Product cybersecurity compliance

RED / EN 18031 readiness without checkbox security.

We help manufacturers of radio and connected products understand relevant cybersecurity requirements, identify gaps and build a defensible path from product architecture to evidence.

When this is relevant

A focused engagement when the question is already real.

  • You manufacture radio equipment or internet-connected devices for the EU market.

  • Your team needs to understand how EN 18031 applies to a specific product and architecture.

  • You need a structured gap assessment and evidence plan before conformity work progresses.

  • Engineering and compliance teams need one shared view of requirements, controls and remediation.

What we help with

Work structured around the product and the decision.

Product & architecture context

Map product boundaries, interfaces, data flows and security-relevant assumptions before assessing requirements.

Requirement applicability

Structure the relevant EN 18031 requirements around the actual product, including the role of EN 18031-1, -2 and where relevant -3.

Gap & evidence assessment

Connect current controls and product behaviour to expected evidence, highlighting gaps and weak traceability.

Remediation support

Translate findings into pragmatic engineering, process and documentation actions that product teams can own.

Outputs

Things your team can use after the workshop ends.

Exact deliverables depend on scope, but the work should create actionable decisions and reusable artefacts — not just commentary.

  • Structured applicability and gap view
  • Evidence and documentation plan
  • Prioritised remediation actions
  • Security-requirement traceability
  • Support for product and compliance stakeholders
How we work

Context → assessment → action → capability.

01Understand
02Assess
03Implement
04Enable
!

Important distinction

Our scope can cover preparation, assessment support, evidence readiness and remediation. Formal conformity assessment or certification, where required, is scoped separately and should never be implied without an agreed assessment route.

Start with the context

Bring us the product, architecture and the question.

We will help define a proportionate next step.

Discuss your project ↗