Who Enforces EN 18031? The Real State of RED Cybersecurity Audits and Fines, One Year In
EN 18031 has been mandatory for radio equipment on the EU market since 1 August 2025. One year later: who can actually audit and fine you, what an inspection looks like, and how much enforcement has really happened, from the Dutch pentest lab to Italy's territorial inspectorates.

Key Takeaways
EN 18031 became mandatory for the RED Directive cybersecurity requirements, Articles 3.3(d), 3.3(e) and 3.3(f), on 1 August 2025. A year later, manufacturers keep asking two questions: who exactly can audit and fine us, and is anyone actually doing it?
Enforcement is national, not central: every Member State designates its own Market Surveillance Authorities (MSAs) under Regulation (EU) 2019/1020. There is no single EU cybersecurity inspector.
The audit is mostly documentary: authorities request your Declaration of Conformity and technical file first, and can also access embedded software, sample devices and send them to a lab.
Cybersecurity-specific checks are confirmed: the Dutch RDI publicly states it tests products against the RED 3.3 requirements in a dedicated IoT lab, including penetration testing and an AI firmware scanner.
The surveillance machinery runs at scale: Germany's Bundesnetzagentur found deficiencies affecting 7.7 million devices in 2025 under general RED surveillance.
The first legal actions have already happened: named products are under RED sales bans, and an EN 18031 documentation gap has already cost one manufacturer 11 weeks of sales. Fines are rarely published with names (in most countries never), so silence in the news means invisibility, not inaction.
Who Enforces EN 18031? National Authorities, Not Brussels
EN 18031 compliance is enforced by national Market Surveillance Authorities (MSAs). Regulation (EU) 2019/1020 requires each Member State to designate one or more authorities per product sector, radio equipment included. They coordinate at EU level, but the inspection, the corrective order and the fine always come from a national body.
| Country | RED market surveillance authority |
|---|---|
Germany | Bundesnetzagentur (BNetzA) |
Netherlands | RDI (Rijksinspectie Digitale Infrastructuur) |
Italy | MIMIT (DGTCSI - ISCTI) with its territorial inspectorates |
France | ANFR (Agence nationale des fréquences) |
Ireland | ComReg (sole MSA for the RED) |
Sweden | PTS (Swedish Post and Telecom Authority) |
Austria | Fernmeldebüro (Federal Office for Telecommunications) |
Belgium | BIPT / IBPT (Institute for Postal Services and Telecommunications) |
Bulgaria | State Agency for Metrological and Technical Surveillance |
Croatia | HAKOM (Regulatory Authority for Network Industries) |
Cyprus | OCECPR and the Department of Electronic Communications |
Czechia | Czech Telecommunication Office (ČTÚ) and Czech Trade Inspection |
Denmark | Danish Safety Technology Authority |
Estonia | TTJA (Consumer Protection and Technical Regulatory Authority) |
Finland | Traficom |
Greece | EETT (Hellenic Telecommunications and Post Commission) |
Hungary | NMHH (National Media and Infocommunications Authority) |
Latvia | Consumer Rights Protection Centre (PTAC) |
Lithuania | RRT (Communications Regulatory Authority) |
Luxembourg | ILNAS (Market Surveillance) |
Malta | MCCAA (Market Surveillance Directorate) |
Poland | UKE (Office of Electronic Communications) |
Portugal | ANACOM |
Romania | ANCOM |
Slovakia | Slovak Trade Inspection |
Slovenia | Market Inspectorate |
Spain | State Secretariat for Telecommunications and Digital Infrastructures |
For Italy, the official MIMIT page on market surveillance assigns coordination to the Directorate-General for Digital and Telecommunications through ISCTI. The ministry's territorial inspectorates carry out inspections and act as the sanctioning authorities, technical testing goes to the public Eurolab Radio or accredited laboratories, and the postal and communications police collaborate.
In Ireland, ComReg is the sole MSA for the RED and runs recurring inspection campaigns on radio equipment sold in the country.
What an EN 18031 Audit Actually Looks Like

EU law never uses the word audit. Regulation 2019/1020 speaks of documentary checks and, where appropriate, physical and laboratory checks. Article 14 lets MSAs demand technical documentation, access embedded software where needed, carry out unannounced inspections and acquire samples. In practice, a check on the RED cybersecurity requirements follows a recognisable sequence:
The authority selects your product: random sampling, online marketplace monitoring, a customs referral, a complaint, or a finding by another Member State.
It contacts the manufacturer or importer and requests the EU Declaration of Conformity and the technical documentation.
It checks whether Articles 3.3(d)/(e)/(f) apply to your product and whether the file actually contains an assessment against them, which since 1 August 2025 normally means EN 18031.
If needed, it buys or samples a physical unit and sends it for laboratory or cybersecurity testing.
It issues findings and, depending on severity, the ladder runs from corrective action and firmware fixes to stop-sale, withdrawal, recall and a fine.
Notice where the sequence starts: with your paperwork. A product whose documentation never mentions the cybersecurity requirements can be found non-compliant before anyone connects it to a test bench.
One Year In: How Much Enforcement Is Actually Happening?

