RED cybersecurity requirements
Cybersecurity requirements for internet-connected radio equipment have applied since 1 August 2025. EN 18031-1:2024 has been published as a harmonised standard, with restrictions.
SECURITY AND STANDARDS
For a device that stays in the field for ten years, the real question is not “is there encryption” but “what happens when a vulnerability appears, and until when is it supported”.
SECURITY CONTROLS
The topics below have been verified by the product team. Technical detail and related documents for each row are shared in the technical file.
| Topic | Status | Scope |
|---|---|---|
| Device identity and commissioning | Verified | Every device carries a unique identity number created once during production. |
| Mutual authentication | Verified | The device and the server authenticate each other on first connection. |
| Communication encryption | Verified | Every communication is encrypted with AES-128. |
| Key management | Verified | Each device uses its own AES-128 key; keys are managed through İnodya's infrastructure. |
| Firmware integrity | Verified | The firmware package is cryptographically signed and encrypted, and anti-rollback protection is active. Thanks to the dual-bank layout, an interrupted update leaves the device booting the previous version. |
| Command authorisation | Verified | Valve commands can be issued by the utility or by an authorised customer; when the utility withdraws that permission, the customer can no longer issue commands. The command and its issuer are recorded on the IWS Platform. |
| Logging and audit trail | Verified | The device records all of its actions in its own memory: approximately 12,000 hourly, 1,200 daily and 200 monthly records, plus 4,000 event records. Logs can be retrieved over NB-IoT or on site via BConnect. |
This table reflects the product team's verification work. The encryption mode, key management detail and certification scope are shared per project together with the technical file.
SUPPORT POLICY
For a public buyer what matters is not the moment of purchase but the years that follow. The terms below are provided as a visible annex to the contract.
REGULATORY CONTEXT
The following is informational and does not constitute a declaration that the product conforms to these frameworks.
Cybersecurity requirements for internet-connected radio equipment have applied since 1 August 2025. EN 18031-1:2024 has been published as a harmonised standard, with restrictions.
Regulation (EU) 2024/2847 requires secure design, vulnerability handling, security updates and disclosure of the support period. General application starts 11 December 2027; reporting obligations start 11 September 2026.
Drinking water suppliers and distributors are listed among sectors of high criticality. This means supply chain security, incident management and update capability will be assessed more strictly.
Detailed consumption data can constitute personal data revealing household behaviour. Data minimisation, retention period, access rights, audit trail and notification must be part of the design.
Provides a useful security baseline for consumer IoT devices. It is not on its own evidence of conformity for a municipal water meter; it is treated as a complementary reference.
Defines a standard data model between devices and head-end systems. It is not present in the current Orion NB-IoT release; the Water Smart Meter Generic Companion Profile target is on the roadmap.
This section is not a legal declaration of conformity. Review by a regulatory and conformity specialist is required before publication; applicable requirements vary by target country and project.
RELEASE STATUS
Roadmap items are work not present in the current release. Preserving that distinction is critical for a buyer writing a technical specification.
Not a claim — the way of working that is applied.
Technical detail and verification records for these items are shared in the technical file.
These items are not present in the current release and are not a declaration of conformity.
The roadmap is not a binding delivery date or a declaration of current conformity. Final scope and timing are given in the product announcement.
Primary sources for the regulatory references on this page. Links go to official publications.
NEXT STEP
Let us validate the coverage, data, battery and integration assumptions together in a limited pilot. We write the success criteria before the pilot begins.