Home Europe European Commission Commission Implementing Decision (EU) 2025/138 of 28 January...
Date: 30-Jan-2025 Category: Not Applicable State: Union Government Country: Europe

Commission Implementing Decision (EU) 2025/138 of 28 January 2025 amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the essential requirements of Directive 2014/53/EU of the European Parliament and of the Council that relate to cybersecurity, for the categories and classes of radio equipment specified in Delegated Regulation (EU) 2022/30

Issued by European Commission · Directorate-General for Internal Market

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

What it means

  • Commission Implementing Decision (EU) 2025/138 amends Implementing Decision (EU) 2022/2191 to include references to harmonised standards EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024 in support of the essential cybersecurity requirements of Directive 2014/53/EU for specific categories of radio equipment. These standards relate to the cybersecurity of internet-connected radio equipment.

Key Changes

  • The decision adds references to three new harmonised standards (EN 18031-1:2024, EN 18031-2:2024, EN 18031-3:2024) to Annex I of Implementing Decision (EU) 2022/2191.
  • These standards provide a presumption of conformity with Article 3(3)(d), (e), and (f) of Directive 2014/53/EU, which relate to cybersecurity requirements for radio equipment.
  • The publication of these standards in the Official Journal of the European Union is subject to certain restrictions, detailed in the notices associated with each standard in the Annex.
  • Specifically, the 'rationale' and 'guidance' sections within each standard do not confer a presumption of conformity.
  • Allowing users not to set or use any password when applying clauses 6.2.5.1 and 6.2.5.2 of the standards does not confer a presumption of conformity.
  • For EN 18031-2:2024, parental or guardian access control must be ensured when applying clauses 6.1.3.4.2, 6.1.4.4.2, 6.1.5.4.2 and 6.1.6.4.2 to maintain presumption of conformity for toy and childcare radio equipment.
  • For EN 18031-3:2024, the assessment criteria in clause 6.3.2.4 do not alone ensure conformity with the essential requirements for radio equipment processing virtual money or monetary value.

Impact Analysis

Manufacturers of Radio Equipment

  • Action Item: Review existing product designs and manufacturing processes to ensure compliance with the new standards and their associated restrictions. Update documentation and testing procedures accordingly.

Conformity Assessment Bodies

  • Action Item: Update assessment procedures and checklists to incorporate the requirements and restrictions of EN 18031-1:2024, EN 18031-2:2024, and EN 18031-3:2024. Train assessors on the specific nuances of these standards.

National Standardisation Organisations

  • Action Item: Review national standards to ensure alignment with European harmonised standards and avoid conflicting or redundant requirements.

Consumers

  • Action Item: No specific action is required, but consumers should be aware of the enhanced security features in compliant devices.

