EN 18031 supports assessment of RED cybersecurity requirements for radio equipment. Part 1 addresses network protection, Part 2 personal data and privacy, and Part 3 fraud protection. Determine applicable parts from actual functionality and check restrictions in the EU harmonised references. Prepare interface descriptions, data flows, account roles, firmware versions and update evidence before laboratory testing.
Project preparation
Provide the intended markets, product architecture, interfaces, sample configuration, software versions and available design evidence. Agree testing access, restrictions and a version baseline. Record remediation changes and retest the affected controls before closing findings.
Delivery and scope
The agreed deliverables may include an applicability record, gap list, test plan, findings and retest records. Confirm the report purpose and any additional certification or conformity assessment steps required by the recipient. The preparation guidance below explains the information needed to scope a proposal.
Plan your testing project
What determines the testing scope?
Connectivity, personal data and payment functions to determine EN 18031-1/-2/-3 applicability, including restrictions in the EU harmonised reference. Scope is confirmed against current official requirements and the actual product configuration.
What should be prepared before quotation?
Provide a product description, intended markets, interfaces, architecture and data-flow diagrams, hardware and software versions, update design, account roles and available test samples. Include prior reports and known issues if available.
How are lead time and price determined?
They depend on applicable requirements, number of interfaces and variants, test access, document readiness and remediation cycles. After a document review we agree milestones and quotation assumptions. A universal price or fixed turnaround would not reflect these differences.
What commonly causes retesting?
Missing interface descriptions, inaccessible administrator functions, undocumented cloud dependencies, changing firmware during testing and insufficient evidence of remediation. Agree a version baseline and track each change against affected test cases.
What will be delivered?
The agreed scope may include an applicability record, gap list, test plan, findings, remediation and retest records, and a test report. Confirm report purpose, recipient requirements and any need for a notified or certification body before placing the order.
