- Supports product scope, baseline limitations, provision-specific resource-constraint reasoning, and implementation conformance statement expectations.
"sets a security and data protection baseline"
Decide whether a connected product is a consumer IoT device under ETSI EN 303 645, then define the evidence boundary before making assurance claims.
Based on ETSI EN 303 645 V3.1.3 and ETSI TS 103 701 V2.1.1. Use it as implementation guidance, not for legal interpretation.
Structured answer sets in this page tree.
Cited legal and guidance references.
Use four branches to decide scope. First, determine whether the product is a . Second, identify the physical device and the associated services typically required for its intended functionality. Third, test each provision's mandatory, recommended, conditional, or feature-dependent status against the product facts. Fourth, record the Device Under Test, support decision, evidence, and reassessment triggers before making a claim.
ETSI EN 303 645 applies to consumer IoT devices connected to network infrastructure, such as the Internet or a home network, and to their interactions with associated services. The standard gives examples such as connected children's toys and baby monitors, smoke detectors, door locks, window sensors, gateways, smart cameras, smart TVs, speakers, wearable health trackers, home automation and alarm systems, connected appliances, and smart home assistants.
Decide whether the product is a , which associated services are part of the overall IoT product, and whether any security claim depends on companion apps, cloud services, APIs, telemetry services, gateways, hubs, or support processes. Having software alone does not put a product in scope.
EN 303 645 defines associated services as digital services that, together with the device, form part of the overall consumer IoT product and are typically required for intended functionality. Examples include mobile applications, cloud computing or storage, third-party APIs, and a manufacturer-chosen telemetry service.
EN 303 645 V3.1.3 defines associated services as part of the overall consumer IoT product and applies its provisions to the device and its interactions with those services. For practical evidence work, this means a team should not ignore a service that is required for authentication, updates, telemetry, remote access, deletion, user information, or vulnerability handling.
EN 303 645 recognizes that applicability depends on the device. Provision 5.0-1 requires a recorded justification for each recommendation considered not applicable or not fulfilled. Annex B separately limits an N/A support entry to a conditional provision whose condition is not satisfied or a provision tied to a feature, capability, or mechanism that does not exist.
The standard gives examples such as resource constraints, a missing function, or an additional industry or regulatory requirement that precludes a provision. A statement such as "not relevant to our architecture" is not enough: identify the condition or feature, the product facts, and the supporting evidence.
ETSI TS 103 701 is a conformance assessment methodology for consumer IoT devices, their relation to associated services, and corresponding relevant processes against ETSI EN 303 645. It can be used in first-, second-, or third-party assessment and within certification or conformance-declaration schemes, but it does not define a scheme.
For scope work, the key assessment artifacts are the Device Under Test identification, the Implementation Conformance Statement, and the Implementation eXtra Information for Testing. TS 103 701 says the supplier organization provides ICS and IXIT to the test laboratory, and the test laboratory uses them to derive a test plan.
This ETSI EN 303 645 guidance helps turn scope, associated-service boundaries, provision-specific resource constraints, ICS, and IXIT evidence into assigned review work.
Convert applicability and scope decisions into accountable tasks, evidence requests, and review milestones.
Use cited source material to resolve scope, applicability, evidence, and comparison questions before implementation.
Review scope, evidence, owners, and the next compliance actions with Sorena.
Before a public page, procurement response, or assessment package says that a product follows ETSI EN 303 645, make the scope statement specific enough to test. The standard is a baseline for consumer IoT, while TS 103 701 test cases are generic and expect competent bodies to derive a suitable test plan.
The scope record should stand alone: a reviewer should be able to identify the device, associated services, relevant processes, provisions claimed Yes or N/A, and the evidence location without relying on tribal knowledge.
"sets a security and data protection baseline"
"Search Standards"
"derive a suitable test plan"