The most transparent authority so far is the Dutch RDI. It maintains a dedicated RED 3.3 page and an IoT test lab where inspectors verify whether products meet the cybersecurity requirements applicable since 1 August 2025: password policies, update mechanisms, connection security and account deletion on smart doorbells, baby monitors, routers and smartwatches, including penetration tests. In June 2026 the RDI even won an innovation award for an AI firmware vulnerability scanner its inspectors use to prioritise findings. A European MSA is testing products against RED 3.3 today.
Germany shows the scale of the machinery this plugs into. In its 2025 market surveillance results, the Bundesnetzagentur reported deficiencies affecting 7.7 million devices, with 8,202 suspicious customs consignments (89 percent non-compliant) and over 359,000 items stopped at the border. One honest caveat: those figures cover all RED essential requirements, not cybersecurity specifically. BNetzA also publishes a running list of market-restricting measures naming individual products barred from the market, with entries added as recently as January 2026. Bans against named products are routine business, and cybersecurity is now one more ground for them.
Is there a documented EN 18031 case? One, with a caveat. Compliance provider TecEx published a 2026 case study describing a smart-home gateway launched in four EU markets in September 2025 with a valid CE mark but no Article 3.3(d)/(e)/(f) assessment in its file. A routine documentation audit caught the gap and the product spent 11 weeks off the market while the EN 18031 assessment and an updated Declaration of Conformity were produced. Manufacturer and authority are anonymised, so treat it as industry evidence, not an official decision.
And the fines? Do not expect a press release. In most member states a RED fine is an administrative decision that is never published with the company's name; of the authorities above, only the Dutch RDI names fined companies by default. France's ANFR even documents the administrative fine as a standard step of the same procedure that produces withdrawals and recalls. The visible actions are the bans and suspensions; the fines attached to the same procedures stay out of the public record. Their absence from the news is invisibility, not inaction.
What Non-Compliance Can Cost, Country by Country
The RED sets the obligations, but penalties live in national law, so exposure differs by country. Three verified examples:
| Country | Legal basis | Maximum exposure |
|---|---|---|
Germany | FuAG, Section 37 | Fines up to 100,000 euro for essential-requirement breaches, up to 10,000 euro for documentation and information offences |
Ireland | S.I. No. 14 of 2026, Regulation 58 | On indictment, fines up to 500,000 euro, up to 2 years' imprisonment, or both |
Italy | D.lgs. 128/2016, Article 46 | 5,292 to 31,755 euro for non-compliant equipment, plus 26 to 158 euro per individual unit; lower ranges for documentation failures |
Sources: the German Funkanlagengesetz Section 37, the Irish European Union (Radio Equipment) Regulations 2026, and the Italian d.lgs. 22 June 2016, n. 128. Note the Italian per-unit multiplier: on 10,000 devices it alone can exceed the headline fine.
The fine is rarely the expensive part, though. The real cost sequence is: documentation request, non-compliance finding, sales suspension while you remediate, possible withdrawal or recall, and propagation to other Member States. The anonymised gateway case burned 11 weeks of revenue across four markets before any fine entered the picture.
Frequently Asked Questions
Do notified bodies enforce EN 18031?
No. A notified body is a conformity assessment route (Module B) you use when you cannot or do not want to fully self-declare against the harmonised standard. Enforcement, audits and fines belong exclusively to the national market surveillance authorities. See our guide on Module A self-declaration for how the routes differ.
Has any company been fined for EN 18031 yet?
Quite possibly, but you would not read about it: in most member states a RED fine is an administrative decision that is never published with the company's name. The exception is the Dutch RDI, which publishes fined companies by default and has not yet published one for radio equipment. What is public: RED 3.3 testing by the RDI, named product bans on Germany's list, and an anonymised 11-week market suspension for a missing Article 3.3(d)/(e)/(f) assessment.
Who checks EN 18031 compliance in Italy?
MIMIT, through DGTCSI - ISCTI, coordinates RED market surveillance; its territorial inspectorates perform the inspections and impose the sanctions of Article 46 of d.lgs. 128/2016, with laboratory testing at Eurolab Radio or accredited labs. Italy has not yet published RED 3.3-specific enforcement statistics.
What triggers an inspection?
Random sampling, online marketplace monitoring, customs referrals, user complaints, vulnerability reports, or a measure taken by another Member State's authority. You do not get to schedule it.
Can a decision in one EU country affect my sales everywhere?
Yes. Under the RED safeguard mechanism, a restrictive measure justified in one Member State is communicated to the others and to the Commission, and regularly results in equivalent prohibitions across the EU. Germany's public list of market-restricting measures shows this happening against named products.
Conclusion
So, who enforces EN 18031 and are they already doing it? National market surveillance authorities enforce it: BNetzA in Germany, RDI in the Netherlands, MIMIT's territorial inspectorates in Italy, ANFR in France, ComReg in Ireland. And enforcement has started: documentation checks are routine, the Dutch RDI is penetration-testing products against RED 3.3, and national laws already price non-compliance at up to 100,000 euro in Germany, 500,000 euro in Ireland, and per-unit fines in Italy.
The first legal actions are on the books; the fines that follow them are simply not published with names. It is still the cheapest moment to get compliant: the machinery is running, and the authorities' first question will be for your technical file, not your firmware. If that file already demonstrates EN 18031, the audit is an exchange of documents. If it does not, everything that follows runs on the regulator's schedule.
RedComply: Audit-Ready Before They Ask
Every enforcement path in this article starts with the same request: show us your Declaration of Conformity and technical documentation. RedComply exists so that request never finds you unprepared.
A complete EN 18031 technical file, by construction: guided tables for every requirement of EN 18031-1, -2 and -3, so a documentary check finds an assessment where it expects one.
Decision trees with recorded outcomes: every PASS, FAIL or NOT APPLICABLE verdict is stored with its justification, exactly what a documentary check evaluates.
Test plans across all three assessment types: conceptual, functional completeness and functional sufficiency.
A Declaration of Conformity generated from the data: the document an inspector asks for first is produced from the file that backs it, so the two never diverge.
Market surveillance is no longer theoretical. Visit redcomply.com and have your answer ready before the request arrives.
