---
title: "ETSI EN 303 645 Consumer IoT Security Guide"
canonical_url: "https://www.sorena.io/artifacts/global/etsi-en-303-645"
source_url: "https://www.sorena.io/artifacts/global/etsi-en-303-645"
author: "Sorena AI"
description: "Plain-language guide to the voluntary ETSI EN 303 645 consumer IoT security baseline, including scope, provisions, evidence, assessment, and claim limits."
published_at: "2026-03-04"
updated_at: "2026-07-16"
keywords:
  - "ETSI EN 303 645"
  - "ETSI EN 303 645 requirements"
  - "consumer IoT security standard"
  - "IoT security baseline requirements"
  - "vulnerability disclosure policy"
  - "coordinated vulnerability disclosure"
  - "secure software updates"
  - "secure firmware update mechanism"
  - "no universal default passwords"
  - "secure storage"
  - "secure communications"
  - "minimize attack surface"
  - "input validation"
  - "telemetry anomaly detection"
  - "support period"
  - "ETSI TS 103 701 conformance assessment"
  - "audit evidence mapping"
  - "Consumer IoT security"
  - "Secure update mechanism"
  - "ETSI TS 103 701"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# ETSI EN 303 645 Consumer IoT Security Guide

Plain-language guide to the voluntary ETSI EN 303 645 consumer IoT security baseline, including scope, provisions, evidence, assessment, and claim limits.

![ETSI EN 303 645 artifact preview](https://cdn.sorena.io/cdn-cgi/image/width=1200,quality=88,format=auto/images/3rd-parties/etsi.jpg)

*ETSI EN 303 645* *Free Resource*

## ETSI EN 303 645 Consumer IoT Security Guide

ETSI EN 303 645 is a voluntary, outcome-focused security and data-protection baseline for network-connected consumer IoT devices and their interactions with associated services. It is not itself a law, certification scheme, or guarantee that a product is secure.

Start with the product boundary and applicable provisions, then build implementation evidence. The guides keep the EN baseline separate from ETSI TS 103 701 assessment mechanics and from any law or assurance scheme that may use related evidence.

[Open the requirements map](/artifacts/global/etsi-en-303-645/requirements.md)

## What this artifact helps decide

- **Which provisions apply**: Confirm that the network-connected product is typically used by consumers in the home or as an electronic wearable, identify the device and its interactions with required associated services, then document mandatory, recommended, conditional, and feature-dependent decisions. A business deployment of a consumer product can remain in scope; a product primarily intended for manufacturing, healthcare, or another industrial use is outside the standard's stated scope.
- **What evidence to collect**: Prepare an Annex B implementation conformance statement for every provision, with Y, N, or permitted N/A status and concrete detail. For assessment, add TS 103 701 IXIT records that identify mechanisms, interfaces, documents, processes, and test inputs for the exact device model, software release, and associated-service boundary.
- **How assessment should run**: The supplier organization identifies the Device Under Test and supplies the ICS and IXIT; the test laboratory verifies the claims, derives a product-specific test plan, performs conceptual and functional checks, and assigns test-case, test-group, and overall verdicts. The TS supplies a method, not a certification scheme.

Based on ETSI source material | Consumer IoT baseline | No signup required

### Quick scan

*Artifact*

- **Requirements map**: Trace the baseline provision areas and their legal force: passwords, vulnerability reports, updates, secure storage, communications, attack surface, software integrity, personal data, outages, telemetry, data deletion, setup, and input validation. Annex B marks provisions as mandatory or recommended and may also make them conditional or feature-dependent.
- **Implementation checklist**: Turn each provision into product, firmware, cloud-service, mobile-app, support, and documentation work that can be reviewed before assessment.
- **TS 103 701 evidence workflow**: Plan DUT scope, supplier organization records, test laboratory inputs, ICS applicability statements, IXIT details, conceptual checks, functional checks, and verdict handling.

