Directive 2014/53/EU · Del. Reg. 2022/30Generate my documentation — €99
ACTIVE — Enforcement tracker · Deadline dashboard · Transposition status — Updated weekly from EUR-Lex, Safety Gate, OEIL & 12 official sourcesView regulatory intelligence →

You have read EN 18031. You understand the requirements. What you need is a tool that converts your assessment into structured technical documentation under Art. 21 and Annex V.

EN 18031 is 600+ pages across three parts: EN 18031-1 (network protection, Art. 3(3)(d)), EN 18031-2 (personal data, Art. 3(3)(e)) and EN 18031-3 (fraud, Art. 3(3)(f)). You have evaluated your product against the applicable categories: access control, authentication, password management, secure communications, software integrity, secure updates, vulnerability management, event logging. The problem is not understanding the requirements — it is converting your assessment into a formal documentation package that satisfies Art. 21 and Annex V of Directive 2014/53/EU. A consultancy charges €5,000–20,000 to do exactly that. REDCheck does it in 30 minutes for €99: guided requirement-by-requirement input mapped to the EN 18031 categories, structured output in 5 PDF documents. Your knowledge, our structure.

Generate my RED documentation — €99Free: does my product need RED cybersecurity documentation?

€99 one-time payment · 5 PDF documents in ZIP · 30 minutes · 100% in your browser

Directive 2014/53/EU · Art. 3(3)(d)(e)(f) · Art. 21 + Annex V · Art. 18 + Annex VI · Art. 10(9) + Annex VII · Delegated Reg. (EU) 2022/30 · EN 18031-1, -2, -3

EN 18031 documentation: the numbers

EN 18031 defines the HOW. Directive 2014/53/EU defines the WHAT. REDCheck bridges the gap: your EN 18031 assessment becomes formal technical documentation under Art. 21.

3 parts
EN 18031-1 (network, Art. 3(3)(d)) · EN 18031-2 (data, Art. 3(3)(e)) · EN 18031-3 (fraud, Art. 3(3)(f))
Art. 16
Full application of EN 18031 → presumption of conformity → Module A self-declaration without Notified Body
5 documents
Product classification, technical documentation with EN 18031 mapping, risk assessment, EU declaration of conformity, simplified declaration + label

How REDCheck maps your EN 18031 assessment to Annex V

The generator walks you through the EN 18031 categories requirement by requirement. Your answers are structured into the formal documentation package.

1
Company details
Legal name, role under Directive 2014/53/EU (manufacturer Art. 10, importer Art. 12, or manufacturer by virtue of Art. 14), country, EU contact.
2
Product classification
Determines which parts of EN 18031 apply. Art. 1(1): internet-connected → EN 18031-1. Art. 1(2): personal data processing → EN 18031-2. Art. 1(3): payment capability → EN 18031-3. The generator identifies the applicable combination.
3
EN 18031 requirement mapping
Requirement-by-requirement input across the applicable EN 18031 categories: access control (ASM), authentication (AUM), cryptography (CRM), secure communications (SCM), software integrity (SIM), secure updates (SUM), vulnerability management (VLM), event logging (ELM), personal data (PDM where applicable).
4
Implementation status per requirement
For each requirement: implemented, partially implemented or not applicable. Your answers map to a structured risk table that forms the core of the risk assessment document.
5
EU Declaration of Conformity
Formal declaration under Art. 18 and Annex VI. References the EN 18031 parts applied. If fully applied: basis for Module A self-declaration. If partially applied: documentation prerequisite for Notified Body assessment under Art. 17(4).
6
Download ZIP
5 PDF documents. EN 18031 references embedded in every section. Add to your technical file alongside test reports, schematics and user manual. Retain for 10 years (Art. 10(4)).

Three mistakes compliance teams make about EN 18031 documentation

COMMON ERROR

"We apply EN 18031 — so we don't need separate documentation"

Applying EN 18031 is a technical achievement. Documenting that application is a legal requirement. Art. 21 of Directive 2014/53/EU requires the manufacturer to draw up technical documentation that contains 'all relevant data or details of the means used to ensure compliance.' Applying EN 18031 without documenting how you applied it is like passing an exam without handing in the paper.

