ETSI EN 303 645 Cyber Security for Consumer Internet of Things: Baseline Requirements

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
ETSI EN 303 645 is a European Standard that specifies high-level, outcome-focused security and data protection provisions for consumer Internet of Things (IoT) devices connected to the internet or a home network, together with the services they interact with. It brings widely accepted good practice for connected products into 13 groups of provisions plus data protection provisions, so manufacturers can build security in from design rather than patch it afterward.
The standard is produced by ETSI Technical Committee Cyber Security (CYBER). The current version is V3.1.3 (2024-09), adopted on 11 September 2024, which succeeded the first edition V2.1.1 (2020-06). It is voluntary as a standard, but it is referenced by national consumer IoT security regimes and labeling schemes and is the baseline against which ETSI TS 103 701 conformance assessments are run, so manufacturers, importers, test laboratories, and certification bodies treat it as a de facto requirement.
Organizations implement EN 303 645 by mapping each provision to their device and service design, documenting the implementation conformance statement in Annex B, using ETSI TR 103 621 for implementation guidance, and arranging assessment against ETSI TS 103 701 where a label, customer, or regulator requires it. The provisions are commonly integrated with an ISO/IEC 27001 management system, a secure development lifecycle, and vulnerability disclosure processes.
Why it Matters
ETSI EN 303 645 gives manufacturers and their supply chains one recognized baseline for consumer IoT security that regulators, labeling schemes, and buyers increasingly expect.
Key benefits include:
- Reduce the most common consumer IoT attacks
The provisions target the weaknesses that drive real incidents: universal default passwords, unpatched software, insecure interfaces, and exposed sensitive parameters.
- Meet regulator and labeling expectations
National consumer device security laws and labeling schemes reference EN 303 645, so conformance shortens the route to market.
- Demonstrate security by design
The implementation conformance statement and ETSI TS 103 701 assessment give customers and assessors verifiable evidence rather than marketing claims.
- Protect personal data on devices
Data protection provisions require transparency, consent for telemetry, and easy deletion of user data, supporting privacy law compliance.
- Keep flexibility for constrained devices
Outcome-focused provisions let manufacturers choose implementations that fit energy, memory, and bandwidth limits.
How it Works
The standard is organized into 13 provision groups in clause 5: no universal default passwords; implement a means to manage reports of vulnerabilities; keep software updated; securely store sensitive security parameters; communicate securely; minimize exposed attack surfaces; ensure software integrity; ensure that personal data is secure; make systems resilient to outages; examine system telemetry data; make it easy for users to delete user data; make installation and maintenance of devices easy; and validate input data. Clause 6 adds data protection provisions. Each provision is written as a requirement ("shall") or a recommendation ("should"), with a scheme in Annex B for recording implementation and reasons where a provision does not apply.
Manufacturers implement the standard by threat-modeling the device and associated services, deciding which provisions apply to the product's device states and interfaces, and designing controls such as unique per-device credentials, signed and verified update mechanisms, secure storage of keys, encrypted communications, and a published vulnerability disclosure policy. Typical activities include documenting the defined support period, testing against ETSI TS 103 701, and maintaining the conformance statement across firmware releases.
Within SmartSuite, product security teams can operationalize EN 303 645 by holding the provisions as a control library per product line, assigning owners for each provision, recording the implementation conformance statement and test evidence, tracking vulnerability reports and update releases, and reporting conformance status to leadership and certification bodies.
Key Elements
- Thirteen cyber security provision groups
Clause 5 sets the security outcomes, from unique passwords and vulnerability management to input validation.
- Data protection provisions
Clause 6 requires transparency about personal data processing, consent for telemetry, and simple deletion of personal data.
- Mandatory and recommended provisions
Provisions use "shall" for baseline requirements and "should" for recommendations, letting schemes set the pass mark.
- Implementation conformance statement
Annex B provides the schema manufacturers use to declare how each provision is met or why it does not apply.
- Device states, interfaces, and constrained devices
