Directive 2014/53/EU · Del. Reg. 2022/30Generate my documentation — €99
ACTIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

The cybersecurity risk assessment maps your product's security status to the requirements of Arts. 3(3)(d), (e) and (f). REDCheck generates it requirement by requirement, following the EN 18031 categories.

Annex V of Directive 2014/53/EU requires the technical documentation to contain 'results of design calculations made, examinations carried out, and other relevant similar elements' (Annex V(g)). For cybersecurity, this means a structured risk assessment: which requirements apply, what your product implements, what gaps exist and what risk each gap represents. REDCheck walks you through the EN 18031 categories — access control, authentication, cryptography, secure communications, software integrity, updates, vulnerability management, event logging, personal data protection — and generates a risk table that maps each requirement to your implementation status. 30 minutes. €99 per product.

Generate my RED documentation — €99Free: does my product need RED cybersecurity documentation?

€99 one-time payment · 5 PDF documents in ZIP · 30 minutes · 100% in your browser

Directive 2014/53/EU · Art. 3(3)(d)(e)(f) · Art. 21 + Annex V · Art. 18 + Annex VI · Art. 10(9) + Annex VII · Delegated Reg. (EU) 2022/30 · EN 18031-1, -2, -3

Risk assessment structure: the numbers

The risk assessment is the analytical core of your cybersecurity documentation.

9 categories
EN 18031 organises requirements into categories: ASM, AUM, CRM, SCM, SIM, SUM, VLM, ELM, PDM. REDCheck covers all applicable ones.
3 statuses
For each requirement: Implemented, Partially Implemented, Not Applicable. Your answers drive the risk table.
Annex V(g)
The risk assessment satisfies the 'results of examinations' element required by Art. 21 and Annex V.

How REDCheck builds your risk assessment

The generator walks through each applicable EN 18031 category systematically.

1
Identify applicable requirements
Based on product classification: EN 18031-1 categories for Art. 3(3)(d), EN 18031-2 for (e), EN 18031-3 for (f). Only applicable requirements are included.
2
Assess access control (ASM)
Does your product enforce access control policies? Role-based access? Principle of least privilege? Your answers are recorded.
3
Assess authentication (AUM)
Password management, default credentials, multi-factor authentication where applicable. EN 18031 is specific about what 'implemented' means.
4
Continue through all applicable categories
CRM (cryptography), SCM (secure communications), SIM (software integrity), SUM (secure updates), VLM (vulnerability management), ELM (event logging), PDM (personal data management).
5
Generate risk table
Your answers are mapped to a structured table: requirement → EN 18031 reference → implementation status → risk level. This table is the core of your risk assessment document.
6
Download as part of the 5-document ZIP
The risk assessment is PDF 3 in the package. It references the EN 18031 categories and Arts. 3(3)(d)/(e)/(f) in every row.

Three mistakes about cybersecurity risk assessments

COMMON ERROR

"A penetration test IS the risk assessment"

A penetration test evaluates TECHNICAL vulnerabilities in a running system. The cybersecurity risk assessment required by Art. 21 evaluates REGULATORY compliance: does the product meet each requirement of Arts. 3(3)(d), (e), (f) as detailed in EN 18031? A pentest report is evidence (Annex V(h)). The risk assessment is the structured analysis (Annex V(g)). Both are needed; they serve different purposes.

COMMON ERROR

"We can use our ISO 27001 risk assessment"

ISO 27001 covers information security management SYSTEMS — organisational processes, policies, people. The EN 18031 risk assessment covers PRODUCT-level cybersecurity: does THIS radio equipment implement access control, authentication, secure updates, etc.? The scope is entirely different. ISO 27001 is about your company. EN 18031 is about your product.

COMMON ERROR

"Risk assessment is only needed for high-risk products"

The Directive does not distinguish risk levels for documentation purposes. Art. 21 requires technical documentation for ALL radio equipment covered by Art. 3. A €3 smart plug and a €300 industrial gateway have the same documentation obligation.

What's in the ZIP

5 PDF documents generated from your product data. Each cites the exact article of Directive 2014/53/EU that it covers.

1

Product Classification

Art. 1, Del. Reg. (EU) 2022/30 + Art. 3(3), Dir. 2014/53/EU.

2

Cybersecurity Technical Documentation

Art. 21 + Annex V. Requirement-by-requirement documentation.

3

Risk Assessment

Arts. 3(3)(d) and (e). Structured risk table.

4

EU Declaration of Conformity

Art. 18 + Annex VI.

5

Simplified Declaration + Label

Art. 10(9) + Annex VII.

Look before you buy — Download sample dossier (PDF, fictitious product) — Real structure, real articles, real format. Fictitious data.

Generated from your data, in your browser. No product data leaves your computer.

What you pay

🧾 CONSULTANCY
€5,000–15,000
Per product model. Includes risk assessment as part of a larger engagement.
✓ REDCHECK
€99
5 documents including structured risk assessment. 30 minutes.

