This document is an excerpt from the EUR-Lex website
Document 32025D0138
Commission Implementing Decision (EU) 2025/138 of 28 January 2025 amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the essential requirements of Directive 2014/53/EU of the European Parliament and of the Council that relate to cybersecurity, for the categories and classes of radio equipment specified in Delegated Regulation (EU) 2022/30
Commission Implementing Decision (EU) 2025/138 of 28 January 2025 amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the essential requirements of Directive 2014/53/EU of the European Parliament and of the Council that relate to cybersecurity, for the categories and classes of radio equipment specified in Delegated Regulation (EU) 2022/30
Commission Implementing Decision (EU) 2025/138 of 28 January 2025 amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the essential requirements of Directive 2014/53/EU of the European Parliament and of the Council that relate to cybersecurity, for the categories and classes of radio equipment specified in Delegated Regulation (EU) 2022/30
C/2025/466
OJ L, 2025/138, 30.1.2025, ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj (BG, ES, CS, DA, DE, ET, EL, EN, FR, GA, HR, IT, LV, LT, HU, MT, NL, PL, PT, RO, SK, SL, FI, SV)
In force
![]() |
Official Journal |
EN L series |
2025/138 |
30.1.2025 |
COMMISSION IMPLEMENTING DECISION (EU) 2025/138
of 28 January 2025
amending Implementing Decision (EU) 2022/2191 as regards harmonised standards in support of the essential requirements of Directive 2014/53/EU of the European Parliament and of the Council that relate to cybersecurity, for the categories and classes of radio equipment specified in Delegated Regulation (EU) 2022/30
(Text with EEA relevance)
THE EUROPEAN COMMISSION,
Having regard to the Treaty on the Functioning of the European Union,
Having regard to Regulation (EU) No 1025/2012 of the European Parliament and of the Council of 25 October 2012 on European standardisation, amending Council Directives 89/686/EEC and 93/15/EEC and Directives 94/9/EC, 94/25/EC, 95/16/EC, 97/23/EC, 98/34/EC, 2004/22/EC, 2007/23/EC, 2009/23/EC and 2009/105/EC of the European Parliament and of the Council and repealing Council Decision 87/95/EEC and Decision No 1673/2006/EC of the European Parliament and of the Council (1), and in particular Article 10(6) thereof,
Whereas:
(1) |
In accordance with Article 16 of Directive 2014/53/EU of the European Parliament and of the Council (2), radio equipment which is in conformity with harmonised standards or parts thereof, the references of which have been published in the Official Journal of the European Union, is to be presumed to be in conformity with the essential requirements set out in Article 3 of that Directive where they are covered by those standards or parts thereof. |
(2) |
By Implementing Decision C(2022)5637 (3), the Commission made a request to the European Committee for Standardisation (CEN) and the European Committee for Electrotechnical Standardisation (Cenelec) for the drafting of new harmonised standards in support of Article 3(3), first subparagraph, points (d), (e) and (f), of Directive 2014/53/EU, for the categories and classes of the radio equipment specified in Commission Delegated Regulation (EU) 2022/30 (4) (‘the request’). |
(3) |
On the basis of the request, CEN and Cenelec drafted harmonised standards EN 18031-1:2024 on common security requirements for internet connected radio equipment, in support of the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU; EN 18031-2:2024 on common security requirements for internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment, in support of the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU; and EN 18031-3:2024 on common security requirements for internet connected radio equipment processing virtual money or monetary value, in support of the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU. |
(4) |
The Commission, together with CEN and Cenelec, has assessed whether those harmonised standards comply with the request. |
(5) |
Harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 include numerous sections named ‘rationale’ and ‘guidance’. The section named ‘rationale’ aims to provide a justification for the need to address certain risks. The sections named ‘guidance’ includes examples and considerations on the possibilities to implement certain mitigation measures. Neither of the two aforementioned sections set out specifications. Additionally, the sections named ‘guidance’ include references to standardisation deliverables of national standardisation organisations. As a general rule, harmonised standards should not include normative cross-references to such standardisation deliverables. |
(6) |
Clauses 6.2.5.1 and 6.2.5.2 of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 deal with default passwords. Those clauses offer manufacturers the possibility to allow a user not to set or use any password. It is considered that, if this option is implemented, the relevant authentication risks will not be properly addressed and therefore conformity with the essential requirements set out in Article 3(3), first subparagraph, points (d), (e) and (f), of Directive 2014/53/EU would not be ensured. |
(7) |
