- Grounds the warnings about resource-constraint rationales, associated-service classification, and N/A limitations.
"N/A"
A practical workflow for deciding whether a product is in ETSI EN 303 645 scope and how to document provision-level applicability.
Use it to separate consumer IoT scope decisions, associated-service boundaries, device resource constraints, and TS 103 701 assessment inputs.
Structured answer sets in this page tree.
Cited legal and guidance references.
Decide first whether the product is a : a network-connected or network-connectable device that consumers typically use in the home or wear, rather than equipment primarily intended for manufacturing, healthcare, or another industrial application. Then identify , decide each provision separately, document any resource-constraint rationale, and prepare the evidence needed for an ETSI TS 103 701 V2.1.1 assessment against ETSI EN 303 645 V3.1.3.
ETSI EN 303 645 is written for consumer IoT devices connected to network infrastructure, such as the Internet or a home network, and for the device's interactions with . The standard gives examples including connected toys, baby monitors, smoke detectors, door locks, window sensors, gateways, hubs, smart cameras, TVs, speakers, wearable health trackers, home automation systems, alarms, connected appliances, and smart home assistants.
A product is not outside scope merely because it is used by a business. ETSI defines consumer IoT devices as network-connected or network-connectable devices used by consumers typically in the home or as electronic wearables, and notes that consumer IoT devices can also be used in business contexts. The stronger exclusion is product intent: devices primarily intended for manufacturing, healthcare, or other industrial applications are not in scope.
ETSI EN 303 645 defines an IoT product as the and its . Associated services are digital services that, together with the device, form the overall consumer IoT product and are typically required for the intended functionality. Examples include mobile applications, cloud computing or storage, and third-party APIs when they are part of the product.
The boundary is not every remote service the device can reach. Manufacturer-included telemetry, a companion app required during initialization, and a cloud access service used to control a smart lock are . A user-chosen streaming service, a website opened in a device browser, or an app installed later at the user's choice is not automatically an associated service under the ETSI examples.
ETSI EN 303 645 sets a consumer IoT security and data protection baseline, but provision applicability depends on the device. Provision 5.0-1 requires a recorded justification for each recommendation considered not applicable or not fulfilled. Annex B provides a structured implementation conformance statement table for provision references, status, support, and detail.
Record why each provision is supported, not supported, or not applicable. In the V3.1.3 Annex B pro forma, Y means supported and N means not supported. N/A is available when a stated condition is not satisfied or when the feature, capability, or mechanism to which an F-marked provision applies does not exist; the detail column records the rationale.
ETSI EN 303 645 V3.1.3 addresses rather than defining a blanket constrained-device category. Examples include energy supply, communication bandwidth, processing power, and volatile or non-volatile memory capacity.
A resource-constraint rationale needs product-specific reasoning. For example, provision 5.3-2 allows the absence of a secure update mechanism only when a resource constraint determined by the use case prevents implementation. ETSI says economic reasons alone do not justify that design. Capture the use case, resource limitation, affected provision, risk basis, alternative control, and user-facing support information.
This workflow helps turn scope, associated-service, device-resource, and provision-level decisions into owned ICS, IXIT, and evidence tasks.
Convert applicability decisions into accountable tasks, evidence requests, and assessment milestones.
Resolve product scope, associated-service, device-resource, and evidence questions against cited ETSI sources.
Review the product boundary, provision mapping, evidence owners, and next compliance actions with Sorena.
ETSI TS 103 701 provides a conformance assessment methodology for consumer IoT devices, their relation to , and relevant processes against ETSI EN 303 645. A test laboratory can be part of the supplier organization, a user organization, or an independent testing authority. A separate assessment scheme sets matters outside TS 103 701, such as tester competence, scheme-specific cryptographic requirements, accepted third-party evidence, and publication of results.
For assessment readiness, translate the applicability decision into a defined , supplier organization responsibilities, entries, entries, and evidence records. TS 103 701 explains that the supplier organization provides ICS and IXIT to the test laboratory, and the test laboratory uses those documents to derive a test plan.
Keep this table in release, procurement, or assessment planning. It is intentionally scoped to decisions that EN 303 645 and TS 103 701 cited sources support.
1 | Product scope | Product owner | Intended use, user type, device category, network connectivity | Is this a or primarily industrial, healthcare, manufacturing, or another excluded use?
2 | Associated-service boundary | Architecture owner | App, cloud, telemetry, API, hub, gateway, update, and support-service map | Which services are part of the IoT product because they are manufacturer-included or required for intended functionality?
3 | Provision applicability | Security/compliance owner | Annex B-style provision table with support, N/A, and detail entries | Which provisions are supported, not supported, or conditionally not applicable with a recorded rationale?
4 | Resource-constraint rationale | Engineering owner | Use case, technical limitation, affected provision, risk basis, alternative control, user information | Is non-applicability justified for a specific provision, or is the claim too broad?
5 | Assessment handoff | Supplier organization lead | DUT version, , , external evidence, conceptual and functional test evidence | Can a test laboratory derive a defensible test plan from the supplied evidence?
An applicability record needs the reasoning between product scope, the associated-service boundary, conditional provisions, and assessment evidence. It should show why the product is within the consumer IoT scope, why a specific provision is not applicable, or why the product's primary intended use places it outside scope.
"N/A"
"Defining a certification or conformance declaration scheme is out of scope"