As we reported in an earlier newsletter, the series of standards (EN 18031-X:2024) on cybersecurity will be succeeded by the cybersecurity requirements set forth in the EU’s Cyber Resilience Act.
→ A normative landscape for the Cyber Resilience Act (EU) 2024/2847
These standards will be published in the EN 40000-1-X series. The timeline is once again somewhat uncertain.
Regardless of whether the requirements are set by the RED or the CRA, the requirements themselves remain essentially the same. Under RED, compliance with these requirements has been mandatory for some time now. The CRA will take full effect on December 11, 2027, at which point it will supersede the cybersecurity requirements from RED. From that date onward, the new standards should be available and must be complied with.
Over the past few years, the REDCA has developed Technical Guidance Notes (TGNs), which were published this year:
TGN 35:2026
on the RED compliance requirements for cybersecurity as per
Article 3.3(d), Internet-connected equipment.
TGN 36:2026
on the RED compliance requirements for cybersecurity as per
Article 3.3(e), data processing and child protection.
TGN 37:2026
on the RED compliance requirements for cybersecurity as per
Article 3.3(f), financial transactions or payments.
The TGNs are freely accessible. We have provided the hyperlinks at the end of the article.
These publications do not conflict with the development of the new standards, as their objectives are quite similar, and the new standards clarify a few ambiguities, include some corrections, and adapt to the state of the art. They are expected to be published 2 to 3 years after the EN 18031-X:2024 series. Every three years, European and international standards undergo a review anyway, at which point a decision is made, at the latest, on whether to begin developing a new version. However, the standards committees may also begin work on a new version earlier.
Do you have questions about the RED Technical Guidance Notes?
Whether it’s about the impact on your products, support with implementation, or interpreting current guidelines and standards, our experts are happy to assist you.
Get in touch with us. We’ll provide you with straightforward, practical advice.
Author's note
This article has been machine translated into English.
TERMS AND ABBREVIATIONS
OJEU: Official Journal of the EU
RED: Radio Equipment Directive 2024/53/EU
CRA: Cyber Resilience Act (EU) 2024/2847
CEN, CENELEC, and ETSI are the three EU Standardization Organizations (ESOs)
REDCA: Radio Equipment Directive Compliance Association
An association comprising nearly all RED Notified Bodies. REDCA’s goal is to achieve a uniform assessment of RED products and to maintain close contact and dialogue with the European Commission and the supervisory authorities.