ETSI EN 303 645
What is ETSI EN 303 645?
ETSI EN 303 645 is the European baseline cyber security standard for consumer Internet of Things (IoT) products. Published by ETSI on cyber security in the consumer IoT space, it sets a baseline of 13 cyber security provisions (clause 5.1-5.13) plus reporting implementation (clause 5.0) and data protection provisions for consumer IoT (clause 6). It comprises 15 controls organised across 2 domains, and applies in the European Union.
How ETSI EN 303 645 maps to other frameworks
All 15 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 2 domains ETSI EN 303 645 groups its controls into
Where ETSI EN 303 645 overlaps with the standards you already hold
What ETSI EN 303 645 means in your sector
What ETSI EN 303 645 means for your job
Questions people ask about ETSI EN 303 645
What is ETSI EN 303 645?
How many controls does ETSI EN 303 645 have?
Where does ETSI EN 303 645 apply?
What frameworks does ETSI EN 303 645 map to?
How do I get started with ETSI EN 303 645 compliance?
Query ETSI EN 303 645 programmatically
ETSI EN 303 645, its 15 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ETSI EN 303 645 API reference and MCP config →How ready are you for ETSI EN 303 645?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.