- Baseline source for the provisions assessed through ETSI TS 103 701-style evidence.
"Table B.1: Implementation of provisions for consumer IoT security"
Clear answers to common ETSI EN 303 645 questions for consumer IoT product, cloud, app, and evidence teams.
Based on ETSI EN 303 645 V3.1.3 and ETSI TS 103 701 V2.1.1. These ETSI documents are standards and assessment guidance, not legislation or a product certificate.
Structured answer sets in this page tree.
Cited legal and guidance references.
ETSI EN 303 645 V3.1.3 is an outcome-focused technical baseline for network-connected consumer IoT devices and their interactions with . It is a European Standard, not legislation or a certificate. Read each answer with the product model, software release, provision status, and any TS 103 701 assessment boundary in view.
These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.
ETSI EN 303 645 is used as a baseline for designing, documenting, procuring, and assessing consumer IoT security and data-protection controls. It targets widespread design weaknesses such as easily guessable passwords, weak update practices, missing vulnerability intake, exposed attack surfaces, insecure communications, unclear telemetry use, and poor user-data deletion.
The standard is not a complete answer to every IoT security risk. The source support text says it is not intended to solve all security challenges and does not focus on prolonged or sophisticated attacks or attacks requiring sustained physical access. Treat it as a baseline that product teams can supplement with product-specific risk assessment, threat modelling, sector rules, buyer requirements, and assurance schemes.
The standard applies to consumer IoT devices connected or connectable to network infrastructure, such as the Internet or a home network, and to their interactions with . Examples include connected toys, baby monitors, smoke detectors, locks, hubs, cameras, speakers, televisions, health trackers, home automation, alarms, appliances, and smart home assistants. Devices primarily intended for manufacturing, healthcare, or other industrial applications are outside the stated scope.
A scope decision must name the IoT product, not only the physical device. ETSI defines an IoT product as the consumer IoT device plus its . An associated service is a digital service that forms part of the overall product and is typically needed for the intended functionality. A preconfigured telemetry service can qualify; a website chosen in the device browser or an app installed from a store at the user's choice generally does not.
Where passwords authenticate users against the device or provide machine-to-machine authentication, provision 5.1-1 requires every device password outside factory default to be unique per device or defined by the user. Pre-installed unique passwords must also be generated by a mechanism that reduces automated attack risk. V3.1.3 recommends against passwords for machine-to-machine authentication and requires best-practice cryptography for authentication mechanisms.
Authentication evidence should cover setup, reset, every relevant interface, and each authentication mechanism. The device must let a user or administrator change the authentication value where a user can authenticate. It must also make successful brute-force attacks through network interfaces impracticable unless a resource constraint determined by the use case prevents the control.
ETSI EN 303 645 requires manufacturers to make a vulnerability disclosure policy publicly available. That policy should explain how security researchers and others can report issues, and the standard describes Coordinated Vulnerability Disclosure as the process set used to handle potential vulnerability disclosures and support remediation.
For software updates, the standard recommends that all software components be securely updateable. Provision 5.3-2 requires a secure update mechanism unless a resource constraint determined by the use case prevents implementation. The manufacturer must publish the defined security-update support period. For a device that cannot have its software updated, the manufacturer should also publish the reason and the period and method of hardware replacement support; the device should be isolable and its hardware replaceable.
ETSI EN 303 645 includes both security provisions for personal data and a separate data-protection section. It expects manufacturers to give consumers clear and transparent information about what personal data is processed, how it is used, by whom, and for what purposes, including third parties such as advertisers where they are involved.
Telemetry needs two checks. If telemetry is collected from consumer IoT devices and services, it should be examined for security anomalies. If telemetry includes personal data, the standard also says processing should be kept to the minimum necessary for the intended functionality and that consumers must be told what telemetry is collected, how it is used, by whom, and for what purposes.
Deletion should not be reduced to a vague factory-reset statement. Provision 5.11-1 requires a simple way to erase all user data from the device. The associated-service path is a recommendation: consumers should be able to delete personal data from through functionality on the device. Users should receive clear instructions and confirmation covering the device and associated services.
This FAQ helps turn consumer IoT scope, password, update, vulnerability disclosure, telemetry, deletion, and TS 103 701 evidence questions into owned work.
Convert ETSI EN 303 645 FAQ answers into accountable tasks, evidence requests, and assessment milestones.
Use cited ETSI source material to resolve scope, applicability, evidence, and version questions before implementation.
Review consumer IoT scope, evidence gaps, owners, and next compliance actions with Sorena.
ETSI TS 103 701 V2.1.1 is the compatible assessment methodology for EN 303 645 V3.1.3. The Supplier Organization identifies the Device Under Test, completes the Implementation Conformance Statement (ICS), and supplies the Implementation eXtra Information for Testing (IXIT). The Test Laboratory verifies the ICS, derives the test plan, performs the applicable test groups, and assigns test-case, test-group, and overall verdicts. The TS does not define a certification or conformance-declaration scheme.
A PASS is bounded by the identified DUT, the valid ICS, and the selected test groups; it is not a free-standing certificate for every product variant or associated service. Existing certificates or third-party evaluations can reduce testing only when the laboratory finds their scope, test activities, and assurance level adequate for the relevant test group.
"Table B.1: Implementation of provisions for consumer IoT security"
"The TL uses these documents to derive a test plan."