Artifact GuideGLOBALETSI EN 303 645

ETSI EN 303 645 Frequently Asked Questions

Clear answers to common ETSI EN 303 645 questions for consumer IoT product, cloud, app, and evidence teams.

Based on ETSI EN 303 645 V3.1.3 and ETSI TS 103 701 V2.1.1. These ETSI documents are standards and assessment guidance, not legislation or a product certificate.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
FAQ modules
8

Structured answer sets in this page tree.

Primary sources
2

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 303 645 V3.1.3 is an outcome-focused technical baseline for network-connected consumer IoT devices and their interactions with . It is a European Standard, not legislation or a certificate. Read each answer with the product model, software release, provision status, and any TS 103 701 assessment boundary in view.

Browse sub-FAQs

Choose the question set you need

These focused FAQ modules break this artifact into narrower answer sets so teams can move straight to the right source-backed guidance.

Browse all FAQ items24
Focused FAQ modules
8
Showing 8 of 8
FAQ module

ETSI EN 303 645 consumer IoT products: what is in scope?

Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.

3 items
FAQ module

ETSI EN 303 645 default passwords: what must consumer IoT teams do?

ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.

3 items
FAQ module

ETSI EN 303 645 personal data deletion FAQ for consumer IoT

What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.

3 items
FAQ module

ETSI EN 303 645 support period: what must consumer IoT teams publish?

ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.

3 items
FAQ module

ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?

ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.

3 items
FAQ module

ETSI EN 303 645 test evidence: what should consumer IoT teams keep?

ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.

3 items
FAQ module

ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT

What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.

3 items
FAQ module

How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?

How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.

3 items
Question 1

What is ETSI EN 303 645 used for?

ETSI EN 303 645 is used as a baseline for designing, documenting, procuring, and assessing consumer IoT security and data-protection controls. It targets widespread design weaknesses such as easily guessable passwords, weak update practices, missing vulnerability intake, exposed attack surfaces, insecure communications, unclear telemetry use, and poor user-data deletion.

The standard is not a complete answer to every IoT security risk. The source support text says it is not intended to solve all security challenges and does not focus on prolonged or sophisticated attacks or attacks requiring sustained physical access. Treat it as a baseline that product teams can supplement with product-specific risk assessment, threat modelling, sector rules, buyer requirements, and assurance schemes.

  • Use it to define baseline consumer IoT security expectations before release.
  • Use it to organize evidence for passwords, updates, vulnerability disclosure, secure communication, personal data, telemetry, deletion, installation, and input validation.
  • Do not present it as a complete legal, privacy, product-safety, or high-assurance security certification by itself.
  • Name the ETSI deliverable version used before making public claims.
Question 2

Which products are in scope of ETSI EN 303 645?

The standard applies to consumer IoT devices connected or connectable to network infrastructure, such as the Internet or a home network, and to their interactions with . Examples include connected toys, baby monitors, smoke detectors, locks, hubs, cameras, speakers, televisions, health trackers, home automation, alarms, appliances, and smart home assistants. Devices primarily intended for manufacturing, healthcare, or other industrial applications are outside the stated scope.

A scope decision must name the IoT product, not only the physical device. ETSI defines an IoT product as the consumer IoT device plus its . An associated service is a digital service that forms part of the overall product and is typically needed for the intended functionality. A preconfigured telemetry service can qualify; a website chosen in the device browser or an app installed from a store at the user's choice generally does not.

  • Include companion apps, manufacturer cloud services, telemetry services, and required setup services when they are part of the product's intended functionality.
  • Do not automatically include user-chosen third-party apps or websites that are not required by the manufacturer for the product to work.
  • Record any use-case resource constraint only against the provision it affects; V3.1.3 does not create a blanket constrained-device exemption.
  • Treat a smart television or home security kit as consumer IoT when its product design is typically for consumer use, even if a business deploys it. Treat a device primarily intended for manufacturing, healthcare, or another industrial application as outside the EN's stated scope.
  • Provision 5.0-1 requires a recorded justification for every recommendation considered not applicable or not fulfilled.
Question 3

What does ETSI EN 303 645 say about default passwords and authentication?

Where passwords authenticate users against the device or provide machine-to-machine authentication, provision 5.1-1 requires every device password outside factory default to be unique per device or defined by the user. Pre-installed unique passwords must also be generated by a mechanism that reduces automated attack risk. V3.1.3 recommends against passwords for machine-to-machine authentication and requires best-practice cryptography for authentication mechanisms.