The provision guides use EN 303 645 V3.1.3 (2024-09), the latest edition listed in ETSI's EN 303 645 deliver directory when checked on 25 July 2026. TS 103 701 V2.1.1 (2025-05) names that edition as a normative reference. Neither document is legislation or a product certificate; a buyer, law, laboratory, or assurance scheme may specify another edition or add binding criteria.

| Value | Metric |
| --- | --- |
| 18 | Topics |
| 8 | FAQs |
| 3 | Comparisons |
| 2026 | Updated |

**Key highlights:** Scope first | Plan controls | Track evidence

## Definitions

### Consumer Internet of Things

**Term:** consumer IoT

Consumer IoT covers network-connected devices typically used by consumers, including connected home products and electronic wearables, together with the device interactions needed for their operation. Products primarily intended for industrial, manufacturing, or healthcare use are outside the stated scope.

**Why it matters here:** Scope is based on the product's typical use and network-connected functions. A consumer product used in a business setting can remain in scope, while a specialist industrial product does not enter scope merely because it uses similar technology.

Sources:

- [ETSI EN 303 645 V3.1.3, Scope and terms](https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf?ref=sorena.io)

### Associated services

Associated services are digital services that are required for the consumer IoT device's relevant functions, such as a required cloud service or mobile application. An unrelated third-party service that the device can access is not automatically part of this category.

**Why it matters here:** The product boundary must include the device's interactions with required associated services because several security and data-protection provisions apply across that boundary.

Sources:

- [ETSI EN 303 645 V3.1.3, Terms and Annex A](https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf?ref=sorena.io)

### Device Under Test

The Device Under Test is the specific consumer IoT product submitted for assessment, including the identified hardware, software, configuration, interfaces, and relevant associated-service boundary used for the test plan.

**Why it matters here:** Assessment evidence and verdicts apply to the recorded device and version boundary. Product, software, configuration, or service changes can require the supplier to update the evidence and reassess affected provisions.

Sources:

- [ETSI TS 103 701 V2.1.1, Clause 4.2.1](https://www.etsi.org/deliver/etsi_ts/103700_103799/103701/02.01.01_60/ts_103701v020101p.pdf?ref=sorena.io)

### Implementation Conformance Statement

**Term:** ICS

The ICS is the supplier's provision-by-provision statement of whether and how the product conforms to ETSI EN 303 645. It records applicability and implementation detail using the statuses permitted by the standard.

**Why it matters here:** The ICS is an input to assessment, not an independent certificate. The supplier must keep it aligned with the exact device model, software release, associated services, and supporting evidence.

Sources:

- [ETSI EN 303 645 V3.1.3, Annex B](https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf?ref=sorena.io)
- [ETSI TS 103 701 V2.1.1, Clause 4.4](https://www.etsi.org/deliver/etsi_ts/103700_103799/103701/02.01.01_60/ts_103701v020101p.pdf?ref=sorena.io)

### Implementation eXtra Information for Testing

**Term:** IXIT

The IXIT is the structured implementation detail supplied for testing. It identifies the mechanisms, interfaces, documents, processes, and other product-specific inputs the test laboratory needs to derive and perform the assessment.

**Why it matters here:** A provision-level claim in the ICS needs enough IXIT detail for conceptual and functional checks. Missing or stale IXIT information can block a defensible verdict even when the feature exists.

Sources:

- [ETSI TS 103 701 V2.1.1, Clause 4.5](https://www.etsi.org/deliver/etsi_ts/103700_103799/103701/02.01.01_60/ts_103701v020101p.pdf?ref=sorena.io)

