Since 1 August 2025, any device with a radio (Wi-Fi, Bluetooth, cellular) on the EU market has to meet the RED cybersecurity essential requirements. Delegated Regulation (EU) 2022/30 activated Article 3.3(d), (e), (f); EN 18031 defines how you prove it. ELTON runs the discovery, proves exploitability, produces the evidence.
Delegated Regulation (EU) 2022/30 switched on three cybersecurity essential requirements in RED Article 3.3. They apply to internet-connected radio equipment, which is nearly every modern connected medical device, and became mandatory on 1 August 2025.
The device must not harm the network or misuse its resources. No amplification, no degradation, no becoming a foothold that spreads onto hospital infrastructure.
Safeguards for the personal data of the user and the subscriber. For a medical device, that is patient data, in transit and at rest, across every wireless interface.
Controls against unauthorized use and the manipulation of value or authorization. Access, identity, and integrity have to hold up over the air.
Conformity runs through the harmonized standards EN 18031-1, -2, and -3, one per essential requirement. ELTON tests against them the way an attacker would, then hands you the proof, whether you self-assess or go through a notified body.
A self-declaration of conformity with no evidence behind the wireless claims is exactly what post-market surveillance and market-check authorities are now authorized to challenge.
Every wireless interface is discovered, tested, and either proven exploitable or dismissed with reasoning. The EN 18031 mapping and the artifacts sit ready in one record, for the file and for any challenge.
Start with one wireless device. We build the twin, run discovery across the radio stack, and map the findings to EN 18031 so your RED file carries proof, not promises.