Since 1 August 2025, any device with a radio (Wi-Fi, Bluetooth, cellular) on the EU market has to meet the RED cybersecurity essential requirements. Delegated Regulation (EU) 2022/30 activated Article 3.3(d), (e), (f); EN 18031 defines how you prove it. ELTON runs the discovery, proves exploitability, produces the evidence. ELTON is an exploitability management platform, delivered as a managed program. Our team runs the testing continuously. You get the platform, the evidence, and a TestLink™ appliance, with no new headcount.
Delegated Regulation (EU) 2022/30 switched on three cybersecurity essential requirements in RED Article 3.3. They apply to internet-connected radio equipment, which is nearly every modern connected medical device, and became mandatory on 1 August 2025.
The device must not harm the network or misuse its resources. No amplification, no degradation, no becoming a foothold that spreads onto hospital infrastructure.
Safeguards for the personal data of the user and the subscriber. For a medical device, that is patient data, in transit and at rest, across every wireless interface.
Controls against unauthorized use and the manipulation of value or authorization. Access, identity, and integrity have to hold up over the air.
Conformity runs through the harmonized standards EN 18031-1, -2, and -3, one per essential requirement. ELTON tests against them the way an attacker would, then hands you the proof, whether you self-assess or go through a notified body.
A self-declaration of conformity with no evidence behind the wireless claims is exactly what post-market surveillance and market-check authorities are now authorized to challenge.
Every wireless interface is discovered, tested, and either proven exploitable or dismissed with reasoning. The EN 18031 mapping and the artifacts sit ready in one record, for the file and for any challenge.
Start with one wireless device. We build the twin, run discovery across the radio stack, and map the findings to EN 18031 so your RED file carries proof, not promises.
1 August 2025. Since that date, any device with a radio (Wi-Fi, Bluetooth, cellular) on the EU market has to meet the RED cybersecurity essential requirements. Delegated Regulation (EU) 2022/30 activated Article 3.3(d), (e) and (f) for internet connected radio equipment, which is nearly every modern connected medical device.
Article 3.3(d) requires that the device does not harm the network or misuse its resources. Article 3.3(e) requires safeguards for the personal data of the user and the subscriber, which for a medical device means patient data in transit and at rest. Article 3.3(f) requires controls against unauthorized use and the manipulation of value or authorization.
EN 18031 is the set of harmonized standards that carries presumption of conformity, one part per essential requirement: EN 18031-1 for network protection, EN 18031-2 for personal data and privacy, EN 18031-3 for fraud protection. Conformity runs through those standards whether you self assess or go through a notified body.
Yes, via the harmonized standards. But a self declaration with no evidence behind the wireless claims is exactly what post-market surveillance and market-check authorities are now authorized to challenge. The same evidence package supports either route, self assessment or handing it to a notified body.
Test it the way an attacker would. ELTON discovers every wireless interface, runs continuous discovery across the radio stack, and either proves a finding exploitable on the device or dismisses it with reasoning. Test cases and artifacts are mapped to EN 18031, so the RED file carries proof rather than promises.