EU RED and EN 18031: A Wi-Fi Microinverter Importer Checklist
A technical-file workflow covering RED cybersecurity scope, EN 18031 evidence, passwords, updates and importer traceability.
TMG Technical Team
Compliance Engineering
A Wi-Fi microinverter is not only power-conversion equipment. Its radio and internet-connected functions can bring it within the Radio Equipment Directive cybersecurity requirements that apply from 1 August 2025 under Delegated Regulation (EU) 2022/30.
This checklist focuses on the connected product placed on the EU market. It is distinct from project tender cybersecurity clauses, which are covered in the EU auction cybersecurity guide.
Confirm whether the product is in scope
Map the inverter, radio module, app, cloud service and gateway. Delegated Regulation 2022/30 applies the RED Article 3(3)(d) essential requirement to internet-connected radio equipment and includes additional privacy/fraud provisions for defined classes.
Document which component communicates by radio, whether it reaches the internet directly or through other equipment, and what data it processes. Do not assume that a detachable gateway removes the system from review.
Build the conformity route before labeling
EN 18031-1:2024 is a harmonized standard relevant to protection of networks under RED. Harmonized-standard references and limitations must be read carefully; the Commission's publication includes conditions related to password handling.
The manufacturer should document the chosen conformity-assessment route, applicable clauses, test evidence and any gaps. The importer should not treat a laboratory marketing letter as a complete EU technical file.
| File element | Evidence to request |
|---|---|
| Product identity | Model, hardware, radio module, firmware |
| Scope assessment | Data flows and internet connection diagram |
| Risk assessment | Assets, threats, controls and residual risks |
| EN 18031 evaluation | Clause matrix and report reference |
| Authentication | Unique/default credential and reset policy |
| Software update | Authorization, integrity and failure behavior |
| Vulnerability process | Intake, triage, disclosure and support period |
| EU documents | Declaration, labeling and technical-file index |
Review password and update behavior on samples
Check first-use credentials, forced changes, rate limiting where applicable, recovery, ownership transfer and factory reset. Avoid shared hard-coded passwords across devices. Verify that update packages are authenticated, integrity-checked and recover safely from interruption.
The monitoring handover checklist addresses account ownership and customer support; the RED file must additionally show product-level conformity evidence.
Trace cloud dependencies and support lifetime
Record cloud endpoints, mobile applications, third-party libraries, radio module, certificate handling and the period for security updates. Define what happens if the internet or cloud service is unavailable and which electrical functions remain local.
Require change notification when firmware, app, cloud authentication or radio hardware changes. Assess whether the risk analysis, tests, declaration and instructions need revision.
RED conformity is not the complete lifecycle workflow. From 11 September 2026, the CRA introduces operational reporting deadlines for manufacturers that become aware of actively exploited vulnerabilities or severe product-security incidents. Use the EU CRA Wi-Fi microinverter reporting checklist to assign the 24/72-hour clock, ENISA SRP roles, component evidence and final-report ownership.
Complete importer checks
Before placing stock on the market, verify economic-operator details, product and packaging identification, required instructions/languages, EU declaration availability and technical-document retention responsibilities. Coordinate this file with EMC and radio evidence; the EMC importer checklist covers that separate layer.
This is a technical procurement guide, not legal advice. Send the connection architecture, firmware policy, target EU markets and proposed labels through TMG Contact. The output should be a clause-by-clause gap list before mass production.
Sources & further reading
- https://eur-lex.europa.eu/eli/reg_del/2022/30/2023-10-27/eng
- https://webgate.ec.europa.eu/circabc-ewpp/d/d/workspace/SpacesStore/8e7cd43d-baab-4450-8f0c-7c9785e75f2c/download
Last reviewed April 8, 2025.


