Standard · Consumer & Industrial

ETSI EN 303 645 — the baseline the whole world copied

Thirteen provisions written plainly enough for a product manager and precisely enough for a test lab — which is why the UK, Singapore, Japan and the US label regimes all trace back to it. One evidence set against this standard is the closest thing consumer IoT has to a universal passport.

At a glance

Owner

ETSI TC CYBER

Current version 3.1.3 (2024)

Scope

Consumer IoT devices

13 provision groups, 33 mandatory requirements, 35 recommendations

Assessment

ETSI TS 103 701

Standardised test specification labs evaluate against

Top three

No default passwords

Plus vulnerability disclosure policy and defined update support

Feeds into

UK PSTI, SG CLS, JP JC-STAR

Aligned with NIST IR 8425 behind the US Cyber Trust Mark

EU status

Evidence, not presumption

Not RED/CRA-harmonised — but the substance overlaps heavily

What it is

Outcome-based, testable, and deliberately modest

EN 303 645 states outcomes — no universal default passwords, keep software updated, secure communication, minimise attack surfaces, make telemetry transparent — rather than prescribing implementations. That restraint is its genius: it fits a €15 sensor and a €1,500 appliance, and it gave regulators worldwide a ready-made technical floor. The companion TS 103 701 turns the provisions into a lab-executable assessment, which is what separates it from aspirational codes of practice.

Its global footprint is the practical story. The UK’s PSTI regime enforces its top three provisions in law; Singapore’s CLS(IoT) grades products against it across four levels; Japan’s JC-STAR builds on the same base; and the US Cyber Trust Mark’s NIST criteria align closely. With mutual-recognition arrangements between the UK, Singapore and Japan now live, an EN 303 645 evidence set has become the common input to four label regimes — a rare convergence in a fragmented world.

In the EU proper, its role is subtler: it is not harmonised under RED (EN 18031 holds that role) or the CRA, but its substance overlaps both heavily, and it remains the fastest structured way for a consumer-device maker to get their security house in order before formal conformity work begins.

When it's the right tool

The first standard a consumer-device maker should meet

Use it for global consumer reach

Selling into the UK, Singapore, Japan or the US labelling programmes? One 303 645 evidence set, mapped per regime, is the efficient route.

 

Use it as the on-ramp to EU conformity

Meeting 303 645 first makes the EN 18031 and CRA gaps visible and small — the provisions cover much of the same ground in plainer language.

Certify against TS 103 701 when buyers need proof

Retailers and importers increasingly want lab reports, not declarations. The test spec exists precisely so claims can be checked.

Don't stop here for EU market access

303 645 alone gives no presumption of conformity under RED or CRA. It is the foundation of the evidence house, not the roof.

Where it matters

EN 303 645 in your industry

The natural habitat

How 303 645 evidence feeds RED, CRA and the global label web — the full market-access picture for connected products.

Platform support for device claims

SESIP-certified platforms make several 303 645 provisions (secure storage, secure boot, updates) inheritable rather than provable per device.

The root of device trust

Label schemes worldwide are built on this standard — scheme designers and labs scoping TS 103 701 capacity start here.

Operator-branded devices

Routers, set-top boxes and CPE carry operator brands — and operator procurement increasingly demands 303 645 conformity.

Expert notes

What we tell clients before they commit

One evidence set, four regimes: the mapping discipline

The regimes consume the same substance differently: PSTI wants a compliance statement on three provisions with defined support periods; CLS levels 3–4 want lab assessment; JC-STAR has its own conformance labels; the Cyber Trust Mark routes through FCC-recognised administration. The waste we see is per-regime evidence rebuilt from scratch. The fix is a master technical file structured on 303 645 provision numbering with per-regime mapping annexes — build once, extract per market.

Our position: treat the master file as the product asset and each label as a report from it. Mutual recognition between regimes only pays if your evidence was structured to travel.

Defined update support periods are where 303 645-family regimes now bite hardest commercially: PSTI mandates publishing them, CRA demands support commensurate with expected lifetime, and buyers compare the numbers. Committing to a period is a supply-chain commitment — chipset firmware, third-party stacks, cloud dependencies — not a marketing line, and the gap between declared and deliverable is becoming an enforcement surface.

Our position: derive the public support period from a documented component-support analysis before declaring it anywhere. One number, defensible, used in every regime — because regulators are starting to cross-read.

The consumer IoT passport, done once

Provision mapping, TS 103 701 assessment prep, multi-regime label strategy — thirty minutes to a plan.

Contact us

Request this document

We’ll send you access by email.