See Full Document Text
Official Journal EN
of the European Union L series
2025/138 30.1.2025
COMMISSION IMPLEMENTING DECISION (EU) 2025/138
of 28 January 2025
amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the
essential requirements of Directive 2014/53/EU of the European Parliament and of the Council that
relate to cybersecurity, for the categories and classes of radio equipment specified in Delegated
Regulation (EU) 2022/30
(Text with EEA relevance)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012on
European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC,
95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament
and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European
Parliament and of the Council(1), and in particular Article 10(6) thereof,
Whereas:
(1) In accordance with Article 16 of Directive 2014/53/EU of the European Parliament and of the Council(2), radio
equipment which is in conformity with harmonised standards or parts thereof, the references of which have been
published in the Official Journal of the European Union, is to be presumed to be in conformity with the essential
requirements set out in Article 3 of that Directive where they are covered by those standards or parts thereof.
(2) By Implementing Decision C(2022)5637(3), the Commission made a request to the European Committee for
Standardisation (CEN) and the European Committee for Electrotechnical Standardisation (Cenelec) for the drafting
of new harmonised standards in support of Article 3(3), first subparagraph, points (d), (e) and (f), of
Directive 2014/53/EU, for the categories and classes of the radio equipment specified in Commission Delegated
Regulation (EU) 2022/30(4)(‘the request’).
(3) On the basis of the request, CEN and Cenelec drafted harmonised standards EN 18031-1:2024 on common security
requirements for internet connected radio equipment, in support of the essential requirement set out in Article 3(3),
first subparagraph, point (d), of Directive 2014/53/EU; EN 18031-2:2024 on common security requirements for
internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio
equipment, in support of the essential requirement set out in Article 3(3), first subparagraph, point (e), of
Directive 2014/53/EU; and EN 18031-3:2024 on common security requirements for internet connected radio
equipment processing virtual money or monetary value, in support of the essential requirement set out in
Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU.
(1) OJ L 316, 14.11.2012, p. 12, ELI: http://data.europa.eu/eli/reg/2012/1025/oj.
(2) Directive 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the
Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC (OJ L 153,
22.5.2014, p. 62, ELI: http://data.europa.eu/eli/dir/2014/53/oj).
(3) Commission Implementing Decision C(2022)5637 of 5 August 2022 on a standardisation request to the European Committee for
Standardisation and the European Committee for Electrotechnical Standardisation as regards radio equipment in support of
Directive 2014/53/EU of the European Parliament and of the Council and Commission Delegated Regulation (EU) 2022/30.
(4) Commission Delegated Regulation (EU) 2022/30 of 29 October 2021 supplementing Directive 2014/53/EU of the European
Parliament and of the Council with regard to the application of the essential requirements referred to in Article 3(3), points (d), (e) and
(f), of that Directive (OJ L 7, 12.1.2022, p. 6, ELI: http://data.europa.eu/eli/reg_del/2022/30/oj).
ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj 1/4EN
OJ L, 30.1.2025
(4) The Commission, together with CEN and Cenelec, has assessed whether those harmonised standards comply with
the request.
(5) Harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 include numerous sections
named ‘rationale’ and ‘guidance’. The section named ‘rationale’ aims to provide a justification for the need to address
certain risks. The sections named ‘guidance’ includes examples and considerations on the possibilities to implement
certain mitigation measures. Neither of the two aforementioned sections set out specifications. Additionally, the
sections named ‘guidance’ include references to standardisation deliverables of national standardisation
organisations. As a general rule, harmonised standards should not include normative cross-references to such
standardisation deliverables.
(6) Clauses 6.2.5.1 and 6.2.5.2 of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024
deal with default passwords. Those clauses offer manufacturers the possibility to allow a user not to set or use any
password. It is considered that, if this option is implemented, the relevant authentication risks will not be properly
addressed and therefore conformity with the essential requirements set out in Article 3(3), first subparagraph,
points (d), (e) and (f), of Directive 2014/53/EU would not be ensured.
