ETSI EN 303 645Free Resource

ETSI EN 303 645 Consumer IoT Security Guide

ETSI EN 303 645 is a voluntary, outcome-focused security and data-protection baseline for network-connected devices and their interactions with . It is not itself a law, certification scheme, or guarantee that a product is secure.

Based on ETSI source materialConsumer IoT baselineNo signup required
Quick scan
Artifact
Requirements map
Trace the baseline provision areas and their legal force: passwords, vulnerability reports, updates, secure storage, communications, attack surface, software integrity, personal data, outages, telemetry, data deletion, setup, and input validation. Annex B marks provisions as mandatory or recommended and may also make them conditional or feature-dependent.
Implementation checklist
Turn each provision into product, firmware, cloud-service, mobile-app, support, and documentation work that can be reviewed before assessment.
TS 103 701 evidence workflow
Plan DUT scope, supplier organization records, test laboratory inputs, applicability statements, details, conceptual checks, functional checks, and verdict handling.

The provision guides use EN 303 645 V3.1.3 (2024-09), the latest edition listed in ETSI's EN 303 645 deliver directory when checked on 25 July 2026. TS 103 701 V2.1.1 (2025-05) names that edition as a normative reference. Neither document is legislation or a product certificate; a buyer, law, laboratory, or assurance scheme may specify another edition or add binding criteria.

Key dates
18
Topics
8
FAQs
3
Comparisons
2026
Updated
What this artifact helps decide
Which provisions apply
Confirm that the network-connected product is typically used by consumers in the home or as an electronic wearable, identify the device and its interactions with required , then document mandatory, recommended, conditional, and feature-dependent decisions. A business deployment of a consumer product can remain in scope; a product primarily intended for manufacturing, healthcare, or another industrial use is outside the standard's stated scope.
What evidence to collect
Prepare an Annex B implementation conformance statement for every provision, with Y, N, or permitted N/A status and concrete detail. For assessment, add TS 103 701 records that identify mechanisms, interfaces, documents, processes, and test inputs for the exact device model, software release, and associated-service boundary.
How assessment should run
The supplier organization identifies the and supplies the and ; the test laboratory verifies the claims, derives a product-specific test plan, performs conceptual and functional checks, and assigns test-case, test-group, and overall verdicts. The TS supplies a method, not a certification scheme.
Scope first
Plan controls
Track evidence
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 16, 2026

Start with the product boundary and applicable provisions, then build implementation evidence. The guides keep the EN baseline separate from ETSI TS 103 701 assessment mechanics and from any law or assurance scheme that may use related evidence.

Recommended reading path

Choose the next consumer IoT security decision

New to the standard? Start with product scope. If the boundary is already documented, jump to the provision, implementation workflow, evidence pack, version check, or comparison you need.

2

Understand the provisions

Read the outcome-focused baseline before converting it into controls, including the password, update, vulnerability, data-protection, telemetry, and deletion provisions.

3

Implement product and process changes

Turn the applicable provisions into owned engineering, product-support, secure-update, and coordinated-vulnerability-disclosure work.

4

Prepare assessment evidence

Connect the exact device under test to implementation statements, IXIT detail, conceptual and functional checks, verdicts, and appropriately scoped external evidence.

5

Check versions, comparisons, and focused questions

Verify the edition being used, understand what evidence can transfer to legal regimes, and answer a specific product or assessment question without treating the standard as law or certification.

Next step

Turn ETSI EN 303 645 into an assessment-ready product workflow

This artifact is the shared starting point for scope, provision mapping, implementation evidence, and ETSI TS 103 701 assessment preparation.

What this unlocks
  • Identify the , , supplier responsibilities, interfaces, data flows, and software update mechanisms.
  • Assign owners for each baseline provision area and collect the product records needed for and -style assessment inputs.
  • Use Annex B status rules and product facts when deciding whether a provision is mandatory, recommended, conditional, feature-dependent, supported, unsupported, or eligible for N/A; Provision 5.0-1 still requires a recorded justification for every recommendation considered not applicable or not fulfilled.
  • Keep conceptual design evidence, functional test evidence, external evidence decisions, and verdict rationale connected to the same product record.