Here is the honest situation. ETSI EN 303 645 is the baseline security standard for consumer IoT, and it is becoming the reference for regulation and product-security schemes worldwide. Across thirteen provisions it requires no universal default passwords, a vulnerability disclosure policy, secure and timely software updates with a published support period, secure storage of credentials, encrypted communication, a minimized attack surface, verified software integrity, protection of personal data, resilience to outages, easy data deletion, and an implementation conformance statement. Building those into a product and evidencing them is real work, and a device shipped with a hardcoded default password or no update path is exactly where IoT devices fall short.
This Kit removes that translation. It is every EN 303 645 provision written as an adopt-ready control you personalize in a weekend, with the evidence a conformance assessor examines.
What you get, the moment you buy
Grounded in ETSI EN 303 645, with the thirteen provisions from no universal default passwords and vulnerability disclosure through secure updates, secure storage and communication, attack surface minimization, personal data protection and the implementation conformance statement called out. Editable Word and Excel files.
What one control looks like
This is no universal default passwords and secure authentication, the first provision of the baseline. All 33 are built to this depth.
Why this is not another template pack
- The evidence is the point. A provision you cannot evidence fails conformance. This tells you what an assessor examines and where devices fall short, for every provision.
- Updates, disclosure and secure comms built in. The vulnerability disclosure policy, the secure update mechanism and encrypted communication are written into the controls, the core of the baseline.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. EN 303 645 underpins consumer IoT regulation and product-security schemes and aligns with the EU Cyber Resilience Act, so this work feeds your wider product security program.
Who buys this
Consumer IoT device manufacturers and their product security, engineering and compliance leads. Whether it is a first assessment or a product launch, you save weeks and walk in with the provisions, the implementation conformance statement and evidence structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Does it cover the implementation conformance statement? Yes. Reporting your implementation against the provisions is built as a control, in line with the standard's approach.
Does it cover secure updates? Yes. Secure, authenticated, timely updates and the published support period are their own control group.
Does it help with the Cyber Resilience Act? Yes. EN 303 645 aligns with the CRA essential requirements, so the work is reusable.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com