- Grounds the workflow requirement to keep the relied-upon ETSI deliverable PDF and checked source URL visible.
"ETSI deliver"
A practical tracker for recording which ETSI EN 303 645 and ETSI TS 103 701 versions support a consumer IoT security claim.
Based on ETSI deliverables and status-check links. Use it as implementation guidance, not for legal interpretation.
Structured answer sets in this page tree.
Cited legal and guidance references.
ETSI's deliver directory listed V3.1.3 (2024-09) as the latest EN edition when checked on 25 July 2026. The TS 103 701 directory listed V2.1.1 (2025-05), and that assessment edition names EN 303 645 V3.1.3 as a normative reference. Record the baseline, assessment method, product release, status-check date, and selecting authority separately.
The baseline used throughout this artifact is V3.1.3 (2024-09), Cyber Security for Consumer Internet of Things: Baseline Requirements. ETSI's directory contained no later EN edition when checked on 25 July 2026. The change history says V3.1.1 was published as TS 103 645 in January 2024 as a revision to improve applicability and testability; V3.1.3 is the September 2024 EN publication.
The assessment source is ETSI TS 103 701 V2.1.1 (2025-05), Cyber Security for Consumer Internet of Things: Conformance Assessment of Baseline Requirements. Its normative references identify ETSI TS 103 645 V3.1.1 and V3.1.3. This alignment does not decide which edition or assessment scheme a particular buyer, law, or laboratory requires.
ETSI states that electronic or print versions can differ and that the prevailing ETSI deliverable is the PDF made publicly available through the ETSI deliver repository. The EN 303 645 notice points to the ETSI milestones listing for revisions or status changes.
For a public product claim or customer answer, show both the PDF version used and the independent status check. If the milestones listing, Search and Browse Standards, or deliver repository points to a newer or changed deliverable, update the evidence pack before repeating an older claim.
This tracker helps keep standards versions, assessment methods, product boundaries, and public claims aligned before customer or assessor review.
Convert version checks into accountable tasks, evidence requests, and review milestones.
Use cited ETSI source material to resolve version, scope, applicability, and evidence questions before implementation.
Review standards versions, product boundaries, evidence owners, and the next compliance actions with Sorena.
Tie each standard version to the product or assessment boundary that depends on it. ETSI TS 103 701 frames the assessment around a Device Under Test, a Supplier Organization, a Test Laboratory, an ICS, an IXIT, and test groups that support assessment against ETSI TS 103 645 or .
For each product release or assessment pack, record the baseline requirement version, the assessment-method version, the DUT boundary, associated services, user documentation, evidence owner, and the specific public claim that will be made. That makes it clear when an updated ETSI deliverable or a product change requires a review.
Refresh the tracker when the source version changes, when ETSI status information changes, or when the product boundary no longer matches the evidence. EN 303 645 notes that software update management can involve associated service updates, device updates, and other service updates, and that transparency about update support is beneficial to consumers.
Refresh the tracker when the assessment method changes. TS 103 701 notes that ETSI TS 103 645 can be updated before and that the assessment document scope lists compatible versions. Record version alignment as part of the evidence.
This workflow is a markdown-readable operating table in planning documents: Step | Owner | Evidence | Decision.
1 | Standards owner | PDF version and status-check record | Which baseline requirements version supports the claim?
2 | Assessment owner | ETSI TS 103 701 PDF version and compatibility note | Which assessment method version will be used?
3 | Product owner | DUT, associated services, firmware, app, and support-period scope | Does the evidence boundary match the shipped product?
4 | Evidence owner | ICS, IXIT, conceptual tests, functional tests, external evidence, and exceptions | Can the claim be repeated without unsupported assumptions?
5 | Release owner | Change log and next review date | Should the public claim stay, narrow, or be refreshed?
Do not overstate the evidence. A PDF publication date does not prove today's current status, and a completed checklist does not prove conformance if it omits the product boundary, assessment method, or changed associated services.
Keep EN 303 645 baseline versions separate from TS 103 701 assessment versions. Mixing them in one row can hide an incompatible or stale assessment.
"ETSI deliver"
"may be revised or have its status changed"
"may be revised or have its status changed"
"Search Standards"
"Conceptual: Assessing conformity of the IXIT"