ETSI EN 303 645: what it asks of a product list
The consumer IoT baseline standard behind the PSTI regime's deemed-compliance route. Held here at provision-group level (5.0 to 5.13 and 6): the provisions are cited by group, not one by one, and no individual provision is stated.
The provisions are cited by group (5.1, 5.2, 5.3, 5.7), never one by one; the individual provisions are not stated here.
Duties by role
| Role | Clauses |
|---|---|
| manufacturer | ETSI EN 303 645 5.1 (provision group) No universal default passwords ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilities ETSI EN 303 645 5.3 (provision group) Keep software updated |
| importer | none here |
| distributor | none here |
| own brand (becomes the manufacturer) | ETSI EN 303 645 5.1 (provision group) No universal default passwords ETSI EN 303 645 5.2 (provision group) Implement a means to manage reports of vulnerabilities ETSI EN 303 645 5.3 (provision group) Keep software updated |
Notes that cite it
| Note | Clause |
|---|---|
| 5. No support period stated, or under five years with no reason recorded | ETSI EN 303 645 5.3 (provision group) ETSI EN 303 645 5.7 (provision group) |
| 6. A universal default password | ETSI EN 303 645 5.1 (provision group) |
| 7. No published vulnerability contact | ETSI EN 303 645 5.2 (provision group) |
| 8. No security update mechanism, or unsigned updates | ETSI EN 303 645 5.3 (provision group) ETSI EN 303 645 5.7 (provision group) |
ETSI EN 303 645: every clause cited
4 of the 15 heldThe requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.
ETSI EN 303 645 5.1 (provision group)No universal default passwordsWhere passwords are used and in any state other than the factory default, all consumer IoT device passwords shall be unique per device or defined by the user. Pre-installed unique per-device passwords shall be generated by a mechanism that reduces the risk of automated attacks against a class or type of device.
ETSI EN 303 645 5.2 (provision group)Implement a means to manage reports of vulnerabilitiesThe manufacturer shall make available to the public a vulnerability disclosure policy, including a contact for the disclosure of vulnerabilities and an acknowledgement timeline; received reports shall be acted on within a reasonable time, with status updates to the reporter.
ETSI EN 303 645 5.3 (provision group)Keep software updatedSoftware components in consumer IoT devices shall be securely updateable; the manufacturer shall publish a defined support period during which security updates are provided; updates shall be timely and shall not adversely affect the function of the device. Where the device is not updateable, the rationale, replacement period and disposal information shall be published.
ETSI EN 303 645 5.7 (provision group)Ensure software integrityConsumer IoT devices shall verify their software using secure boot mechanisms, and a verifiable record shall be available. If an unauthorised change is detected, the device shall alert and limit functionality.