COMMON ERROR

"Our internal EN 18031 spreadsheet IS the technical documentation"

An internal spreadsheet may contain the right data, but Art. 21 and Annex V require a specific structure: general product description (Annex V(a)), design drawings (V(b)), list of harmonised standards applied (V(d)), results of examinations (V(g)), test reports (V(h)). A spreadsheet that covers EN 18031 categories but does not follow the Annex V structure is incomplete technical documentation. Market surveillance authorities review against Annex V, not against your internal format.

COMMON ERROR

"EN 18031 covers everything — we don't need to reference the Directive articles"

EN 18031 is a harmonised standard that SUPPORTS conformity with the essential requirements. The legal obligation comes from the Directive. Your documentation must reference both: the Directive articles (Art. 3(3)(d), (e), (f)) AND the EN 18031 parts applied. Art. 16 grants presumption of conformity only when the harmonised standards are applied AND their references have been published in the OJEU. The documentation must make this chain explicit.

What's in the ZIP

5 PDF documents structured by EN 18031 categories. Doc 2 (Cybersecurity Technical Documentation) maps your implementation status to ASM, AUM, CRM, SCM, SIM, SUM, VLM, ELM, PDM categories.

1

Product Classification

Art. 1, Del. Reg. (EU) 2022/30 + Art. 3(3), Dir. 2014/53/EU.

2

Cybersecurity Technical Documentation

Art. 21 + Annex V. Requirement-by-requirement documentation.

3

Risk Assessment

Arts. 3(3)(d) and (e). Structured risk table.

4

EU Declaration of Conformity

Art. 18 + Annex VI.

5

Simplified Declaration + Label

Art. 10(9) + Annex VII.

Look before you buy — Download sample dossier (PDF, fictitious product) — Real structure, real articles, real format. Fictitious data.

Generated from your data, in your browser. No product data leaves your computer.

What you pay

🧾 CONSULTANCY / NOTIFIED BODY
€5,000–20,000
Per product model. 2–6 months. They assess your product AND produce documentation. With REDCheck, you assess — we structure.
✓ REDCHECK
€99
5 documents. 30 minutes per product. You already know EN 18031. We give you the Annex V structure.

Technical documentation and third-party testing: two layers

● LAYER 1

Cybersecurity technical documentation (Annex V)

5 PDF documents. 30 min. €99 per product. Maps your EN 18031 assessment to the Annex V structure. This is what Art. 21 requires BEFORE your product can bear CE marking — regardless of conformity route.

∅ LAYER 2

Conformity assessment route

If you fully apply EN 18031, Art. 16 grants presumption of conformity → Module A self-declaration (Annex II) without Notified Body. If partially applied or not applied: Art. 17(4) requires Module B+C (Annex III) or Module H (Annex IV) with Notified Body. REDCheck generates the Layer 1 documentation that is a prerequisite for EITHER route.

We do not assess your product. We do not interpret EN 18031. We structure the documentation that Art. 21 requires based on YOUR assessment of YOUR product.

What happens without cybersecurity documentation

Art. 46 of Directive 2014/53/EU requires Member States to establish penalties that are effective, proportionate and dissuasive.

🇪🇺
Market withdrawal and sales prohibition
Immediate

Art. 40 of Directive 2014/53/EU. Market surveillance authorities can require withdrawal across all 27 Member States.

🇩🇪
Germany — Produktsicherheitsgesetz
€3,000–€30,000

Administrative fines under §19. Up to 1 year of imprisonment for serious offences under §20.

📋
Notified Body rejection
Time + cost lost

If you submit to a Notified Body without complete technical documentation under Annex V, the body will return your file incomplete. Art. 34(3): a Notified Body shall not issue a certificate if essential requirements have not been met. Incomplete documentation delays the process and costs money. Layer 1 first, then Layer 2.

