| Scope and covered activity | ETSI EN 303 645 V3.1.3 covers consumer IoT devices connected to network infrastructure and their interactions with associated services, which it defines as part of the overall consumer IoT product. | RED Article 3(3)(d) applies to internet-connected radio equipment. Point (e) applies to specified radio equipment capable of processing personal, traffic, or location data, including internet-connected equipment, childcare equipment, toys, and wearables. Point (f) applies to internet-connected radio equipment that enables transfers of money, monetary value, or virtual currency. The exclusions in Delegated Regulation (EU) 2022/30 must also be checked. | Start with two scope records: an ETSI consumer IoT boundary for control evidence and a separate RED radio-equipment boundary for legal and CE-file decisions. |
|---|
| Who must act | For an ETSI assessment, the supplier organization requests the DUT assessment, provides ICS and IXIT information, and coordinates across parties such as manufacturers, service providers, component suppliers, application developers, vendors, or distributors. | The RED manufacturer must design and manufacture compliant radio equipment, prepare technical documentation, perform the applicable conformity assessment, issue the EU declaration of conformity, and affix CE marking. Importers and distributors have separate verification and corrective-action duties. | Assign ETSI evidence owners for ICS, IXIT, and testing, then record the RED manufacturer, importer, and distributor roles for scope, conformity assessment, technical documentation, declaration, and CE marking. |
|---|
| Trigger or threshold | ETSI EN 303 645 applies when the team is assessing a consumer IoT device and its relevant interactions with associated services against the baseline provisions. Conditional ETSI provisions then depend on product facts such as whether passwords, update mechanisms, telemetry, consent-based personal-data processing, or hard-coded device identities exist. | The trigger depends on radio-equipment status and the Article 1 category tests, including internet connectivity, specified data processing, childcare, toy or wearable status, or transfer of money or monetary value. The requirements have applied since 1 August 2025. | Use an ETSI condition matrix for provisions and a separate RED trigger matrix for legal applicability. Do not infer RED applicability from the presence of an ETSI control. |
|---|
| Core obligations | ETSI EN 303 645 turns into product-security work: no universal default passwords, vulnerability disclosure, software updates, sensitive security parameter storage, secure communication, attack-surface reduction, software integrity, personal-data security, resilience, telemetry review, user-data deletion, secure usability, and input validation. | RED Article 3(3)(d) requires covered radio equipment not to harm the network or misuse network resources. Point (e) requires safeguards for personal data and privacy. Point (f) requires features that protect against fraud. EN 18031-1, -2, and -3 provide the cited harmonised-standard routes, subject to OJEU limitations. | Build the ETSI action list from clauses 5 and 6, then add RED duties in a separate cited column instead of renaming ETSI provisions as RED obligations. |
|---|
| Evidence and records | ETSI evidence should include the DUT identification, ICS support claims and details, IXIT entries, user documentation, conceptual and functional test results, verdict rationale, and any external evidence accepted for a provision. | RED technical documentation must support the applicable essential requirements and selected conformity route. The file should include the scope decision, risk and design evidence, applied EN 18031 clauses and limitations, test results, conformity-assessment output, EU declaration of conformity, and CE-marking basis. | Create a traceability matrix with source, product version, claim, ETSI artifact, RED artifact, owner, and gap status. Shared evidence should be tagged as supporting evidence, not proof that both regimes are complete. |
|---|
| Timing and cadence | ETSI timing is product-security timing: defined support period, timely vulnerability action, timely security updates, periodic update checks, reassessment after product or service changes, and assessment use of the most up-to-date DUT software. | The delegated RED cybersecurity requirements have applied since 1 August 2025. Product changes still need review under the manufacturer's continuing-conformity duties; the legislation does not set a fixed periodic recertification interval. | Maintain separate clocks: ETSI support and assessment timing for security operations, and RED legal timing for EU market-access decisions. |
|---|
| Enforcement or assurance route | ETSI EN 303 645 is a baseline standard. TS 103 701 can support first-party, second-party, third-party, certification, and conformance-declaration schemes, but defining a certification or conformance-declaration scheme is outside TS 103 701. | For Article 3(3) requirements, internal production control is available when the manufacturer correctly applies applicable harmonised standards whose references are published in the OJEU. If those standards are absent, not applied, or only partly applied, the RED requires EU-type examination plus internal production control or full quality assurance. Authorities can require corrective action or restrict, withdraw, or recall non-compliant equipment. | Use ETSI results as supporting assurance evidence only. Select the RED route from Article 17 and document how any EN 18031 limitation affects the claimed presumption of conformity. |
|---|
| Overlap and reuse | ETSI overlap exists at the control and evidence level: a well-scoped ETSI assessment can show implemented cybersecurity measures for the consumer IoT product. | RED overlap exists when an ETSI artifact supports the same product facts or security outcome required by the applicable EN 18031 part. EN 303 645 does not itself confer RED presumption of conformity, and the published EN 18031 limitations can leave additional work. | Reuse evidence by reference, not by renaming. Keep the ETSI result, RED requirement, common product facts, and remaining RED gaps visible in the same row. |
|---|
| Practical decision rule | Use ETSI EN 303 645 as the controlling source when the decision is about consumer IoT baseline controls, ICS/IXIT content, assessment evidence, or support for a product-security claim. | Use Delegated Regulation (EU) 2022/30 for the applicable radio-equipment categories, Implementing Decision (EU) 2025/138 for EN 18031 citation limits, and the RED for conformity assessment, technical documentation, declaration, CE marking, and market surveillance. | Use a bridge table with the ETSI evidence, applicable RED source, remaining gap, and responsible owner in separate fields. |
|---|