ETSI EN 303 645 — Consumer IoT security
Apply a practical baseline for consumer connected products, covering credentials, vulnerability disclosure, updates, data protection and resilient operation.
After this module, you should be able to:
- Explain the baseline and its outcome-focused provisions
- Translate provisions into product and service requirements
- Plan updates and vulnerability disclosure across the support period
- Recognise implementation and assessment evidence
The standard establishes a practical security baseline.
ETSI EN 303 645 defines high-level cybersecurity provisions for consumer Internet of Things products and associated services. It focuses on common, high-impact weaknesses and is intended to be technology-neutral.
Its provisions cover areas such as unique credentials, vulnerability reporting, software updates, secure storage and communication, attack-surface reduction, software integrity, personal data, resilience and user-facing installation or deletion. Product context still determines the detailed controls.
Translate the framework into controlled engineering work.
| Area | Question | Typical evidence |
|---|---|---|
| Credentials | Are passwords and secrets unique, protected and changeable where needed? | Provisioning and credential records |
| Vulnerability handling | Can researchers report issues and can the organisation act? | Disclosure policy and response process |
| Updates | Are updates timely, authorised, integrity-protected and recoverable? | Update architecture and support policy |
| Attack surface | Are interfaces, privileges and exposed services minimised? | Service inventory and hardening evidence |
| Personal data | Is data protected, transparent and erasable as required? | Data map, controls and user guidance |
Apply the current controlled source
This module is an orientation. Confirm the applicable edition, amendments, adopted regional version, contractual commitments and sector-specific interpretations before defining compliance.
Use a risk-based application sequence.
- 1. Define the consumer IoT product, associated services, users and support period
- 2. Map each applicable provision to a product requirement or justified rationale
- 3. Design unique identity, secure defaults and least-privilege interfaces
- 4. Implement vulnerability intake and secure, recoverable update capability
- 5. Test exposed services, credentials, data flows, reset and deletion behaviour
- 6. Publish support and security information that users can understand
Worked application: connected thermostat
Each thermostat receives a unique device identity during controlled provisioning. The service authenticates the device and user, the update package is authorised and recoverable, unused local services are disabled, and factory reset removes personal association. The manufacturer publishes a reporting route and support period.
Build evidence that explains the reasoning.
Provision, product interpretation and rationale.
Testable controls across device, app and services.
Unique identities, secret handling and factory controls.
Interface, credential, update and data-deletion tests.
Public reporting route, triage and remediation flow.
Update commitment and end-of-support communication.
Common failure patterns
Apps, APIs and provisioning services escape assessment.
One disclosure compromises the installed fleet.
Signature exists but interruption and rollback are not handled.
Users cannot make an informed security decision.
Further learning
- ETSI · Consumer IoT securityOfficial ETSI resources for the consumer IoT security baseline.
- TEA-204 · Application and connectivity engineersEnd-to-end identity, command and compatibility concerns.
Use the standard to strengthen decisions, not decorate them.
Make scope, tailoring, responsibilities, technical reasoning and objective evidence explicit—and always work from the current authorised text.