## Primary sources

- [ETSI EN 303 645 V3.1.3 consumer IoT baseline requirements](https://www.etsi.org/deliver/etsi_en/303600_303699/303645/03.01.03_60/en_303645v030103p.pdf?ref=sorena.io) - Grounds this cluster's current detailed scope, terminology, outcome-focused provisions, data-protection provisions, Provision 5.0-1 reporting, and Annex B content.
- [ETSI EN 303 645 deliver directory](https://www.etsi.org/deliver/etsi_en/303600_303699/303645/?ref=sorena.io) - Official directory used on 25 July 2026 to confirm that 03.01.03_60 was the latest listed EN 303 645 edition.
- [ETSI TS 103 701 V2.1.1 conformance assessment methodology](https://www.etsi.org/deliver/etsi_ts/103700_103799/103701/02.01.01_60/ts_103701v020101p.pdf?ref=sorena.io) - Grounds the 2025 assessment roles, device-under-test boundary, ICS, IXIT, test-plan, verdict, external-evidence, scheme-limit, and version-alignment explanations.
- [ETSI milestones listing](https://www.etsi.org/milestones?ref=sorena.io) - Official status source identified in the EN 303 645 notice for checking whether an ETSI deliverable has been revised or had its status changed.
- [ETSI standards search](https://www.etsi.org/search-and-browse-standards?ref=sorena.io) - Primary ETSI discovery source for EN 303 645 and related consumer IoT cybersecurity deliverables.
- [ETSI intellectual property rights database](https://ipr.etsi.org/?ref=sorena.io) - Supports ETSI's notice that essential or potentially essential IPR information for normative deliverables is published through the ETSI IPR service.

*Recommended reading path*

## Choose the next consumer IoT security decision

New to the standard? Start with product scope. If the boundary is already documented, jump to the provision, implementation workflow, evidence pack, version check, or comparison you need.

### 1. Start here: product scope and applicability

Decide whether the product is consumer IoT, distinguish the physical device from its associated services, identify constrained-device facts, and record the assessment boundary.

1. [ETSI EN 303 645 Applicability and Scope](/artifacts/global/etsi-en-303-645/applicability-and-scope.md): Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
2. [ETSI EN 303 645 IoT Applicability Workflow](/artifacts/global/etsi-en-303-645/iot-applicability-workflow.md): Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.

### 2. Understand the provisions

Read the outcome-focused baseline before converting it into controls, including the password, update, vulnerability, data-protection, telemetry, and deletion provisions.

3. [ETSI EN 303 645 requirements: consumer IoT provision map](/artifacts/global/etsi-en-303-645/requirements.md): Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
4. [ETSI EN 303 645 Secure Updates and Vulnerability Disclosure](/artifacts/global/etsi-en-303-645/secure-update-and-vulnerability-disclosure.md): Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
5. [ETSI EN 303 645 Data Protection Provisions](/artifacts/global/etsi-en-303-645/data-protection-provisions.md): Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.

### 3. Implement product and process changes

Turn the applicable provisions into owned engineering, product-support, secure-update, and coordinated-vulnerability-disclosure work.

6. [ETSI EN 303 645 implementation checklist](/artifacts/global/etsi-en-303-645/implementation-checklist.md): This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
7. [ETSI EN 303 645 Secure Update Workflow](/artifacts/global/etsi-en-303-645/secure-update-workflow.md): Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
8. [ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports](/artifacts/global/etsi-en-303-645/vulnerability-disclosure-cvd-workflow.md): Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.

### 4. Prepare assessment evidence

Connect the exact device under test to implementation statements, IXIT detail, conceptual and functional checks, verdicts, and appropriately scoped external evidence.

9. [ETSI EN 303 645 compliance: ICS, IXIT, evidence](/artifacts/global/etsi-en-303-645/compliance.md): Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
10. [ETSI EN 303 645 ICS and IXIT Evidence Template](/artifacts/global/etsi-en-303-645/ics-and-ixit-evidence-template.md): Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
11. [ETSI EN 303 645 Implementation Evidence Guide](/artifacts/global/etsi-en-303-645/implementation-evidence.md): Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
12. [ETSI EN 303 645 Secure Update Evidence Workflow](/artifacts/global/etsi-en-303-645/secure-update-evidence-workflow.md): Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
13. [ETSI TS 103 701 Test Evidence Workflow for EN 303 645](/artifacts/global/etsi-en-303-645/ts-103-701-test-evidence-workflow.md): Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.

