Artifact GuideGLOBALETSI EN 303 645

ETSI EN 303 645 Test evidence for consumer IoT assessments

A focused answer on what evidence should sit behind ETSI EN 303 645 support claims when TS 103 701 assessment concepts are used.

Use ETSI EN 303 645 V3.1.3 for the provision claims and ETSI TS 103 701 V2.1.1 for the compatible assessment method.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Identify the exact and editions first. Use EN 303 645 V3.1.3 to record provision support in the , then use TS 103 701 V2.1.1 to supply detail, derive the test plan, perform the applicable test groups, assess any , and assign verdicts.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What counts as test evidence for ETSI EN 303 645?

EN 303 645 is the baseline requirements standard. Annex B classifies provisions as mandatory, recommended, conditional, and feature-dependent and lets the user record Y, N, or N/A. The detail field records implemented measures, reasons for non-support, or the rationale for N/A. Provision 5.0-1 separately requires a justification for each recommendation considered not applicable or not fulfilled.

TS 103 701 is the compatible assessment methodology. It defines the (DUT), Supplier Organization, Test Laboratory, , , conceptual and functional tests, , and verdict rules. An evidence pack should therefore identify the DUT and software version, associated services and processes in scope, each ICS claim, supporting IXIT detail, applied test group or accepted external evidence, indications, and verdict.

  • Keep the EN 303 645 provision mapping separate from TS 103 701 assessment records.
  • For each supported provision, retain the support claim and the information needed to prepare and perform assessment activities.
  • Tie each test result to the specific DUT, software version, associated services, user documentation, and development or management process in scope.
  • Reassess affected claims when the hardware, software, configuration, interface, associated service, supplier process, cited standard edition, or relied-on changes.
Citations
Question 2

How should ICS and IXIT evidence be prepared?

The Supplier Organization completes DUT identification and the , then supplies the necessary information for provisions claimed Y. The Test Laboratory checks the IXIT for completeness, consistency, and soundness with the supplier. It also verifies that no mandatory provision is claimed N and tests whether N/A claims match the provision's stated condition or feature.

The must be specific enough to select test methods, equipment, conditions, and instructions. A referenced document has to be supplied to the laboratory. Missing or insufficient information can produce at test-case level because the test cannot be properly executed; it should not be recorded as PASS merely because no failure was observed.

  • Record Y, N, or N/A in the , using N/A only where the relevant condition is unsatisfied or the feature, capability, or mechanism does not exist.
  • Do not claim a mandatory provision N: TS 103 701 requires the laboratory to reject that during verification.
  • Complete the required entries for provisions claimed Y, and make each entry exhaustive, correct, and distinctly referenced.
  • Where the references existing documentation, provide that documentation to the test laboratory instead of relying on an unsupported assertion.
Citations
Question 3

Can existing certificates or third-party reports replace testing?

Sometimes, but only for the test group covered by the TS 103 701 external-evidence rules. Existing security certifications or third-party evaluations of parts of the DUT can reduce assessment effort. The Supplier Organization must identify the evidence in the relevant detail field and provide the certificate, scope, test reports, and other information needed for verification.

The Test Laboratory decides whether the evidence is adequate for that test group. It checks whether the scope matches the objective, the prior test activities satisfy every test purpose, and the test depth or evaluation assurance level fits the baseline assessment. Evidence accepted for one component or test group does not establish an overall verdict for the whole DUT.

Verdicts roll up in a fixed order. A test group passes when every test case passes or accepted satisfies clause 4.7. Any failed test case fails its test group. The overall result passes only if the is valid and every test group for a provision claimed Y passes; one failed applicable group produces FAIL, while an applicable group produces INCONCLUSIVE when no fail criterion applies.

  • Do not reuse a certificate or report unless its scope covers the same DUT part, feature, software, service, or process needed by the test group.
  • Keep the reference in the detail field together with the supporting report or certification details.
  • Treat as a TS 103 701 assessment input, not as a blanket EN 303 645 conformance claim for the whole product.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Primary ETSI source for the consumer IoT baseline provisions and the support, not-supported, and not-applicable detail model in the ICS pro forma.
"Table B.1 can provide a mechanism"
etsi.org
Referenced sections
  • Primary ETSI source for using the ICS detail column to explain implemented measures, reasons for non-support, and rationales for not-applicable provisions.
"the entry in the detail column"
etsi.org
Referenced sections
  • Assessment source for deciding whether existing certifications or third-party evaluations can replace test activities for a test group and when accepted external evidence can support a PASS verdict.
"Existing security certifications or third-party evaluations"
Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.