Artifact GuideGLOBALETSI EN 303 645

ETSI EN 303 645 Consumer IoT product scope

A focused answer on which consumer IoT products ETSI EN 303 645 covers and how to turn that scope decision into reviewable evidence.

Based on ETSI EN 303 645 V3.1.3 and ETSI TS 103 701 V2.1.1. Scope follows the product's intended consumer use and associated services that are typically required for its intended functionality.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 303 645 V3.1.3 covers network-connected or network-connectable devices typically used by consumers at home or as electronic wearables, plus their interactions with . Scope the physical device, associated digital services, software version, interfaces, and relevant lifecycle processes before recording provision support.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What counts as a consumer IoT product under ETSI EN 303 645?

ETSI defines a as a network-connected or network-connectable device that has relationships to and is typically used by consumers in the home or as an electronic wearable. An is the consumer IoT device plus its associated services. Consumer devices do not leave scope merely because a business also uses them.

Examples include connected children's toys, baby monitors, smoke detectors, locks, window sensors, gateways, hubs, cameras, speakers, televisions, wearable health trackers, home automation and alarms, appliances, and smart home assistants. Devices primarily intended for manufacturing, healthcare, or other industrial applications are outside the document's scope.

  • Start the scope note with the exact device or product family, its network connectivity, and the consumer use case. If the device is not network-connected or network-connectable, this EN 303 645 scope test ends.
  • Include digital services that form part of the product and are typically required for its intended functionality, such as manufacturer cloud access, preconfigured telemetry, or a required companion app.
  • Treat a user-chosen website or store-installed app as outside the associated-service boundary unless product-specific facts show that the manufacturer made it part of the intended product.
  • Do not stretch the scope to a product primarily intended for industrial, manufacturing, or healthcare use merely because it connects to a network.
  • If consumer and professional uses overlap, document the intended market, ordinary user, sales channels, instructions, and service configuration instead of treating business use alone as an exclusion.
Citations
ETSI TS 103 701 V2.1.1, scope

Assessment source confirming that the methodology covers consumer IoT devices, their associated services, and corresponding relevant processes.

Question 2

How should teams document product scope for assessment?

ETSI TS 103 701 uses the (DUT) as the specific submitted for assessment. The test scenarios cover DUT functionality, its relation to , and relevant development or management processes. The most up-to-date DUT software version should be used for the assessment.

The Supplier Organization can be the developer, manufacturer, vendor, or distributor requesting the assessment. It provides the ICS and IXIT to the Test Laboratory and coordinates necessary product and supply-chain information. The laboratory uses those records to verify scope, derive a test plan, perform applicable test groups, and assign verdicts.

  • Identify the DUT, software version, interfaces, , and relevant supplier-side processes before claiming assessment readiness.
  • Use the EN 303 645 implementation conformance statement pro forma to record support, non-support, or not-applicable rationale for each provision.
  • Use the TS 103 701 IXIT structure to point assessors to the evidence needed for conceptual and functional tests.
Citations
Question 3

What scope mistakes create weak ETSI EN 303 645 claims?

A weak scope claim treats ETSI EN 303 645 as a generic product-security label. The standard is product- and provision-specific: applicability can depend on a provision's condition, whether a feature exists, which form part of the product, and the exact DUT version.

V3.1.3 no longer defines a general constrained-device category. A use-case resource constraint matters only where a provision makes it relevant, such as the condition in provision 5.1-5. Provision 5.0-1 also requires a recorded justification for each recommendation considered not applicable or not fulfilled.

  • Avoid saying a whole product is compliant without naming the assessed DUT, , provisions, software version, and evidence boundary.
  • Do not exclude a cloud service or companion app when it is an associated service required for the product's intended functionality.
  • Record feature, condition, resource-constraint, and recommendation decisions separately instead of using a generic N/A statement.
  • Reassess scope when connectivity, intended use, target users, required apps or cloud services, default service configuration, supplier responsibilities, model designation, or assessed software version changes.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Current ETSI source for consumer IoT scope, IoT product and associated-service boundaries, provision applicability, recommendation justifications, and Annex B ICS details.
"high-level security and data protection provisions for consumer IoT devices"
etsi.org
Referenced sections
  • Primary ETSI source for the implementation conformance statement pro forma and support-detail rationale.
"give information about the implementation of the provisions"
etsi.org
Referenced sections
  • Primary ETSI source for consumer IoT device, IoT product, associated services, examples, and out-of-scope industrial use.
"consumer IoT device and its associated services"
etsi.org
Referenced sections
  • Assessment source explaining that TSOs are generic because consumer IoT devices are heterogeneous and a suitable test plan must be derived.
"not feasible to describe a specific testing procedure"
etsi.org
Referenced sections
  • Assessment methodology source for DUT, SO, TL, ICS, IXIT, conceptual tests, functional tests, and test-plan derivation.
"The TL uses these documents to derive a test plan."
etsi.org
Referenced sections
  • Assessment source confirming that the methodology covers consumer IoT devices, their associated services, and corresponding relevant processes.
"consumer IoT devices, their relation to associated services"
Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.