Initial Situation
Since August 2025, additional cybersecurity requirements of the Radio Equipment Directive have applied to certain radio equipment. This can also affect connected devices in industry and building technology that were previously not subject to any cybersecurity standards. The embedded device under investigation has a radio interface and processes personal data. According to the RED, it is therefore considered radio equipment connected to the internet. For the analysis, the requirements from EN 18031-1 for network protection and EN 18031-2 for the protection of personal data were therefore relevant.

The Contribution of SCS
SCS systematically tested the product together with the client and their development partner according to EN 18031. Predefined SCS templates guided the process from applicability and risk analysis to the evaluation of existing security mechanisms.
Result
The client received a precise overview of which RED requirements were relevant for their product, which security mechanisms were already sufficiently implemented, and where further action was required. The detailed analysis documented risks, relevant mechanisms according to EN 18031, and their conceptual assessment, thereby creating a reliable basis for the next development steps. The result was positive. Cybersecurity was already part of product development at the manufacturer and its development partner from the very beginning. This security-by-design approach was reflected accordingly in the analysis.
EN 18031-1 & -2
relevant standard parts for network and data protection.
5 Steps
from applicability to assessment of implementation.
Security by Design
Cybersecurity already considered during product development.




