Case Study

Radio equipment cybersecurity readiness

How we guided a global electronics group to prepare for Delegated Regulation (EU) 2022/30 under the Radio Equipment Directive; spanning products across automotive, off-highway, agriculture, energy, transportation, and other sectors, by establishing a clear, portfolio wide compliance path using the EN 18031 standards and the 2022 Blue Guide.
Radio equipment cybersecurity readiness
About

Clarity at portfolio scale, from ambiguity to evidence

A global electronics group specializing in connectivity and vehicle electronics needed a coordinated program to address the new RED cybersecurity requirements across their portfolio of connected products. The scope spanned multiple sectors, including automotive, off-highway, agriculture, energy, and transportation, with products such as TCUs and gateways at the core.

Awedco took the role of governance partner and enabler; guiding, overseeing, and providing on-hand support where required. We created clarity in roles and responsibilities, aligned suppliers and clients, and established a repeatable evidence model toward presumption of conformity via EN 18031.

Given the confirmed application date of 1 August 2025, we prioritized early visibility by clarifying the scope, consistent documentation, and proactive communication with suppliers, notified bodies, and competent/market-surveillance authorities to reduce late surprises.

Our focus was on reducing ambiguity while preparing the organization for the application date.

Services
Industry

Multi-sector

The engagement covered products deployed in diverse operating contexts, from road and off-highway machinery to energy and transport. The cross-sector footprint required a single playbook that could travel between divisions without reinterpreting scope.
Client

Global electronics group

A multi-division manufacturer designing, among others, radio-enabled systems used across mobility and industrial environments. The portfolio spans on-board electronics, connectivity, and control units delivered through regional business units and partner suppliers.
Regulatory alignment

Notified bodies and authorities

To close interpretation gaps early, we coordinated clarifications with standardization working groups, notified bodies and maintained touchpoints with market surveillance authorities where appropriate. These conversations, paired with supplier and customer communications, helped align interface boundaries, responsibilities, and test coverage.
Scope and standards

EU 2022/30, EN 18031, and Blue Guide

We established a compliance path under the RED cybersecurity delegated regulation, using the EN 18031 series as the organizing spine for requirements, and applied the Blue Guide to clarify roles and documentation responsibilities between the group, suppliers, and customers. This alignment reduced ambiguity around interfaces, evidence ownership, and the practical meaning of “presumption of conformity.”

Our Approach

Phase 1

Phase 2

Phase 3

Result

Readiness realized

The group established a single, portfolio-level view of RED cybersecurity obligations, what’s in scope, the rationale, and the prioritization, along with a repeatable compliance model based on EN 18031 and a consistent approach to supplier and client alignment.

Using EN 18031 standards as the organizing spine, we implemented a traceable evidence model and practical templates that teams reused across product lines. This cut work, set common expectations with suppliers, and supported presumption of conformity once harmonized references were published. 

Clarifications with notified bodies and touchpoints with competent/market-surveillance authorities closed interpretation gaps early. Supplier and customer communication moved from ad hock requests to a shared playbook, supporting confident progress toward the 1 August 2025 date.

Ready when you are

Share a few lines about your context, goals, constraints, or timelines. We will work with you to define the next steps with clarity.
CTA