Authentication evidence should cover setup, reset, every relevant interface, and each authentication mechanism. The device must let a user or administrator change the authentication value where a user can authenticate. It must also make successful brute-force attacks through network interfaces impracticable unless a resource constraint determined by the use case prevents the control.

  • Record whether passwords exist on device interfaces, apps, web interfaces, APIs, and .
  • Show that non-factory-default passwords are user-defined or unique per device when passwords are used.
  • Include brute-force mitigation evidence for network-accessible authentication mechanisms, or document the use-case resource constraint that prevents it.
  • Avoid broad claims such as "no default passwords" unless the claim covers every relevant state and interface.
Question 4

What are the key vulnerability disclosure and software update expectations?

ETSI EN 303 645 requires manufacturers to make a vulnerability disclosure policy publicly available. That policy should explain how security researchers and others can report issues, and the standard describes Coordinated Vulnerability Disclosure as the process set used to handle potential vulnerability disclosures and support remediation.

For software updates, the standard recommends that all software components be securely updateable. Provision 5.3-2 requires a secure update mechanism unless a resource constraint determined by the use case prevents implementation. The manufacturer must publish the defined security-update support period. For a device that cannot have its software updated, the manufacturer should also publish the reason and the period and method of hardware replacement support; the device should be isolable and its hardware replaceable.

  • Publish a vulnerability disclosure policy before relying on EN 303 645 as a release or procurement claim.
  • Keep an intake, triage, remediation, and communication record for reported vulnerabilities.
  • Document the update mechanism, including how update authenticity and integrity are checked.
  • For devices that cannot be patched, publish the rationale and hardware-replacement support information, and document how the device can be isolated and replaced.
Question 5

How should teams handle personal data, telemetry, and deletion questions?

ETSI EN 303 645 includes both security provisions for personal data and a separate data-protection section. It expects manufacturers to give consumers clear and transparent information about what personal data is processed, how it is used, by whom, and for what purposes, including third parties such as advertisers where they are involved.

Telemetry needs two checks. If telemetry is collected from consumer IoT devices and services, it should be examined for security anomalies. If telemetry includes personal data, the standard also says processing should be kept to the minimum necessary for the intended functionality and that consumers must be told what telemetry is collected, how it is used, by whom, and for what purposes.

Deletion should not be reduced to a vague factory-reset statement. Provision 5.11-1 requires a simple way to erase all user data from the device. The associated-service path is a recommendation: consumers should be able to delete personal data from through functionality on the device. Users should receive clear instructions and confirmation covering the device and associated services.

  • Inventory personal data by device, app, associated service, third party, purpose, retention period, protection mechanism, and deletion path.
  • Separate telemetry collected for security anomaly detection from telemetry collected only for product performance or analytics.
  • Confirm whether deletion works for transfer of ownership, service removal, device disposal, and multi-user scenarios.
  • Explain deletion from , not only from local device storage.
Question 6

What evidence does ETSI TS 103 701 add to an ETSI EN 303 645 FAQ?

ETSI TS 103 701 V2.1.1 is the compatible assessment methodology for EN 303 645 V3.1.3. The Supplier Organization identifies the Device Under Test, completes the Implementation Conformance Statement (ICS), and supplies the Implementation eXtra Information for Testing (IXIT). The Test Laboratory verifies the ICS, derives the test plan, performs the applicable test groups, and assigns test-case, test-group, and overall verdicts. The TS does not define a certification or conformance-declaration scheme.

A PASS is bounded by the identified DUT, the valid ICS, and the selected test groups; it is not a free-standing certificate for every product variant or associated service. Existing certificates or third-party evaluations can reduce testing only when the laboratory finds their scope, test activities, and assurance level adequate for the relevant test group.

  • Identify the DUT before answering scope or evidence questions.
  • Maintain ICS-style statements for which provisions apply and how they are implemented.
  • Maintain IXIT-style details for authentication mechanisms, update mechanisms, secure communication, personal data, telemetry, deletion functions, interfaces, and input validation.
  • Keep external evidence tied to the provision and product version so it can support an assessment without drifting into generic compliance language.
Primary sources

References and citations

Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.