for toys and childcare from EN 18031-2 were removed. In the second group the preliminary applicability question also disappears for logging and resilience; there it is absorbed into the growth.

The real break is in applicability

EN 40000-1-4 is conceived as a catalogue. It describes what a technical control should achieve, but it does not demand that every product implements every control. The “shall” only takes effect when the cybersecurity risk assessment has selected the control. For one product the catalogue therefore remains short, for another it becomes long.

The two-stage logic of EN 18031 disappears in two ways. Four of those requirements are dropped as independent requirements; for access control their content moves into the functional requirement. Seven more are rewritten as functional requirements: the applicability of update mechanisms becomes the requirement that all non-immutable software components must be updatable. CRA now requires the decision itself elsewhere. Under Article 13(3) the cybersecurity risk assessment indicates whether and in what way the requirements from Annex I Part I number 2 apply to the product.

In conformity assessments, applicability was the most convenient part of the whole standard. Whoever declared a family not applicable did not have to implement its requirements, only justify why it did not apply. The justification went into the manual, and the issue was settled. This became common practice: manufacturers quickly relied on non-applicability and did not even touch the requirements behind it.

If applicability follows from the risk assessment, that shortcut no longer holds. Take the control panel of a machine. Previously one could argue that no one would access the device during operation, therefore it needed neither access control nor authentication. But if the machine stands in a hall where visitor groups regularly pass through, the risk assessment looks different. Then you need a password on the panel that you didn’t need before. The need for access control and authentication does not vanish; only the justification for skipping them no longer covers the deployment environment.

Do your EN 18031 justifications withstand the CRA?

The CRA readiness check assesses your current maturity in product security, organization and schedule and shows where you need to act next.

What the four new categories require

There was no prior work from the RED implementation for the four new families. They add eleven requirements in total and cover four points that the CRA requires in Annex I Part I number 2, which RED did not address:

  • Data minimization. The product processes only what the intended purpose requires, already in the default configuration. This affects, for example, an industrial IoT sensor that routinely sends not only the measured value but also serial number, firmware version and location data.
  • Monitoring of security-relevant activities. The standard separates logging and monitoring into two distinct families. For an embedded controller with a web interface the existing log is therefore not sufficient.
  • Protection of processed data. Not only stored and transmitted data, but also data currently being processed.
  • Limitation of impact on external systems. This refers to products that themselves can become tools of an attack: limit outbound traffic, switch to a restricted network operation mode in case of suspicion. In a machine this affects the integrated switch and the cell firewall.

The expansion of the adopted families is also where the CRA goes beyond RED: secure default and boot configuration, reset to factory state, omission of unnecessary software components, behavior of automatic updates, recovery after incidents.

How much of your RED work counts for the CRA

Article 69(1) CRA regulates the transition: EU type-examination certificates issued for cybersecurity requirements under other harmonization legislation remain valid until 11 June 2028. That applies to RED certificates but has two caveats. A certificate only covers the risks it has examined, and Article 13(2) CRA obliges you to carry out your own risk assessment anyway. Above all, the transition applies only if you actually possess a certificate. A EU type-examination certificate is issued by a notified body. Whoever applied EN 18031 and declared conformity themselves has nothing that can be carried over.

That lets you sort your inventory. The evidence for access control, authentication, storage, communication and cryptographic keys moves with you, but you must review it substantively; simply relabeling identifiers is not enough. You will need to newly develop the four new families, the additional update and resilience requirements, and the whole vulnerability handling per Annex I Part II CRA, for which there is no equivalent in EN 18031. And you must rewrite every applicability justification that was based on the old two-stage model. We contextualize the overall transition from RED to CRA in the repeal of the RED delegated act.

For many radio devices an ETSI standard will apply in the end

Before you match your evidence against the horizontal catalogue, clarify whether EN 40000-1-4 is even the right standard for your product. Routers, modems and Wi‑Fi access points are radio devices currently tested to EN 18031. The CRA lists them in Annex III as important products of class I, the Implementing Regulation (EU) 2025/2392 provides the technical description, and for exactly this category an ETSI EN 304 627 standard is being developed. It names wired and wireless routers as well as bridges and thus Wi‑Fi access points. Whoever builds such a product will likely demonstrate conformity via that standard and not via EN 40000-1-4, once the standard is cited in the Official Journal.

Two limitations are in the scope. Devices without an administration function are excluded, and products for the industrial OT sector are explicitly excluded; for them EN 50770 series OT profiles are referenced. ETSI EN 304 636 covers firewalls as well as IDS and IPS; there the CRA assigns those products to class II.

Vertical standards speak their own language. None of the vertical standards we reviewed normatively references EN 18031 or EN 40000-1-4, and each uses its own requirement schema. They only quote the terminology standard from the EN 40000 series. The common denominator remains Annex I of the CRA, which each standard maps back to in its own annex. In return they supply what the horizontal standard leaves open: ETSI EN 304 627 contains an elaborate threat landscape including an assessment framework. The horizontal standard gives you the catalogue and leaves the threat analysis to you.

Why the strands diverge is shown by the standardization request. It mandates 41 standardization projects and requires coherence only with the framework standard and the vulnerability handling standard; alignment with the other horizontal standards is mentioned merely as a goal to be considered. Added to that is the timetable: the framework standard and the vulnerability handling standard are due on 30 August 2026, all 26 vertical standards on 30 October 2026, and the thirteen remaining horizontal standards not until 30 October 2027. The vertical standards are therefore scheduled one year ahead of the bulk of the horizontal requirements.

The request expects the two strands to converge over regular revision cycles. We consider that optimistic. Convergence would mean changing the requirement schema in 26 standards and putting each through voting again, for a benefit only standards specialists would notice. Expect the vocabularies to coexist side by side.

For mechanical and plant engineering a second strand is added: the EN 50770 series is developing OT profiles based on IEC 62443. At least the two strands know of each other: the ETSI standards exclude the industrial domain and refer to the OT profiles. Our ETSI draft standards for the CRA provide an overview.

What this means for your planning

Do not wait for the standards to be finalized before you implement. The catalogue is available, the additional requirements are named, and the effort for data minimization, update behavior and resilience comes in development, not in documentation. Those who wait for Official Journal listing lose the time needed for design changes.

Test in parallel to understand the actual risk. Just because something looks right on paper does not mean it is correctly implemented. This is particularly true for the new families because there is neither test experience nor established evidence formats yet.

We are skeptical about the timetable. The standardization request schedules the last horizontal standards for 30 October 2027, and after that the Commission must still assess each standard and cite it in the Official Journal before it can carry a presumption of conformity. Only six weeks remain for that until 11 December 2027. Plan therefore for a route that does not rely on a presumption of conformity: your own risk assessment, from which you must in any case derive which requirements apply to your product.

The statements about EN 40000-1-4 are based on a non-public working draft from CEN and CENELEC dated July 2026. The information on the standardization status reflects the situation in August 2026.

Clarify CRA conformity assessment for your product

We assess which CRA modules, evidence and deadlines apply to your product in addition to EN 18031 and what that means for your declaration of conformity.