Alternatives

AlternativeCostWhat you get
Notified Body (full service)€5,000–20,000 per modelAssessment + documentation. 2–6 months. Overkill if you already know EN 18031.
EU cybersecurity consultancy€3,000–15,000 per modelCustom report. Weeks. Their format, not necessarily Annex V structure.
Structure documentation yourself€0 (your time)Annex V has 9 elements. EN 18031 has 600+ pages. No template.
REDCheck€99Your EN 18031 assessment → 5 structured PDFs in 30 min

Documenting more than one product model?

If you document 10 or more product models, the Professional Pack saves 85%: €999 for 70 generations with a single license key. One generation per product model. Switch between products freely.

Request volume pricing
Reply within one business day.

What REDCheck guarantees and what it does not

REDCheck generates a document structured under Art. 21 and Annex V of Directive 2014/53/EU based on the information you enter. The truthfulness, accuracy and completeness of that information is your responsibility as manufacturer of the radio equipment.

We guarantee that the document structure follows Art. 21 and Annex V of Directive 2014/53/EU and that the legal references cited are correct as of the latest verification date. We do not guarantee that a specific document will be accepted by a market surveillance authority in a specific case, nor by a commercial buyer in a procurement process.

REDCheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.

Frequently asked questions — EN 18031 documentation tool

Does REDCheck cover all three parts of EN 18031?
Yes. The generator identifies which parts apply based on your product classification: EN 18031-1 for Art. 3(3)(d), EN 18031-2 for Art. 3(3)(e), EN 18031-3 for Art. 3(3)(f). If your product triggers multiple requirements, the documentation covers all applicable parts in a single package.
I partially apply EN 18031. Can I still use REDCheck?
Yes. REDCheck documents your implementation status requirement by requirement — including 'partially implemented' and 'not applicable.' If you partially apply EN 18031, your documentation will reflect that. Note that partial application means you CANNOT self-declare via Module A: Art. 17(4) requires Module B+C or H with a Notified Body. REDCheck generates the Layer 1 documentation that the Notified Body will review as part of the EU-type examination.
What about Implementing Decision (EU) 2025/138 restrictions?
Implementing Decision (EU) 2025/138 published EN 18031 references in the OJEU with certain restrictions — for example, requirements allowing users to skip password setup. If your product falls under a restriction, presumption of conformity for that specific requirement is NOT granted even if EN 18031 is applied. Your product may require Module B+C or H for those specific points. REDCheck flags this in the product classification step.
What happens when the CRA replaces the RED cybersecurity requirements?
Delegated Regulation (EU) 2022/30 will be repealed with effect from 11 December 2027, when the Cyber Resilience Act — Regulation (EU) 2024/2847 — enters full application. REDCheck covers the window from 1 August 2025 to 11 December 2027. For CRA documentation from that date, SolidwareTools offers CRACheck.
Is it a subscription?
No. One-time payment. Each license includes a 30-day editing window and up to 10 regenerations. The 5 PDF documents you download are yours permanently.
Can I request a refund?
Under Art. 16(m) of Directive (EU) 2011/83 on consumer rights, by activating the license you give express consent to the immediate generation of the digital content, waiving the 14-day right of withdrawal. Refunds are accepted only for reproducible technical failures reported to hello@solidwaretools.com within 14 days of purchase.
What if the regulation changes?
If Directive 2014/53/EU, Delegated Regulation (EU) 2022/30 or the EN 18031 standards change during your license validity period, you can regenerate the documents with the updated version of the generator at no additional cost.
⚠️ Important notice: REDCheck is a documentary self-assessment tool, not legal advice or a third-party audit. The document is generated from the data you enter. The accuracy of the data is your responsibility under Art. 10(1) of Directive 2014/53/EU. REDCheck does not replace a conformity assessment by a Notified Body where required under Art. 17(4) of the Directive.

You already know EN 18031. Convert your assessment into Annex V documentation in 30 minutes.

Five PDF documents. EN 18031 categories mapped to Art. 21 and Annex V. Your implementation status structured requirement by requirement. Your product data never leaves your browser.

€99 per product
One-time payment · No subscription · 30 minutes · 10 regenerations · 30-day editing window · Professional Pack: €999
Generate my RED documentation — €99
✓ Last regulatory check: 6 May 2026 · No substantive changes detected · View history