Recently, the Cybersecurity Laboratory of Shenzhen E-You Technology Co., Ltd. officially obtained the CNAS accreditation for the EU cybersecurity standard EN18031 and the UK ETSI EN 303 645 standards. This indicates that E-You Technology Co., Ltd. has opened a digital trust compliance channel for wireless devices to enter the EU and the UK markets, and has the capability for software security testing for IoT and wireless terminal devices. This is not only an important upgrade in the company's business scope, but also means that E-You can provide more solid technical guarantees for enterprises' products to smoothly enter the international market.
1. Coverage of Products
The applicable products include most wireless terminal devices that can access the Internet, covering but not limited to the following product types:
Network communication equipment: such as routers, cameras;
Smart home products: such as smart locks, smart appliances;
Wearable devices: such as smart watches, health monitoring devices;
Mobile terminals: such as smartphones, tablets;
Children-related products: such as smart toys, baby monitors, etc.
Corresponding regulations and products:
EN18031-1 corresponds to RED Article 3.3 (d), applicable to devices related to network protection;
EN18031-2 corresponds to RED Article 3.3 (e), applicable to devices processing personal data, traffic data or location data;
EN18031-3 corresponds to RED Article 3.3 (f), applicable to radio devices that enable the transfer of money, currency value or virtual currency as defined in Article 2 (d) of EU Directive 2019/713 by the holder or user;
ETSI EN 303 645 corresponds to the UK PSTI Act, aiming to enhance the cybersecurity level of connected Internet products, resist cyber attacks and protect user data.
2. About EN18031
On January 30, 2025, the European Commission officially published Decision (EU) 2025/138 in the Official Journal of the European Union, including EN 18031-1, EN 18031-2, and EN 18031-3 in the list of harmonized standards for the Radio Equipment Directive (RED). This series of standards clearly stipulates the compliance requirements for cybersecurity, privacy protection, and anti-fraud in radio equipment. As of August 1, 2025, all radio equipment entering the EU market must comply with the relevant requirements of RED Directive Article 3(3)(d), (e), and (f), otherwise it will not be able to be sold on the market.
3. About ETSI EN 303 645
Since April 29, 2024, the UK has officially implemented the Product Safety and Telecommunications Infrastructure Act (PSTI Act), imposing mandatory cybersecurity requirements on connected consumer devices. ETSI EN 303 645, as the core technical basis of this act, has been widely adopted by countries and regions such as the UK, the EU, and Australia, serving as the fundamental regulatory framework for the cybersecurity compliance of consumer IoT devices.
The Cybersecurity Laboratory of E-You will continue to track the latest developments in international cybersecurity regulations, working together with enterprises to jointly address compliance challenges in the global market, and helping manufacturers and technology providers develop secure, trustworthy, and reliable connected products, safeguarding the safety and efficient global market entry of products.