ComparisonGLOBALETSI EN 303 645

ETSI EN 303 645 vs RED Cybersecurity Delegated Act

Use ETSI EN 303 645 to structure consumer IoT security controls and evidence, then keep a separate RED analysis for radio-equipment legal scope, CE documentation, and EU market-access decisions.

The RED cybersecurity requirements have applied since 1 August 2025. EN 18031-1, -2, and -3 are the cited harmonised standards, subject to published limitations; EN 303 645 is not their substitute.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 303 645 V3.1.3 and the can apply to the same connected consumer product, but they are not equivalent. EN 303 645 is a voluntary consumer IoT baseline. Delegated Regulation (EU) 2022/30 activates binding RED Article 3(3)(d), (e), and (f) cybersecurity requirements for specified radio-equipment categories from 1 August 2025. Reuse EN 303 645 and TS 103 701 evidence for matching controls, then complete a separate RED scope decision, EN 18031 mapping, technical documentation, conformity assessment, EU declaration of conformity, and CE-marking record.

Side-by-side comparison

ETSI EN 303 645 vs RED Cybersecurity Delegated Act: evidence boundary

A narrow comparison for connected-product teams deciding what ETSI EN 303 645 can prove, what RED must prove separately, and when evidence can be bridged without overclaiming.

Review all sources
First framework
ETSI EN 303 645

A consumer IoT cybersecurity baseline for network-connected consumer devices and their interactions with associated services, with TS 103 701 providing an assessment method.

Second framework
RED Cybersecurity Delegated Act

Binding RED cybersecurity requirements for specified radio equipment, supported by the EN 18031 harmonised standards and the RED conformity-assessment framework.

Comparison row 1

Scope and covered activity

ETSI EN 303 645

ETSI EN 303 645 V3.1.3 covers consumer IoT devices connected to network infrastructure and their interactions with associated services, which it defines as part of the overall consumer IoT product.

RED Cybersecurity Delegated Act

RED Article 3(3)(d) applies to internet-connected radio equipment. Point (e) applies to specified radio equipment capable of processing personal, traffic, or location data, including internet-connected equipment, childcare equipment, toys, and wearables. Point (f) applies to internet-connected radio equipment that enables transfers of money, monetary value, or virtual currency. The exclusions in Delegated Regulation (EU) 2022/30 must also be checked.

Operational implication

Start with two scope records: an ETSI consumer IoT boundary for control evidence and a separate RED radio-equipment boundary for legal and CE-file decisions.

Comparison row 2

Who must act

ETSI EN 303 645

For an ETSI assessment, the supplier organization requests the DUT assessment, provides ICS and IXIT information, and coordinates across parties such as manufacturers, service providers, component suppliers, application developers, vendors, or distributors.

RED Cybersecurity Delegated Act

The RED manufacturer must design and manufacture compliant radio equipment, prepare technical documentation, perform the applicable conformity assessment, issue the EU declaration of conformity, and affix CE marking. Importers and distributors have separate verification and corrective-action duties.

Operational implication

Assign ETSI evidence owners for ICS, IXIT, and testing, then record the RED manufacturer, importer, and distributor roles for scope, conformity assessment, technical documentation, declaration, and CE marking.

Comparison row 3

Trigger or threshold

ETSI EN 303 645

ETSI EN 303 645 applies when the team is assessing a consumer IoT device and its relevant interactions with associated services against the baseline provisions. Conditional ETSI provisions then depend on product facts such as whether passwords, update mechanisms, telemetry, consent-based personal-data processing, or hard-coded device identities exist.

RED Cybersecurity Delegated Act

The trigger depends on radio-equipment status and the Article 1 category tests, including internet connectivity, specified data processing, childcare, toy or wearable status, or transfer of money or monetary value. The requirements have applied since 1 August 2025.

Operational implication

Use an ETSI condition matrix for provisions and a separate RED trigger matrix for legal applicability. Do not infer RED applicability from the presence of an ETSI control.

Comparison row 4

Core obligations

ETSI EN 303 645

ETSI EN 303 645 turns into product-security work: no universal default passwords, vulnerability disclosure, software updates, sensitive security parameter storage, secure communication, attack-surface reduction, software integrity, personal-data security, resilience, telemetry review, user-data deletion, secure usability, and input validation.

RED Cybersecurity Delegated Act

RED Article 3(3)(d) requires covered radio equipment not to harm the network or misuse network resources. Point (e) requires safeguards for personal data and privacy. Point (f) requires features that protect against fraud. EN 18031-1, -2, and -3 provide the cited harmonised-standard routes, subject to OJEU limitations.

Operational implication

Build the ETSI action list from clauses 5 and 6, then add RED duties in a separate cited column instead of renaming ETSI provisions as RED obligations.