Technical documentation and third-party testing: two layers

● LAYER 1

Cybersecurity technical documentation (Annex V)

5 PDF documents. 30 min. €99 per product. Maps your EN 18031 assessment to the Annex V structure. This is what Art. 21 requires BEFORE your product can bear CE marking — regardless of conformity route.

∅ LAYER 2

Conformity assessment route

If you fully apply EN 18031, Art. 16 grants presumption of conformity → Module A self-declaration (Annex II) without Notified Body. If partially applied or not applied: Art. 17(4) requires Module B+C (Annex III) or Module H (Annex IV) with Notified Body. REDCheck generates the Layer 1 documentation that is a prerequisite for EITHER route.

We do not assess your product. We do not interpret EN 18031. We structure the documentation that Art. 21 requires based on YOUR assessment of YOUR product.

What happens without cybersecurity documentation

Art. 46 of Directive 2014/53/EU requires Member States to establish penalties that are effective, proportionate and dissuasive.

🇪🇺
Market withdrawal and sales prohibition
Immediate

Art. 40 of Directive 2014/53/EU. Market surveillance can require withdrawal across all 27 Member States.

🇩🇪
Germany — Produktsicherheitsgesetz
€3,000–€30,000

Administrative fines under §19. Up to 1 year of imprisonment under §20.

🛒
Marketplace listing removal
Revenue loss

Amazon and EU marketplaces require conformity documentation. Missing cybersecurity documentation triggers listing suspension.

Alternatives

AlternativeCostWhat you get
Notified Body / accredited lab€5,000–10,000 per model3–6 months. Full third-party assessment.
Cybersecurity consultancy€5,000–15,000 per modelCustom report. Weeks of wait.
Assemble documentation yourself€0 (your time)EN 18031 has 600+ pages. No template.
REDCheck€995 documents, 30 min, per model

Documenting more than one product?

Professional Pack: €999 for 70 generations.

Request volume pricing
Reply within one business day.

What REDCheck guarantees and what it does not

REDCheck generates a document structured under Art. 21 and Annex V of Directive 2014/53/EU based on the information you enter. The truthfulness, accuracy and completeness of that information is your responsibility as manufacturer of the radio equipment.

We guarantee that the document structure follows Art. 21 and Annex V of Directive 2014/53/EU and that the legal references cited are correct as of the latest verification date. We do not guarantee that a specific document will be accepted by a market surveillance authority in a specific case, nor by a commercial buyer in a procurement process.

REDCheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.

Frequently asked questions — cybersecurity risk assessment

What does the risk assessment actually look like?
A structured table with one row per applicable EN 18031 requirement. Each row contains: the requirement ID, the EN 18031 category (e.g., AUM-3: password management), the applicable Directive article, your implementation status (implemented/partial/N/A), and a risk descriptor. Download the sample dossier to see the format.
If all requirements are 'implemented,' is the risk assessment still needed?
Yes. The risk assessment documents the POSITIVE case as well as gaps. Full implementation is the best outcome — but it must be documented to demonstrate compliance under Art. 21.
What happens when the CRA replaces the RED cybersecurity requirements?
Delegated Regulation (EU) 2022/30 will be repealed with effect from 11 December 2027, when the Cyber Resilience Act — Regulation (EU) 2024/2847 — enters full application. REDCheck covers the window from 1 August 2025 to 11 December 2027. For CRA documentation from that date, SolidwareTools offers CRACheck.
Is it a subscription?
No. One-time payment. Each license includes a 30-day editing window and up to 10 regenerations. The 5 PDF documents you download are yours permanently.
Can I request a refund?
Under Art. 16(m) of Directive (EU) 2011/83 on consumer rights, by activating the license you give express consent to the immediate generation of the digital content, waiving the 14-day right of withdrawal. Refunds are accepted only for reproducible technical failures reported to hello@solidwaretools.com within 14 days of purchase.
What if the regulation changes?
If Directive 2014/53/EU, Delegated Regulation (EU) 2022/30 or the EN 18031 standards change during your license validity period, you can regenerate the documents with the updated version of the generator at no additional cost.
⚠️ Important notice: REDCheck is a documentary self-assessment tool, not legal advice or a third-party audit. The document is generated from the data you enter. The accuracy of the data is your responsibility under Art. 10(1) of Directive 2014/53/EU. REDCheck does not replace a conformity assessment by a Notified Body where required under Art. 17(4) of the Directive.

Generate a structured cybersecurity risk assessment for your radio equipment in 30 minutes.

Five PDF documents. Art. 21 and Annex V. EN 18031 categories mapped requirement by requirement. Your product data never leaves your browser.

€99 per product
One-time payment · No subscription · 30 minutes · 10 regenerations · 30-day editing window · Professional Pack: €999
Generate my RED documentation — €99
✓ Last regulatory check: 6 May 2026 · No substantive changes detected · View history