Cybersecurity Standard
DETAIL

ETSI EN 303 645 Cyber Security for Consumer Internet of Things: Baseline Requirements

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

ETSI EN 303 645 is a European Standard that specifies high-level, outcome-focused security and data protection provisions for consumer Internet of Things (IoT) devices connected to the internet or a home network, together with the services they interact with. It brings widely accepted good practice for connected products into 13 groups of provisions plus data protection provisions, so manufacturers can build security in from design rather than patch it afterward.

The standard is produced by ETSI Technical Committee Cyber Security (CYBER). The current version is V3.1.3 (2024-09), adopted on 11 September 2024, which succeeded the first edition V2.1.1 (2020-06). It is voluntary as a standard, but it is referenced by national consumer IoT security regimes and labeling schemes and is the baseline against which ETSI TS 103 701 conformance assessments are run, so manufacturers, importers, test laboratories, and certification bodies treat it as a de facto requirement.

Organizations implement EN 303 645 by mapping each provision to their device and service design, documenting the implementation conformance statement in Annex B, using ETSI TR 103 621 for implementation guidance, and arranging assessment against ETSI TS 103 701 where a label, customer, or regulator requires it. The provisions are commonly integrated with an ISO/IEC 27001 management system, a secure development lifecycle, and vulnerability disclosure processes.

Why it Matters

ETSI EN 303 645 gives manufacturers and their supply chains one recognized baseline for consumer IoT security that regulators, labeling schemes, and buyers increasingly expect.

Key benefits include:

  • Reduce the most common consumer IoT attacks

The provisions target the weaknesses that drive real incidents: universal default passwords, unpatched software, insecure interfaces, and exposed sensitive parameters.

  • Meet regulator and labeling expectations

National consumer device security laws and labeling schemes reference EN 303 645, so conformance shortens the route to market.

  • Demonstrate security by design

The implementation conformance statement and ETSI TS 103 701 assessment give customers and assessors verifiable evidence rather than marketing claims.

  • Protect personal data on devices

Data protection provisions require transparency, consent for telemetry, and easy deletion of user data, supporting privacy law compliance.

  • Keep flexibility for constrained devices

Outcome-focused provisions let manufacturers choose implementations that fit energy, memory, and bandwidth limits.

How it Works

The standard is organized into 13 provision groups in clause 5: no universal default passwords; implement a means to manage reports of vulnerabilities; keep software updated; securely store sensitive security parameters; communicate securely; minimize exposed attack surfaces; ensure software integrity; ensure that personal data is secure; make systems resilient to outages; examine system telemetry data; make it easy for users to delete user data; make installation and maintenance of devices easy; and validate input data. Clause 6 adds data protection provisions. Each provision is written as a requirement ("shall") or a recommendation ("should"), with a scheme in Annex B for recording implementation and reasons where a provision does not apply.

Manufacturers implement the standard by threat-modeling the device and associated services, deciding which provisions apply to the product's device states and interfaces, and designing controls such as unique per-device credentials, signed and verified update mechanisms, secure storage of keys, encrypted communications, and a published vulnerability disclosure policy. Typical activities include documenting the defined support period, testing against ETSI TS 103 701, and maintaining the conformance statement across firmware releases.

Within SmartSuite, product security teams can operationalize EN 303 645 by holding the provisions as a control library per product line, assigning owners for each provision, recording the implementation conformance statement and test evidence, tracking vulnerability reports and update releases, and reporting conformance status to leadership and certification bodies.

Key Elements

  • Thirteen cyber security provision groups

Clause 5 sets the security outcomes, from unique passwords and vulnerability management to input validation.

  • Data protection provisions

Clause 6 requires transparency about personal data processing, consent for telemetry, and simple deletion of personal data.

  • Mandatory and recommended provisions

Provisions use "shall" for baseline requirements and "should" for recommendations, letting schemes set the pass mark.

  • Implementation conformance statement

Annex B provides the schema manufacturers use to declare how each provision is met or why it does not apply.

  • Device states, interfaces, and constrained devices

Annex A models the architecture and states the provisions apply to, with allowances for resource constraints.

  • Companion assessment and guidance documents

ETSI TS 103 701 specifies conformance test cases and ETSI TR 103 621 gives implementation examples for each provision.

Framework Scope

EN 303 645 applies to consumer IoT devices connected to network infrastructure and their associated services, such as connected toys and baby monitors, smoke detectors and door locks, gateways and hubs, smart cameras, speakers, and televisions, wearable health trackers, home automation and alarm systems, connected appliances, and smart home assistants. It excludes devices intended primarily for industrial, medical, or enterprise use, which fall under other standards, and it is adopted by manufacturers, importers, and test laboratories that need a recognized baseline.