(7) Clauses 6.1.3, 6.1.4, 6.1.5 and 6.1.6 of harmonised standard EN 18031-2:2024 include specifications on access
control mechanism for toy radio equipment and for childcare radio equipment. More specifically, the
implementation categories described under the subsections ‘assessment criteria’ are the following: role-based access
control, discretionary access control, mandatory access control or others. Certain of these categories might not be
compatible with parental or guardian control. In such a case, it is considered that, if parental or guardian control is
not implemented, the relevant authentication risks will not be addressed and, therefore, conformity with the
essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU would not be
ensured.
(8) Clause 6.3.2.4 of harmonised standard EN 18031-3:2024 includes assessment criteria for secure updates. Four
different implementation categories are laid down, based on digital signatures, secure communication mechanisms,
access control mechanisms or others. None of the methods alone are sufficient for the treatment of financial assets.
It is considered that the assessment criteria do not properly address the relevant authentication risks and cannot
therefore ensure conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of
Directive 2014/53/EU.
(9) The references of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 should
therefore be published in the Official Journal of the European Union with restrictions.
(10) Annex I to Commission Implementing Decision (EU) 2022/2191(5)provides the references of harmonised standards
conferring a presumption of conformity with Directive 2014/53/EU. In order to ensure that the references of
harmonised standards drafted in support of Directive 2014/53/EU are listed in one act, the references of
harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 should be included in that
Annex, with restrictions.
(11) Implementing Decision (EU) 2022/2191 should therefore be amended accordingly.
(12) Compliance with a harmonised standard confers a presumption of conformity with the corresponding essential
requirements set out in Union harmonisation legislation from the date of publication of the reference of such
standard in the Official Journal of the European Union. This Decision should therefore enter into force on the day of its
publication,
(5) Commission Implementing Decision (EU) 2022/2191 of 8 November 2022 on the harmonised standards for radio equipment drafted
in support of Directive 2014/53/EU of the European Parliament and of the Council (OJ L 289, 10.11.2022, p. 7, ELI: http://data.
europa.eu/eli/dec_impl/2022/2191/oj).
2/4 ELI: http://data.europa.eu/eli/dec_impl/2025/138/ojEN
OJ L, 30.1.2025
HAS ADOPTED THIS DECISION:
Article 1
Annex I to Implementing Decision (EU) 2022/2191 is amended in accordance with the Annex to this Decision.
Article 2
This Decision shall enter into force on the day of its publication in the Official Journal of the European Union.
Done at Brussels, 28 January 2025.
For the Commission
The President
Ursula VON DER LEYEN
ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj 3/4EN
OJ L, 30.1.2025
ANNEX
In Annex I, the following rows are added:
No Reference of the standard
‘164. EN 18031-1:2024
Common security requirements for radio equipment – Part 1: internet connected radio equipment
Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a
presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of
Directive 2014/53/EU.
Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement
set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1
and 6.2.5.2, the user is allowed not to set and use any password.
165. EN 18031-2:2024
Common security requirements for radio equipment – Part 2: radio equipment processing data, namely internet
connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment
Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a
presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of
Directive 2014/53/EU.
Notice 2: This harmonised standard does not confer a presumption of conformity with Article 3(3), first
subparagraph, point (e), of Directive 2014/53/EU if, by applying its clauses 6.2.5.1 and 6.2.5.2, the user is
allowed not to set and use any password.
Notice 3: For the classes or categories of radio equipment covered by clause 6.1.3, 6.1.4, 6.1.5 or 6.1.6 of this
harmonised standard, this harmonised standard does not confer a presumption of conformity with the essential
requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU if, by applying its
clauses 6.1.3.4.2, 6.1.4.4.2, 6.1.5.4.2 and 6.1.6.4.2, parental or guardian access control is not ensured.
166. EN 18031-3:2024
Common security requirements for radio equipment – Part 3: internet connected radio equipment processing
virtual money or monetary value
Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a
presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of
Directive 2014/53/EU.
Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement
set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1
and 6.2.5.2, the user is allowed not to set and use any password.
Notice 3: As regards the assessment criteria set out in clause 6.3.2.4 of this harmonised standard, this
harmonised standard does not confer a presumption of conformity with the essential requirement set out in
Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU.’
4/4 ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj