Artifact GuideGLOBALETSI EN 303 645

ETSI EN 303 645 Vulnerability disclosure for consumer IoT products

ETSI EN 303 645 V3.1.3 requires a public vulnerability disclosure policy with reporting contact details and acknowledgement and status-update timelines.

The policy requirement is mandatory. Timely action and continuous vulnerability monitoring during the defined support period are recommendations.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Provision 5.2-1 requires the manufacturer to publish a with reporting contact information, a timeline for initial acknowledgement, and timelines for status updates until resolution. Provisions 5.2-2 and 5.2-3 recommend timely action and continuous monitoring, identification, and rectification during the .

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What must the public vulnerability disclosure policy include?

A security mailbox alone is not enough. Provision 5.2-1 says the manufacturer shall make the policy publicly available and include contact information for reporting issues, a timeline for initial acknowledgement of receipt, and timelines for status updates to the reporter until resolution.

For visitors, buyers, researchers, and assessors, the policy should make the reporting path visible without requiring private documentation. TS 103 701 turns that into both a conceptual and functional assessment: the test laboratory checks the publication route described in IXIT 2-UserInfo and verifies that the policy is publicly accessible.

  • Publish a clear external location for the , such as a security page or support path that remains reachable without authentication.
  • Include contact information that lets security researchers and other reporters submit potential vulnerabilities.
  • State an acknowledgement timeline and status-update timelines. ETSI allows different ways to express time values, but the policy still has to tell reporters what to expect.
  • Keep product documentation, app help, or support pages aligned with the public policy location if those channels direct users to report security issues.
Citations
ETSI EN 303 645 V3.1.3, clause 5.2

Primary ETSI requirement for publishing a vulnerability disclosure policy with reporting contact information and acknowledgement/status-update timelines.

Question 2

How should reported vulnerabilities be handled after disclosure?

Provision 5.2-2 recommends timely action. Its explanatory text says timing varies by incident and describes 90 days as a conventional completion point for a properly documented software vulnerability-management process, including patch availability and notification. It is not a mandatory universal remediation deadline, and hardware fixes or device rollouts can take longer.

Evidence should therefore define the action and time frame for each vulnerability type in IXIT 3-VulnTypes. TS 103 701 asks the laboratory to consider the public policy, severity and criticality, whether the issue affects firmware, hardware, or software, process steps and responsibilities, deployment route, and third-party involvement.

  • Define how reports are triaged, investigated, confirmed, fixed, mitigated, or escalated for the product and its associated services.
  • Separate timelines where firmware, cloud service, mobile app, hardware, operating system, or third-party library vulnerabilities follow different paths.
  • Document who owns each step, including security incident teams, software teams, supplier contacts, and external vendors where relevant.
  • Avoid claiming a fixed universal remediation deadline unless the evidence supports that timeline for the vulnerability type and deployment route.
  • Retain the report, acknowledgement, reporter updates, severity and applicability decision, affected versions, supplier handoffs, remediation or mitigation decision, release evidence, and closure record.
Citations
Question 3

What evidence supports vulnerability monitoring and rectification?

Provision 5.2-3 recommends that manufacturers continually monitor for, identify, and rectify vulnerabilities in consumer IoT products they sell, produce, or have produced and in associated services they operate during the . The recommendation is bounded by that period unless the manufacturer makes a longer commitment.

TS 103 701 maps this to IXIT 5-VulnMon. The assessment asks whether the described monitoring approach systematically gathers vulnerability information that could affect the device under test or its associated services, whether the identification approach determines applicability, and whether the rectification approach addresses or mitigates susceptibility.

  • Maintain a list of software components and sub-components, or an that supplies that view, so third-party and open-source vulnerabilities can be matched to the product.
  • Record vulnerability sources monitored, the review cadence, how potential matches are assessed for applicability, and how non-applicable findings are documented.
  • Tie monitoring output back into the same vulnerability handling process used for externally reported issues.
  • Keep the evidence bounded to the unless the manufacturer actually continues monitoring and security updates beyond that period.
  • Reassess the policy and IXIT records when the reporting contact, acknowledgement or update timeline, product scope, component inventory, associated service, supplier route, remediation process, public URL, or changes.
Citations
ETSI EN 303 645 V3.1.3, provision 5.2-3

Primary ETSI source for continuous monitoring, identification, and rectification during the defined support period and component-list prerequisites for vulnerability monitoring.

Primary sources

References and citations

etsi.org
Referenced sections
  • Primary ETSI requirement for publishing a vulnerability disclosure policy with reporting contact information and acknowledgement/status-update timelines.
"The manufacturer shall make a vulnerability disclosure policy publicly available."
etsi.org
Referenced sections
  • Primary ETSI source for timely action on disclosed vulnerabilities and the standard's explanation of incident-specific timing.
"Disclosed vulnerabilities should be acted on in a timely manner."
etsi.org
Referenced sections
  • Primary ETSI source for continuous monitoring, identification, and rectification during the defined support period and component-list prerequisites for vulnerability monitoring.
"Manufacturers should continually monitor for, identify and rectify security vulnerabilities"
etsi.org
Referenced sections
  • Assessment method for IXIT 3-VulnTypes action and time-frame evidence, including responsibilities, third-party involvement, and indicators of timely deployment.
"the documentation of the point of contacts and defined procedures for the collaboration are indicators for a timely deployment"
etsi.org
Referenced sections
  • Assessment method for IXIT 5-VulnMon evidence covering monitoring, identification, and rectification procedures for the DUT and associated services.
"systematically gather information about security vulnerabilities that potentially can affect the DUT or its associated services"
etsi.org
Referenced sections
  • Assessment method for checking that the vulnerability disclosure policy publication is available and publicly accessible through IXIT 2-UserInfo.
"the publication of the vulnerability disclosure policy is available for anybody"
Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.