Framework Objectives

ETSI EN 303 645 aims to raise the security baseline of consumer IoT products and protect the people who use them.

Eliminate universal default passwords and other well-known weaknesses from consumer devices

Ensure products receive security updates for a defined and published support period

Protect sensitive security parameters, communications, and software integrity

Give consumers transparency and control over personal data processed by devices

Provide a common baseline for conformance assessment, labeling, and regulation

Keep provisions outcome-focused so constrained devices can comply

Framework in Context

EN 303 645 is the baseline referenced by national consumer IoT codes and labeling schemes, is assessed through ETSI TS 103 701, and aligns with the EU Cyber Resilience Act, ISO/IEC 27402, NIST IR 8259A, and IEC 62443-4-2 for component security. Manufacturers usually run it inside an ISO/IEC 27001 management system with NIST CSF 2.0 for program-level governance.

Common Framework Mappings

Organizations map EN 303 645 provisions to national IoT security requirements, product security standards, and information security management systems to avoid duplicate testing and to show regulators and customers a single conformance picture.

Mapped frameworks include:

ETSI TS 103 701

ISO/IEC 27402

NIST IR 8259A

EU CRA

Australia IoT Code

CSA IoT SCF v2

IEC 62443-4-2

UL 2900-1

NCA CGIoT-1:2024

ISO 27001:2022

NIST CSF 2.0

GDPR

UK PSTI Act 2022

At a Glance
ETSI EN 303 645 Cyber Security for Consumer Internet of Things: Baseline Requirements
  • Classification
    Category
    Cybersecurity Standard
    Domain
    Cybersecurity
    Framework Family
    Other
  • Regulatory Context
    Type
    Standard
    Legal Instrument
    Standard
    Sector
    Consumer IoT / Technology
    Industry
    Cross-Industry
  • Region / Publisher
    Region
    Europe
    Region Detail
    ETSI (Europe), adopted internationally
    Publisher
    European Telecommunications Standards Institute (ETSI)
  • Versioning
    Version
    V3.1.3 (2024-09)
    Effective Date
    2024
    Issue Date
    2020
  • Adoption
    Adoption Model
    Voluntary
    Implementation Complexity
    Medium
  • Official Reference
License Information

License included / downloadable: Yes

ETSI publishes EN 303 645 free of charge as a PDF on its deliver site; the text remains ETSI copyright and is not reproduced within the platform.

Framework text is licensed by its publisher and is included only where stated above.

SMARTSUITE

How SmartSuite Supports ETSI EN 303 645

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.

Manage EN 303 645 conformance by holding every provision, its implementation conformance statement, test evidence, and vulnerability and update records per product line in one workspace.

EN 303 645 Provision Library

Load the clause 5 and clause 6 provisions with their shall/should status and link each to product designs and policies.

Ownership and Release Cadence

Assign provision owners per product line and schedule reviews for each firmware release and support-period milestone.

Conformance Statement and Evidence

Record the Annex B implementation conformance statement with design documents, test reports, and reviewer sign-off.

Assessment and Remediation Tracking

Capture ETSI TS 103 701 test results and labeling scheme findings and drive remediation to closure.

Vulnerability Disclosure and Update Management

Track vulnerability reports, response times, and security update releases against the published support period.

Product Security Reporting

Report conformance status, open findings, and support-period commitments to leadership, customers, and certification bodies.

Related frameworks

EU CRA

The EU Cyber Resilience Act mandates cybersecurity requirements for products with digital elements sold in the EU to reduce vulnerabilities.

Australia IoT Code

Australia IoT Code of Practice is a voluntary framework providing guidance to secure consumer IoT devices and protect end-user data.

CSA IoT SCF v2

CSA IoT SCF provides guidance for identifying and implementing security controls across IoT devices, networks, and data throughout their lifecycle.

IEC 62443-4-2

IEC 62443-4-2 specifies technical security requirements for industrial automation and control system components to protect them from cyber threats.

UL 2900-1

UL 2900-1 specifies cybersecurity requirements for software in network-connectable products to reduce vulnerabilities and ensure secure operation.

NCA CGIoT-1:2024

Saudi Arabia's CGIoT-1:2024 provides cybersecurity guidance for securing cloud services and IoT devices in organizations.

ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

ONBOARDING FAQS

Frequently Asked Questions For ETSI EN 303 645

No items found.

Operationalize ETSI EN 303 645 with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.