Independent learning for embedded-systems engineersHardware · Firmware · Software
TEA-306STANDARDS & GUIDANCECONSUMER IoT

ETSI EN 303 645 — Consumer IoT security

Apply a practical baseline for consumer connected products, covering credentials, vulnerability disclosure, updates, data protection and resilient operation.

After this module, you should be able to:

  • Explain the baseline and its outcome-focused provisions
  • Translate provisions into product and service requirements
  • Plan updates and vulnerability disclosure across the support period
  • Recognise implementation and assessment evidence
01 / INTENT

The standard establishes a practical security baseline.

ETSI EN 303 645 defines high-level cybersecurity provisions for consumer Internet of Things products and associated services. It focuses on common, high-impact weaknesses and is intended to be technology-neutral.

Its provisions cover areas such as unique credentials, vulnerability reporting, software updates, secure storage and communication, attack-surface reduction, software integrity, personal data, resilience and user-facing installation or deletion. Product context still determines the detailed controls.

BASELINERemove common weaknessPasswords, exposed services and insecure defaults
LIFECYCLESupport the productDisclosure, updates and defined support period
DATAProtect peopleSecure communication, storage and deletion
The product includes its associated services.Mobile apps, cloud APIs, provisioning systems and update infrastructure can determine whether the physical device meets the intended security outcome.
02 / FRAMEWORK

Translate the framework into controlled engineering work.

AreaQuestionTypical evidence
CredentialsAre passwords and secrets unique, protected and changeable where needed?Provisioning and credential records
Vulnerability handlingCan researchers report issues and can the organisation act?Disclosure policy and response process
UpdatesAre updates timely, authorised, integrity-protected and recoverable?Update architecture and support policy
Attack surfaceAre interfaces, privileges and exposed services minimised?Service inventory and hardening evidence
Personal dataIs data protected, transparent and erasable as required?Data map, controls and user guidance

Apply the current controlled source

This module is an orientation. Confirm the applicable edition, amendments, adopted regional version, contractual commitments and sector-specific interpretations before defining compliance.

03 / APPLICATION

Use a risk-based application sequence.

  1. 1. Define the consumer IoT product, associated services, users and support period
  2. 2. Map each applicable provision to a product requirement or justified rationale
  3. 3. Design unique identity, secure defaults and least-privilege interfaces
  4. 4. Implement vulnerability intake and secure, recoverable update capability
  5. 5. Test exposed services, credentials, data flows, reset and deletion behaviour
  6. 6. Publish support and security information that users can understand

Worked application: connected thermostat

Each thermostat receives a unique device identity during controlled provisioning. The service authenticates the device and user, the update package is authorised and recoverable, unused local services are disabled, and factory reset removes personal association. The manufacturer publishes a reporting route and support period.

04 / EVIDENCE

Build evidence that explains the reasoning.

Applicability matrix

Provision, product interpretation and rationale.

Security requirements

Testable controls across device, app and services.

Provisioning evidence

Unique identities, secret handling and factory controls.

Security verification

Interface, credential, update and data-deletion tests.

Disclosure process

Public reporting route, triage and remediation flow.

Support statement

Update commitment and end-of-support communication.

Common failure patterns

Device-only scope

Apps, APIs and provisioning services escape assessment.

Shared default secret

One disclosure compromises the installed fleet.

Update checkbox

Signature exists but interruption and rollback are not handled.

Silent end of support

Users cannot make an informed security decision.

05 / REFERENCES

Further learning

KEY TAKEAWAY

Use the standard to strengthen decisions, not decorate them.

Make scope, tailoring, responsibilities, technical reasoning and objective evidence explicit—and always work from the current authorised text.