Artifact GuideGLOBALETSI EN 303 645

ETSI EN 303 645 Default passwords for consumer IoT products

A focused answer on what ETSI EN 303 645 provision 5.1 expects when consumer IoT products use passwords or other authentication values.

Based on ETSI EN 303 645 V3.1.3 and the compatible ETSI TS 103 701 V2.1.1 assessment method.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
9

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Where passwords authenticate users against the device or provide , ETSI EN 303 645 V3.1.3 requires every password outside to be unique per device or defined by the user. A universal operational password fails that rule. Pre-installed unique passwords also need a generation mechanism that reduces automated attack risk.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does ETSI EN 303 645 require for default passwords?

Provision 5.1-1 applies where passwords authenticate users against the device or provide . In every state other than , all device passwords must be unique per device or defined by the user. A universal value such as "admin" cannot remain usable as an operational password after initialization.

The standard permits unique pre-installed passwords, a user-selected password during initialization, or another authentication method that does not use passwords. Standard pairing codes are not treated as machine-to-machine passwords. V3.1.3 separately recommends that passwords not be used for and requires applicable authentication mechanisms to use best-practice cryptography.

Apply the test to every password-bearing path. Check local administration, remote APIs, network protocols, companion-app handoffs, service credentials used by the device, initialization, recovery, and factory reset. Record which state each credential is usable in and whether reset restores a unique value or forces a user-defined value before normal operation.

  • List every user and mechanism, including device interfaces, companion apps, local APIs, and network protocols.
  • For each mechanism, state whether the password is user-defined, unique per device, factory-default only, or not used.
  • Do not present a product as aligned with provision 5.1 if a universal password remains usable after initialization or reset into an operational state.
Citations
ETSI EN 303 645 V3.1.3, clause 5.1

Current ETSI source for unique or user-defined passwords outside factory default, machine-to-machine password guidance, authentication cryptography, change mechanisms, and brute-force protection.

Question 2

How should pre-installed unique passwords be handled?

Provision 5.1-2 applies when pre-installed unique per-device passwords are used. The generation mechanism must reduce the risk of automated attacks against a class or type of device, so the evidence has to cover the generation method, not only a sample label or onboarding screenshot.

ETSI gives examples of weak patterns to avoid: incremental counters, common strings, and passwords obviously related to public information such as MAC addresses or Wi-Fi SSIDs. TS 103 701 turns that into conceptual checks on regularities, common patterns, relationship to public information, and appropriate complexity.

  • Document the password generation mechanism in IXIT 1-AuthMech, including the authentication mechanism that uses it.
  • Show that generated passwords are not based on predictable counters, public identifiers, common strings, or obvious device information.
  • Keep functional evidence that sampled device passwords match the documented generation mechanism.
Citations
Question 3

What else belongs in a provision 5.1 password evidence pack?

Default-password work is only one part of clause 5.1. If a user can authenticate against the device, provision 5.1-4 requires a simple way for the user or an administrator to change the authentication value, whether that value is a password, PIN, biometric, or other token. Provision 5.1-5 requires a mechanism that makes successful brute-force attacks through network interfaces impracticable unless a resource constraint determined by the use case prevents implementation.

For an assessment, TS 103 701 expects the supplier organization to complete ICS and IXIT information so the test laboratory can derive a test plan. Incomplete IXIT information can lead to an inconclusive test result because the test case cannot be properly executed.

  • Include user-facing instructions for changing passwords or other authentication values, and verify the old value stops working after change.
  • Document brute-force prevention for network-accessible authentication, such as rate limits, increasing delays, account suspension, lockout, suitable entropy, or multi-factor authentication. If a use-case resource constraint prevents the control, identify the constraint and its effect.
  • Tie each claim to the assessed device version, user manual, interfaces, onboarding flow, reset behavior, and IXIT entries used by the test plan.
  • Reassess clause 5.1 when an authentication interface, credential source, generation algorithm, onboarding or recovery flow, factory-reset behavior, network protocol, or device software version changes.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Current ETSI source for unique or user-defined passwords, pre-installed password generation, machine-to-machine password guidance, cryptography, changeable authentication values, and brute-force protection.
etsi.org
Referenced sections
  • Current ETSI source for unique or user-defined passwords outside factory default, machine-to-machine password guidance, authentication cryptography, change mechanisms, and brute-force protection.
"all consumer IoT device passwords shall be unique per device or defined by the user"
etsi.org
Referenced sections
  • Primary ETSI source for requirements on pre-installed unique per-device password generation.
"generated with a mechanism that reduces the risk of automated attacks"
etsi.org
Referenced sections
  • Current ETSI source for changing authentication values and making successful brute-force attacks through network interfaces impracticable, including the use-case resource-constraint condition.
"simple mechanism to change the authentication value"
etsi.org
Referenced sections
  • Use ETSI's public standards search to check current deliverable status before making procurement, audit, or public compliance claims.
etsi.org
Referenced sections
  • Assessment source for ICS, IXIT, test-plan derivation, and inconclusive verdicts when required evidence is insufficient.
"The TL uses these documents to derive a test plan."
etsi.org
Referenced sections
  • Assessment source for checking obvious regularities, common patterns, public-information links, complexity, and implementation consistency.
"obvious regularities in pre-installed passwords"
etsi.org
Referenced sections
  • Assessment source for documenting and testing password-based authentication mechanisms in IXIT 1-AuthMech.
"password-based authentication mechanisms used to authenticate users against the DUT"
Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.