Key Entities Referenced

European Commission: The executive branch of the European Union, responsible for proposing and implementing legislation. European Parliament: The directly elected parliamentary body of the European Union, sharing legislative power with the Council of the European Union. Council of the European Union: A body composed of government ministers from each EU member state, sharing legislative power with the European Parliament. CEN (European Committee for Standardisation): A European standards organisation responsible for developing and maintaining voluntary technical standards. Cenelec (European Committee for Electrotechnical Standardisation): A European standards organisation responsible for developing and maintaining voluntary technical standards in the electrotechnical field. Directive 2014/53/EU: The Radio Equipment Directive (RED), which sets out essential requirements for radio equipment placed on the market in the European Union. Regulation (EU) No 1025/2012: Regulation on European standardisation, which sets the framework for European standards. Delegated Regulation (EU) 2022/30: Supplements Directive 2014/53/EU with regard to the application of essential requirements related to cybersecurity. Implementing Decision (EU) 2022/2191: Commission Implementing Decision on the harmonised standards for radio equipment drafted in support of Directive 2014/53/EU. EN 18031-1:2024: Common security requirements for radio equipment – Part 1: internet connected radio equipment EN 18031-2:2024: Common security requirements for radio equipment – Part 2: radio equipment processing data, namely internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment EN 18031-3:2024: Common security requirements for radio equipment – Part 3: internet connected radio equipment processing virtual money or monetary value
Official Source Record View Original Source →
See Full Document Text
Official Journal EN of the European Union L series 2025/138 30.1.2025 COMMISSION IMPLEMENTING DECISION (EU) 2025/138 of 28 January 2025 amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the essential requirements of Directive 2014/53/EU of the European Parliament and of the Council that relate to cybersecurity, for the categories and classes of radio equipment specified in Delegated Regulation (EU) 2022/30 (Text with EEA relevance) THE EUROPEAN COMMISSION, Having regard to the Treaty on the Functioning of the European Union, Having regard to Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council(1), and in particular Article 10(6) thereof, Whereas: (1) In accordance with Article 16 of Directive 2014/53/EU of the European Parliament and of the Council(2), radio equipment which is in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, is to be presumed to be in conformity with the essential requirements set out in Article 3 of that Directive where they are covered by those standards or parts thereof. (2) By Implementing Decision C(2022)5637(3), the Commission made a request to the European Committee for Standardisation (CEN) and the European Committee for Electrotechnical Standardisation (Cenelec) for the drafting of new harmonised standards in support of Article 3(3), first subparagraph, points (d), (e) and (f), of Directive 2014/53/EU, for the categories and classes of the radio equipment specified in Commission Delegated Regulation (EU) 2022/30(4)(‘the request’). (3) On the basis of the request, CEN and Cenelec drafted harmonised standards EN 18031-1:2024 on common security requirements for internet connected radio equipment, in support of the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU; EN 18031-2:2024 on common security requirements for internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment, in support of the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU; and EN 18031-3:2024 on common security requirements for internet connected radio equipment processing virtual money or monetary value, in support of the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU. (1) OJ L 316, 14.11.2012, p. 12, ELI: http://data.europa.eu/eli/reg/2012/1025/oj. (2) Directive 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC (OJ L 153, 22.5.2014, p. 62, ELI: http://data.europa.eu/eli/dir/2014/53/oj). (3) Commission Implementing Decision C(2022)5637 of 5 August 2022 on a standardisation request to the European Committee for Standardisation and the European Committee for Electrotechnical Standardisation as regards radio equipment in support of Directive 2014/53/EU of the European Parliament and of the Council and Commission Delegated Regulation (EU) 2022/30. (4) Commission Delegated Regulation (EU) 2022/30 of 29 October 2021 supplementing Directive 2014/53/EU of the European Parliament and of the Council with regard to the application of the essential requirements referred to in Article 3(3), points (d), (e) and (f), of that Directive (OJ L 7, 12.1.2022, p. 6, ELI: http://data.europa.eu/eli/reg_del/2022/30/oj). ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj 1/4EN OJ L, 30.1.2025 (4) The Commission, together with CEN and Cenelec, has assessed whether those harmonised standards comply with the request. (5) Harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 include numerous sections named ‘rationale’ and ‘guidance’. The section named ‘rationale’ aims to provide a justification for the need to address certain risks. The sections named ‘guidance’ includes examples and considerations on the possibilities to implement certain mitigation measures. Neither of the two aforementioned sections set out specifications. Additionally, the sections named ‘guidance’ include references to standardisation deliverables of national standardisation organisations. As a general rule, harmonised standards should not include normative cross-references to such standardisation deliverables. (6) Clauses 6.2.5.1 and 6.2.5.2 of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 deal with default passwords. Those clauses offer manufacturers the possibility to allow a user not to set or use any password. It is considered that, if this option is implemented, the relevant authentication risks will not be properly addressed and therefore conformity with the essential requirements set out in Article 3(3), first subparagraph, points (d), (e) and (f), of Directive 2014/53/EU would not be ensured. (7) Clauses 6.1.3, 6.1.4, 6.1.5 and 6.1.6 of harmonised standard EN 18031-2:2024 include specifications on access control mechanism for toy radio equipment and for childcare radio equipment. More specifically, the implementation categories described under the subsections ‘assessment criteria’ are the following: role-based access control, discretionary access control, mandatory access control or others. Certain of these categories might not be compatible with parental or guardian control. In such a case, it is considered that, if parental or guardian control is not implemented, the relevant authentication risks will not be addressed and, therefore, conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU would not be ensured. (8) Clause 6.3.2.4 of harmonised standard EN 18031-3:2024 includes assessment criteria for secure updates. Four different implementation categories are laid down, based on digital signatures, secure communication mechanisms, access control mechanisms or others. None of the methods alone are sufficient for the treatment of financial assets. It is considered that the assessment criteria do not properly address the relevant authentication risks and cannot therefore ensure conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU. (9) The references of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 should therefore be published in the Official Journal of the European Union with restrictions. (10) Annex I to Commission Implementing Decision (EU) 2022/2191(5)provides the references of harmonised standards conferring a presumption of conformity with Directive 2014/53/EU. In order to ensure that the references of harmonised standards drafted in support of Directive 2014/53/EU are listed in one act, the references of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 should be included in that Annex, with restrictions. (11) Implementing Decision (EU) 2022/2191 should therefore be amended accordingly. (12) Compliance with a harmonised standard confers a presumption of conformity with the corresponding essential requirements set out in Union harmonisation legislation from the date of publication of the reference of such standard in the Official Journal of the European Union. This Decision should therefore enter into force on the day of its publication, (5) Commission Implementing Decision (EU) 2022/2191 of 8 November 2022 on the harmonised standards for radio equipment drafted in support of Directive 2014/53/EU of the European Parliament and of the Council (OJ L 289, 10.11.2022, p. 7, ELI: http://data. europa.eu/eli/dec_impl/2022/2191/oj). 2/4 ELI: http://data.europa.eu/eli/dec_impl/2025/138/ojEN OJ L, 30.1.2025 HAS ADOPTED THIS DECISION: Article 1 Annex I to Implementing Decision (EU) 2022/2191 is amended in accordance with the Annex to this Decision. Article 2 This Decision shall enter into force on the day of its publication in the Official Journal of the European Union. Done at Brussels, 28 January 2025. For the Commission The President Ursula VON DER LEYEN ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj 3/4EN OJ L, 30.1.2025 ANNEX In Annex I, the following rows are added: No Reference of the standard ‘164. EN 18031-1:2024 Common security requirements for radio equipment – Part 1: internet connected radio equipment Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. 165. EN 18031-2:2024 Common security requirements for radio equipment – Part 2: radio equipment processing data, namely internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU if, by applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. Notice 3: For the classes or categories of radio equipment covered by clause 6.1.3, 6.1.4, 6.1.5 or 6.1.6 of this harmonised standard, this harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU if, by applying its clauses 6.1.3.4.2, 6.1.4.4.2, 6.1.5.4.2 and 6.1.6.4.2, parental or guardian access control is not ensured. 166. EN 18031-3:2024 Common security requirements for radio equipment – Part 3: internet connected radio equipment processing virtual money or monetary value Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. Notice 3: As regards the assessment criteria set out in clause 6.3.2.4 of this harmonised standard, this harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU.’ 4/4 ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj

Continue your research