Assessment and Limitations of Standards:
•Limitation of Presumption of Conformity: The “rationale” and “guidance” sections of the standards do not confer a presumption of conformity.
•Password Settings: Clauses 6.2.5.1 and 6.2.5.2 of these standards allow users not to set or use any password, which is deemed inadequate to properly address authentication risks.
Cerpass advice:If the device allows users not to set a password, it must be reviewed by NB.
•Access Control: In EN 18031-2:2024, the access control mechanisms for toy and childcare radio equipment are non-compliant if parental or guardian control is not implemented.
Cerpass advice:Child care devices and toys products that do not have a parental control mechanism must be reviewed by NB, and the Risk assessment must be evaluated
•Secure Updates: Clause 6.3.2.4 of EN 18031-3:2024, regarding assessment criteria for secure updates, is insufficient to handle authentication risks related to financial assets.
Cerpass advice:Since the product involves financial transactions, Cerpass advice:it must have a higher standard security update mechanism and must be reviewed by NB.