What it means
EN 303 645 is not a market access requirement by itself, but several national schemes and retailer requirements use it as the reference. Compliance is usually evidenced by a test report against the provisions plus the corresponding data protection guidance.
Applies to
- Consumer IoT devices such as cameras, hubs and sensors
- Companion mobile apps and cloud services
- Manufacturers designing a security baseline programme
What it does not cover
- Industrial or medical device security requirements
- Full ISO 27001 style management system certification
- Legal data protection compliance
Verification checklist
- Eliminate universal default passwords and enforce unique credentials
- Provide a vulnerability disclosure contact and process
- Publish a support period and update policy
- Secure sensitive data in transit and at rest
- Test the device against the thirteen provisions