Comparison row 5

Evidence and records

ETSI EN 303 645

ETSI evidence should include the DUT identification, ICS support claims and details, IXIT entries, user documentation, conceptual and functional test results, verdict rationale, and any external evidence accepted for a provision.

RED Cybersecurity Delegated Act

RED technical documentation must support the applicable essential requirements and selected conformity route. The file should include the scope decision, risk and design evidence, applied EN 18031 clauses and limitations, test results, conformity-assessment output, EU declaration of conformity, and CE-marking basis.

Operational implication

Create a traceability matrix with source, product version, claim, ETSI artifact, RED artifact, owner, and gap status. Shared evidence should be tagged as supporting evidence, not proof that both regimes are complete.

Comparison row 6

Timing and cadence

ETSI EN 303 645

ETSI timing is product-security timing: defined support period, timely vulnerability action, timely security updates, periodic update checks, reassessment after product or service changes, and assessment use of the most up-to-date DUT software.

RED Cybersecurity Delegated Act

The delegated RED cybersecurity requirements have applied since 1 August 2025. Product changes still need review under the manufacturer's continuing-conformity duties; the legislation does not set a fixed periodic recertification interval.

Operational implication

Maintain separate clocks: ETSI support and assessment timing for security operations, and RED legal timing for EU market-access decisions.

Comparison row 7

Enforcement or assurance route

ETSI EN 303 645

ETSI EN 303 645 is a baseline standard. TS 103 701 can support first-party, second-party, third-party, certification, and conformance-declaration schemes, but defining a certification or conformance-declaration scheme is outside TS 103 701.

RED Cybersecurity Delegated Act

For Article 3(3) requirements, internal production control is available when the manufacturer correctly applies applicable harmonised standards whose references are published in the OJEU. If those standards are absent, not applied, or only partly applied, the RED requires EU-type examination plus internal production control or full quality assurance. Authorities can require corrective action or restrict, withdraw, or recall non-compliant equipment.

Operational implication

Use ETSI results as supporting assurance evidence only. Select the RED route from Article 17 and document how any EN 18031 limitation affects the claimed presumption of conformity.

Comparison row 8

Overlap and reuse

ETSI EN 303 645

ETSI overlap exists at the control and evidence level: a well-scoped ETSI assessment can show implemented cybersecurity measures for the consumer IoT product.

RED Cybersecurity Delegated Act

RED overlap exists when an ETSI artifact supports the same product facts or security outcome required by the applicable EN 18031 part. EN 303 645 does not itself confer RED presumption of conformity, and the published EN 18031 limitations can leave additional work.

Operational implication

Reuse evidence by reference, not by renaming. Keep the ETSI result, RED requirement, common product facts, and remaining RED gaps visible in the same row.

Comparison row 9

Practical decision rule

ETSI EN 303 645

Use ETSI EN 303 645 as the controlling source when the decision is about consumer IoT baseline controls, ICS/IXIT content, assessment evidence, or support for a product-security claim.

RED Cybersecurity Delegated Act

Use Delegated Regulation (EU) 2022/30 for the applicable radio-equipment categories, Implementing Decision (EU) 2025/138 for EN 18031 citation limits, and the RED for conformity assessment, technical documentation, declaration, CE marking, and market surveillance.

Operational implication

Use a bridge table with the ETSI evidence, applicable RED source, remaining gap, and responsible owner in separate fields.

Practical decision rule

How to choose the controlling source

  • Choose ETSI EN 303 645 when the question is whether a consumer IoT control is implemented, documented, tested, or supported in the ICS/IXIT evidence.
  • Choose RED and Delegated Regulation (EU) 2022/30 when the question is whether radio equipment meets EU cybersecurity, conformity-assessment, technical-documentation, CE-marking, or market-access requirements.
  • Use both only through a bridge table that keeps ETSI control evidence and RED legal conclusions separate.
Section 1

What ETSI EN 303 645 can and cannot answer

ETSI EN 303 645 V3.1.3 is a consumer IoT cybersecurity baseline. It is written for network-connected consumer IoT devices and their interactions with associated services, which it defines as part of the overall consumer IoT product.

That makes it useful for product-security evidence: passwords, vulnerability reporting, secure updates, secure storage of sensitive security parameters, secure communication, attack-surface minimization, software integrity, personal-data security, resilience, telemetry review, user-data deletion, installation and maintenance usability, input validation, and data-protection transparency. It does not decide whether a product is radio equipment, which RED Article 3(3) requirements apply, whether a cited EN 18031 limitation affects the product, or which conformity-assessment route is available.

