THREAT BRIEFING · 09.10.2026 DEENFRES

Strategy & Governance

New Security Requirements for the Internet of Things

By Tobias Massow · April 14, 2021 · 7 min read

A German IoT security label based on the ETSI EN 303 645 standard could improve security across the Internet of Things – and boost transparency for consumers, say cybersecurity experts from the eco Association. To ensure this process is fair and transparent, IoT security specialists within the eco Association have formulated five key demands for a secure Internet of Things.

Whether smart door locks, power outlets, refrigerators, or heating systems – billions of devices are connected via the Internet of Things (IoT). While sensors and wireless interfaces enable practical functionality, security often remains an afterthought. Even many security-critical devices – such as surveillance cameras or routers – are poorly protected and lack mechanisms to improve security via firmware updates. If hackers gain access to such devices, they can hijack them into botnets for DDoS attacks – or exploit them to steal private data. For this reason, eco – Association of the German Internet Industry e.V. welcomes the IoT security standard ETSI EN 303 645, published in June 2020 by the ETSI Technical Committee on Cybersecurity (TC CYBER). The standard defines globally binding security requirements and recommendations, test standards, and certification schemes.

TL;DR

“Security by Design” in IoT Is Still Not Standard Practice

“Manufacturers must integrate security considerations right from the development and design stages of new IoT devices,” says Markus Schaffrin, IT security expert and Head of Member Services at the eco Association. “Security by Design and Security by Default are still missing from far too many consumer IoT devices – from smart TVs to heating systems,” Schaffrin adds. Moreover, it remains nearly impossible for consumers to assess how secure – or insecure – their IoT devices truly are.

 

User authentication, software update mechanisms, communication safeguards, and data protection must become standard features. This is precisely the objective of TS 103 701 – the test specification built upon EN 303 645 – which expands the standard with test cases to support a harmonized conformity assessment process and a unified label. TS 103 701 serves as the framework for evaluating compliance with the new standard. The document remains open for public comments until the end of April at the ETSI CYBER Open Drafts portal.

IT Security Act 2.0 to Strengthen IoT Security

IoT devices will be subject to regular security assessments going forward. Source: iStock / hakule

Building on these standards, a German IoT security label is expected to further improve transparency for consumers. Its legal foundation and regulatory framework will be provided by the upcoming IT Security Act 2.0. The BSI (Federal Office for Information Security) should mandate periodic reassessments of products and services bearing the IT security label – to verify that security requirements continue to be met.

 

To ensure this process is fair and transparent, IoT security experts within the eco Association formulated five core demands during a March 2021 roundtable hosted by its IoT and Security competence groups:

 

1.Integrate Existing Labels and Certifications

Certification schemes already established in the market must not be sidelined by the new standard or the planned German IT security label. Vendors must be more actively involved in the process to achieve the goal of a clear, unified testing standard.

 

2.Traceability of the Label

The German IT security label must maintain strong real-world relevance – and be fully traceable for both manufacturers and consumers. Only then can the label evolve into a competitive advantage, gain market acceptance, and instill confidence in users purchasing IoT devices.

 

3.Independent Testing

Independent testing laboratories must assess IoT devices against defined security requirements – especially for the national IT security label. This ensures transparency for consumers, upholds the label’s credibility, and verifies actual compliance with security standards – strengthening trust on both manufacturer and user sides.

 

4.Consider the Full IoT Device Lifecycle

Security must be considered from day one – and embedded directly into IoT device development. Security must be maintained throughout the entire product lifecycle via timely updates. The “Security by Design” principle must be moved earlier into development processes. To build foundational understanding of Security by Design principles, TeleTrust’s guidance document “Security by Design – A Handbook for Decision-Makers” is recommended.

 

5.Enhance Sustainability

Security by Design significantly contributes to IoT device sustainability. With long-term availability of security updates and bug fixes – far beyond what most current devices offer – devices need no longer be prematurely discarded. Legacy devices would cease to pose security risks, and consumers could use their devices much longer – and safely.

 

“While the EN 303 645 standard, TS 103 701, and a future German IT security label point in the right direction, it remains to be seen how implementation and real-world adoption will unfold in the market,” says Schaffrin. The relevant documents are still under coordination and may be reviewed and commented on via the link above – before ratification is expected around mid-2021.

 

 

This article is based on a press release issued by the eco Association of the German Internet Industry.

Key Facts

IoT Attacks: In 2024, attacks targeting IoT devices rose by 400 percent year-on-year.

Unprotected Devices: 57 percent of enterprise IoT devices harbor known vulnerabilities.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Why are IoT devices especially vulnerable to cyberattacks?

Many IoT devices possess limited computing power for security functions, rely on default passwords, receive firmware updates infrequently – if at all – and often remain invisible to security monitoring tools. Basic encryption and authentication mechanisms are frequently absent.

How do you protect an enterprise network from IoT-related risks?

Implement network segmentation (placing IoT devices in dedicated VLANs), apply firmware updates regularly, change all default passwords, monitor IoT traffic, and maintain an up-to-date inventory of all connected devices.

What does the Cyber Resilience Act require of IoT manufacturers?

Starting in 2027, all EU-based manufacturers of connected products must guarantee Security by Design, report vulnerabilities, and provide security updates over the full product lifecycle. Non-compliance may trigger fines of up to 15 million Euro.

Related Articles

More from the MBF Media Network

Digital ChiefsIT Strategies for Decision-Makers at digital-chiefs.deMyBusinessFutureMore IT Security Trends at mybusinessfuture.com

Translated from the German original using artificial intelligence. The German version is authoritative.

Further reading

A magazine by Evernine Media GmbH