Clauses 6.1.3, 6.1.4, 6.1.5 and 6.1.6 of harmonised standard EN 18031-2:2024 include specifications on access control mechanism for toy radio equipment and for childcare radio equipment. More specifically, the implementation categories described under the subsections ‘assessment criteria’ are the following: role-based access control, discretionary access control, mandatory access control or others. Certain of these categories might not be compatible with parental or guardian control. In such a case, it is considered that, if parental or guardian control is not implemented, the relevant authentication risks will not be addressed and, therefore, conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU would not be ensured. |
(8) |
Clause 6.3.2.4 of harmonised standard EN 18031-3:2024 includes assessment criteria for secure updates. Four different implementation categories are laid down, based on digital signatures, secure communication mechanisms, access control mechanisms or others. None of the methods alone are sufficient for the treatment of financial assets. It is considered that the assessment criteria do not properly address the relevant authentication risks and cannot therefore ensure conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU. |
(9) |
The references of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 should therefore be published in the Official Journal of the European Union with restrictions. |
(10) |
Annex I to Commission Implementing Decision (EU) 2022/2191 (5) provides the references of harmonised standards conferring a presumption of conformity with Directive 2014/53/EU. In order to ensure that the references of harmonised standards drafted in support of Directive 2014/53/EU are listed in one act, the references of harmonised standards EN 18031-1:2024, EN 18031-2:2024 and EN 18031-3:2024 should be included in that Annex, with restrictions. |
(11) |
Implementing Decision (EU) 2022/2191 should therefore be amended accordingly. |
(12) |
Compliance with a harmonised standard confers a presumption of conformity with the corresponding essential requirements set out in Union harmonisation legislation from the date of publication of the reference of such standard in the Official Journal of the European Union. This Decision should therefore enter into force on the day of its publication, |
HAS ADOPTED THIS DECISION:
Article 1
Annex I to Implementing Decision (EU) 2022/2191 is amended in accordance with the Annex to this Decision.
Article 2
This Decision shall enter into force on the day of its publication in the Official Journal of the European Union.
Done at Brussels, 28 January 2025.
For the Commission
The President
Ursula VON DER LEYEN
(1) OJ L 316, 14.11.2012, p. 12, ELI: http://data.europa.eu/eli/reg/2012/1025/oj.
(2) Directive 2014/53/EU of the European Parliament and of the Council of 16 April 2014 on the harmonisation of the laws of the Member States relating to the making available on the market of radio equipment and repealing Directive 1999/5/EC (OJ L 153, 22.5.2014, p. 62, ELI: http://data.europa.eu/eli/dir/2014/53/oj).
(3) Commission Implementing Decision C(2022)5637 of 5 August 2022 on a standardisation request to the European Committee for Standardisation and the European Committee for Electrotechnical Standardisation as regards radio equipment in support of Directive 2014/53/EU of the European Parliament and of the Council and Commission Delegated Regulation (EU) 2022/30.
(4) Commission Delegated Regulation (EU) 2022/30 of 29 October 2021 supplementing Directive 2014/53/EU of the European Parliament and of the Council with regard to the application of the essential requirements referred to in Article 3(3), points (d), (e) and (f), of that Directive (OJ L 7, 12.1.2022, p. 6, ELI: http://data.europa.eu/eli/reg_del/2022/30/oj).
(5) Commission Implementing Decision (EU) 2022/2191 of 8 November 2022 on the harmonised standards for radio equipment drafted in support of Directive 2014/53/EU of the European Parliament and of the Council (OJ L 289, 10.11.2022, p. 7, ELI: http://data.europa.eu/eli/dec_impl/2022/2191/oj).
ANNEX
In Annex I, the following rows are added:
No |
Reference of the standard |
‘164. |
EN 18031-1:2024 Common security requirements for radio equipment – Part 1: internet connected radio equipment Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (d), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. |
165. |
EN 18031-2:2024 Common security requirements for radio equipment – Part 2: radio equipment processing data, namely internet connected radio equipment, childcare radio equipment, toys radio equipment and wearable radio equipment Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU if, by applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. Notice 3: For the classes or categories of radio equipment covered by clause 6.1.3, 6.1.4, 6.1.5 or 6.1.6 of this harmonised standard, this harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (e), of Directive 2014/53/EU if, by applying its clauses 6.1.3.4.2, 6.1.4.4.2, 6.1.5.4.2 and 6.1.6.4.2, parental or guardian access control is not ensured. |
166. |
EN 18031-3:2024 Common security requirements for radio equipment – Part 3: internet connected radio equipment processing virtual money or monetary value Notice 1: The sections named “rationale” and “guidance”, in this harmonised standard, do not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU. Notice 2: This harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU if, when applying its clauses 6.2.5.1 and 6.2.5.2, the user is allowed not to set and use any password. Notice 3: As regards the assessment criteria set out in clause 6.3.2.4 of this harmonised standard, this harmonised standard does not confer a presumption of conformity with the essential requirement set out in Article 3(3), first subparagraph, point (f), of Directive 2014/53/EU.’ |
ELI: http://data.europa.eu/eli/dec_impl/2025/138/oj
ISSN 1977-0677 (electronic edition)