  • Use ETSI EN 303 645 when the question is about consumer IoT security controls and implementation evidence.
  • Use RED and Delegated Regulation (EU) 2022/30 for radio-equipment scope and legal obligations, and the current OJEU harmonised-standards decision for the EN 18031 presumption-of-conformity conditions.
  • Treat ETSI-to-RED reuse as supporting evidence. The RED file must still identify the applicable Article 3(3) point, conformity route, technical documentation, EU declaration of conformity, and CE-marking record.
Section 2

Evidence boundary for a comparison

Start the ETSI side with the consumer IoT product boundary: the device, firmware, network interfaces, user interfaces, update mechanism, telemetry, personal-data processing, user-data deletion functions, user instructions, and the interactions with associated services that are necessary to provide the product's intended functionality.

TS 103 701 assesses a specific Device Under Test. The supplier organization provides the ICS and IXIT, and the test laboratory uses those documents to derive a test plan. That evidence model is more precise than a general policy checklist and is the right unit for any later RED bridge.

  • Identify the DUT and its most up-to-date software version before mapping controls.
  • Separate on-device functionality from associated-service interactions so the comparison does not overclaim the ETSI scope.
  • Keep ICS support claims, IXIT details, user documentation, and test results linked to the same product configuration.
Section 3

Where evidence reuse is strongest - and what RED still needs

Evidence reuse is strongest where the RED workstream needs proof of actual cybersecurity controls in a connected consumer product and the ETSI evidence is tied to the same shipped configuration. Examples include removal of universal default passwords, vulnerability disclosure handling, secure software updates, secure communication, secure handling of sensitive security parameters, telemetry anomaly review, user-data deletion, and input validation.

Reuse should be documented as a bridge, not a substitution. The RED harmonised standards are EN 18031-1:2024 for internet-connected radio equipment, EN 18031-2:2024 for radio equipment processing specified data, and EN 18031-3:2024 for internet-connected radio equipment that enables transfers of money or monetary value. Their OJEU citations carry limitations, so the manufacturer must check the applicable notice as well as the standard.

  • Reuse ETSI records only when the product version, software, interfaces, associated services, and user-facing information match the RED evidence boundary.
  • Carry over the actual ETSI artifacts: ICS rows, IXIT entries, conceptual-test conclusions, functional-test results, and external-evidence references.
  • Add a RED bridge note that names Article 3(3)(d), (e), or (f), the applicable EN 18031 clauses and OJEU limitations, the evidence reused, and what remains outside the ETSI assessment.
Section 4

How to document unsupported or non-applicable items

ETSI EN 303 645 includes an Implementation Conformance Statement pro forma. The support column can mark provisions as supported, not supported, or not applicable. The detail column is where the team records implemented measures, reasons a provision is not supported, or the rationale for a not-applicable decision.

TS 103 701 makes those entries assessable. It requires the supplier organization to complete the ICS correctly, provide IXIT information for provisions claimed as supported, and justify N/A or not-supported positions so the test laboratory can verify the claim and assign reproducible verdicts.

  • Do not write a bare N/A for an ETSI provision; include the condition or feature reason that makes it not applicable.
  • Do not mark a mandatory provision unsupported and still describe the product as conforming without explaining the failed claim.
  • Mark the RED row unresolved when the product category, applicable Article 3(3) point, EN 18031 coverage, or conformity route has not been established.
Section 5

Implementation checklist for the ETSI-to-RED bridge

Use this checklist to carry ETSI EN 303 645 work into a RED cybersecurity file. Produce a traceable bridge rather than merging the two instruments into one checklist.

  • Confirm the product is a consumer IoT device for the ETSI side and record any associated services needed for intended functionality.
  • Identify the DUT, software version, user documentation, network interfaces, user interfaces, update paths, telemetry, data deletion functions, and personal-data processing.
  • Complete or reference the ICS and IXIT entries for each claimed ETSI provision.
  • Attach conceptual and functional test evidence, including the test plan basis and verdicts where TS 103 701 assessment has been performed.
  • Create a separate RED column stating the applicable Article 3(3) point, EN 18031 part and limitation, conformity route, reused ETSI evidence, and remaining RED evidence.
Section 6

Common mistakes to avoid

EN 303 645 is not one of the RED cybersecurity harmonised standards cited by Implementing Decision (EU) 2025/138. A team may have useful ETSI evidence but still lack the RED scope decision, applicable EN 18031 coverage, conformity assessment, technical documentation, declaration, or CE-marking analysis.

Keep every ETSI artifact tied to the product version, support-period information, associated-service dependencies, ICS status, IXIT detail, test method, verdict, and external evidence.

  • Do not present ETSI EN 303 645 as a RED legal requirement or as the harmonised-standard route for Article 3(3)(d), (e), or (f).
  • Do not reuse ETSI evidence for a product variant, firmware version, app, cloud service, or data-processing flow that was not inside the assessed boundary.
  • Do not hide conditional or unsupported provisions in narrative text; put the rationale in the ICS detail or bridge record.
  • Do not cite private reference labels, screenshots, or unpublished working notes as public sources.
Primary sources

References and citations

Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.