Annex A models the architecture and states the provisions apply to, with allowances for resource constraints.
- Companion assessment and guidance documents
ETSI TS 103 701 specifies conformance test cases and ETSI TR 103 621 gives implementation examples for each provision.
Framework Scope
EN 303 645 applies to consumer IoT devices connected to network infrastructure and their associated services, such as connected toys and baby monitors, smoke detectors and door locks, gateways and hubs, smart cameras, speakers, and televisions, wearable health trackers, home automation and alarm systems, connected appliances, and smart home assistants. It excludes devices intended primarily for industrial, medical, or enterprise use, which fall under other standards, and it is adopted by manufacturers, importers, and test laboratories that need a recognized baseline.
Framework Objectives
ETSI EN 303 645 aims to raise the security baseline of consumer IoT products and protect the people who use them.
Eliminate universal default passwords and other well-known weaknesses from consumer devices
Ensure products receive security updates for a defined and published support period
Protect sensitive security parameters, communications, and software integrity
Give consumers transparency and control over personal data processed by devices
Provide a common baseline for conformance assessment, labeling, and regulation
Keep provisions outcome-focused so constrained devices can comply
Framework in Context
EN 303 645 is the baseline referenced by national consumer IoT codes and labeling schemes, is assessed through ETSI TS 103 701, and aligns with the EU Cyber Resilience Act, ISO/IEC 27402, NIST IR 8259A, and IEC 62443-4-2 for component security. Manufacturers usually run it inside an ISO/IEC 27001 management system with NIST CSF 2.0 for program-level governance.
Common Framework Mappings
Organizations map EN 303 645 provisions to national IoT security requirements, product security standards, and information security management systems to avoid duplicate testing and to show regulators and customers a single conformance picture.
Mapped frameworks include:
ETSI TS 103 701
ISO/IEC 27402
NIST IR 8259A
EU CRA
Australia IoT Code
CSA IoT SCF v2
IEC 62443-4-2
UL 2900-1
NCA CGIoT-1:2024
ISO 27001:2022
NIST CSF 2.0
GDPR
UK PSTI Act 2022
- ClassificationCategoryCybersecurity StandardDomainCybersecurityFramework FamilyOther
- Regulatory ContextTypeStandardLegal InstrumentStandardSectorConsumer IoT / TechnologyIndustryCross-Industry
- Region / PublisherRegionEuropeRegion DetailETSI (Europe), adopted internationallyPublisherEuropean Telecommunications Standards Institute (ETSI)
- VersioningVersionV3.1.3 (2024-09)Effective Date2024Issue Date2020
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
ETSI publishes EN 303 645 free of charge as a PDF on its deliver site; the text remains ETSI copyright and is not reproduced within the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports ETSI EN 303 645
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Manage EN 303 645 conformance by holding every provision, its implementation conformance statement, test evidence, and vulnerability and update records per product line in one workspace.
EN 303 645 Provision Library
Load the clause 5 and clause 6 provisions with their shall/should status and link each to product designs and policies.
Ownership and Release Cadence
Assign provision owners per product line and schedule reviews for each firmware release and support-period milestone.
Conformance Statement and Evidence
Record the Annex B implementation conformance statement with design documents, test reports, and reviewer sign-off.
Assessment and Remediation Tracking
Capture ETSI TS 103 701 test results and labeling scheme findings and drive remediation to closure.
Vulnerability Disclosure and Update Management
Track vulnerability reports, response times, and security update releases against the published support period.
Product Security Reporting
Report conformance status, open findings, and support-period commitments to leadership, customers, and certification bodies.
Related frameworks

The EU Cyber Resilience Act mandates cybersecurity requirements for products with digital elements sold in the EU to reduce vulnerabilities.

Australia IoT Code of Practice is a voluntary framework providing guidance to secure consumer IoT devices and protect end-user data.

CSA IoT SCF provides guidance for identifying and implementing security controls across IoT devices, networks, and data throughout their lifecycle.

IEC 62443-4-2 specifies technical security requirements for industrial automation and control system components to protect them from cyber threats.

UL 2900-1 specifies cybersecurity requirements for software in network-connectable products to reduce vulnerabilities and ensure secure operation.

Saudi Arabia's CGIoT-1:2024 provides cybersecurity guidance for securing cloud services and IoT devices in organizations.
Frequently Asked Questions For ETSI EN 303 645
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

