ETSI EN 303 645 Consumer IoT Security Guide
ETSI EN 303 645 is a voluntary, outcome-focused security and data-protection baseline for network-connected devices and their interactions with . It is not itself a law, certification scheme, or guarantee that a product is secure.
The provision guides use EN 303 645 V3.1.3 (2024-09), the latest edition listed in ETSI's EN 303 645 deliver directory when checked on 25 July 2026. TS 103 701 V2.1.1 (2025-05) names that edition as a normative reference. Neither document is legislation or a product certificate; a buyer, law, laboratory, or assurance scheme may specify another edition or add binding criteria.
Start with the product boundary and applicable provisions, then build implementation evidence. The guides keep the EN baseline separate from ETSI TS 103 701 assessment mechanics and from any law or assurance scheme that may use related evidence.
Choose the next consumer IoT security decision
New to the standard? Start with product scope. If the boundary is already documented, jump to the provision, implementation workflow, evidence pack, version check, or comparison you need.
Start here: product scope and applicability
Decide whether the product is consumer IoT, distinguish the physical device from its associated services, identify constrained-device facts, and record the assessment boundary.
Understand the provisions
Read the outcome-focused baseline before converting it into controls, including the password, update, vulnerability, data-protection, telemetry, and deletion provisions.
Implement product and process changes
Turn the applicable provisions into owned engineering, product-support, secure-update, and coordinated-vulnerability-disclosure work.
Prepare assessment evidence
Connect the exact device under test to implementation statements, IXIT detail, conceptual and functional checks, verdicts, and appropriately scoped external evidence.
Check versions, comparisons, and focused questions
Verify the edition being used, understand what evidence can transfer to legal regimes, and answer a specific product or assessment question without treating the standard as law or certification.
Turn ETSI EN 303 645 into an assessment-ready product workflow
This artifact is the shared starting point for scope, provision mapping, implementation evidence, and ETSI TS 103 701 assessment preparation.
- Identify the , , supplier responsibilities, interfaces, data flows, and software update mechanisms.
- Assign owners for each baseline provision area and collect the product records needed for and -style assessment inputs.
- Use Annex B status rules and product facts when deciding whether a provision is mandatory, recommended, conditional, feature-dependent, supported, unsupported, or eligible for N/A; Provision 5.0-1 still requires a recorded justification for every recommendation considered not applicable or not fulfilled.
- Keep conceptual design evidence, functional test evidence, external evidence decisions, and verdict rationale connected to the same product record.