### 5. Check versions, comparisons, and focused questions

Verify the edition being used, understand what evidence can transfer to legal regimes, and answer a specific product or assessment question without treating the standard as law or certification.

14. [ETSI EN 303 645 Current Version Tracker](/artifacts/global/etsi-en-303-645/current-version-tracker.md): Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
15. [ETSI EN 303 645 vs EU CRA for Consumer IoT](/artifacts/global/etsi-en-303-645/etsi-en-303-645-vs-eu-cra.md): Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
16. [ETSI EN 303 645 vs RED Cybersecurity Delegated Act](/artifacts/global/etsi-en-303-645/etsi-en-303-645-vs-red-cybersecurity-delegated-act.md): Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
17. [ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk](/artifacts/global/etsi-en-303-645/etsi-en-303-645-vs-uk-psti.md): Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
18. [ETSI EN 303 645 FAQ: Consumer IoT Security Questions](/artifacts/global/etsi-en-303-645/faq.md): Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.

### 6. More guides

Additional guidance related to this artifact.

19. [ETSI EN 303 645 consumer IoT products: what is in scope?](/artifacts/global/etsi-en-303-645/faq/iot-consumer-products.md): Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
20. [ETSI EN 303 645 default passwords: what must consumer IoT teams do?](/artifacts/global/etsi-en-303-645/faq/default-passwords.md): ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
21. [ETSI EN 303 645 personal data deletion FAQ for consumer IoT](/artifacts/global/etsi-en-303-645/faq/personal-data-deletion.md): What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
22. [ETSI EN 303 645 support period: what must consumer IoT teams publish?](/artifacts/global/etsi-en-303-645/faq/support-period.md): ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
23. [ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?](/artifacts/global/etsi-en-303-645/faq/telemetry.md): ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
24. [ETSI EN 303 645 test evidence: what should consumer IoT teams keep?](/artifacts/global/etsi-en-303-645/faq/test-evidence.md): ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
25. [ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT](/artifacts/global/etsi-en-303-645/faq/vulnerability-disclosure.md): What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
26. [How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?](/artifacts/global/etsi-en-303-645/faq/constrained-devices.md): How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.

## Key milestones for ETSI EN 303 645

*Timeline*

ETSI publication dates are not compliance deadlines. Use the version tracker to record the edition used and check separately whether a law, contract, buyer, or assurance scheme makes a particular edition relevant.

*Next step*

## Turn ETSI EN 303 645 into an assessment-ready product workflow

This artifact is the shared starting point for consumer IoT scope, provision mapping, implementation evidence, and ETSI TS 103 701 assessment preparation.

- Identify the device under test, associated services, supplier responsibilities, interfaces, data flows, and software update mechanisms.
- Assign owners for each baseline provision area and collect the product records needed for ICS and IXIT-style assessment inputs.
- Use Annex B status rules and product facts when deciding whether a provision is mandatory, recommended, conditional, feature-dependent, supported, unsupported, or eligible for N/A; Provision 5.0-1 still requires a recorded justification for every recommendation considered not applicable or not fulfilled.
- Keep conceptual design evidence, functional test evidence, external evidence decisions, and verdict rationale connected to the same product record.

- [Open Assessment Autopilot](/solutions/assessment.md): Turn ETSI EN 303 645 provision mapping into owned tasks, evidence requests, review checkpoints, and assessment records.
- [Open Research Copilot](/solutions/research-copilot.md): Answer device scope, applicability, version, and interpretation questions with cited outputs from the same artifact.
- [Talk through implementation](/contact.md): Review your consumer IoT product scope, evidence model, assessment path, and next implementation steps.


---

[Privacy Policy](https://www.sorena.io/privacy.md) | [Terms of Use](https://www.sorena.io/terms-of-use.md) | [DMCA](https://www.sorena.io/dmca.md) | [About Us](https://www.sorena.io/about-us.md)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/global/etsi-en-303-645.md
