EN 303 645 states outcomes — no universal default passwords, keep software updated, secure communication, minimise attack surfaces, make telemetry transparent — rather than prescribing implementations. That restraint is its genius: it fits a €15 sensor and a €1,500 appliance, and it gave regulators worldwide a ready-made technical floor. The companion TS 103 701 turns the provisions into a lab-executable assessment, which is what separates it from aspirational codes of practice.
Its global footprint is the practical story. The UK’s PSTI regime enforces its top three provisions in law; Singapore’s CLS(IoT) grades products against it across four levels; Japan’s JC-STAR builds on the same base; and the US Cyber Trust Mark’s NIST criteria align closely. With mutual-recognition arrangements between the UK, Singapore and Japan now live, an EN 303 645 evidence set has become the common input to four label regimes — a rare convergence in a fragmented world.
In the EU proper, its role is subtler: it is not harmonised under RED (EN 18031 holds that role) or the CRA, but its substance overlaps both heavily, and it remains the fastest structured way for a consumer-device maker to get their security house in order before formal conformity work begins.