New Security Requirements for the Internet of Things
A German IoT security label based on the ETSI EN 303 645 standard could improve security across the Internet of Things – and boost transparency for consumers, say cybersecurity experts from the eco Association. To ensure this process is fair and transparent, IoT security specialists within the eco Association have formulated five key demands for a secure Internet of Things.
Whether smart door locks, power outlets, refrigerators, or heating systems – billions of devices are connected via the Internet of Things (IoT). While sensors and wireless interfaces enable practical functionality, security often remains an afterthought. Even many security-critical devices – such as surveillance cameras or routers – are poorly protected and lack mechanisms to improve security via firmware updates. If hackers gain access to such devices, they can hijack them into botnets for DDoS attacks – or exploit them to steal private data. For this reason, eco – Association of the German Internet Industry e.V. welcomes the IoT security standard ETSI EN 303 645, published in June 2020 by the ETSI Technical Committee on Cybersecurity (TC CYBER). The standard defines globally binding security requirements and recommendations, test standards, and certification schemes.
TL;DR
- A German IoT security label based on the ETSI EN 303 645 standard could improve IoT security and enhance transparency for consumers, experts say…
- …the IoT security standard ETSI EN 303 645, published in June 2020 by the ETSI Technical Committee on Cybersecurity (TC CYBER).
- This is also the goal of the test specification TS 103 701 – built upon EN 303 645 – which extends the standard with concrete test cases to enable a harmonized testing procedure and a uniform label.
- The TS 103 701 document is currently in its public comment phase until the end of April and remains open for proposals and revisions.
“Security by Design” in IoT Is Still Not Standard Practice
“Manufacturers must integrate security considerations right from the development and design stages of new IoT devices,” says Markus Schaffrin, IT security expert and Head of Member Services at the eco Association. “Security by Design and Security by Default are still missing from far too many consumer IoT devices – from smart TVs to heating systems,” Schaffrin adds. Moreover, it remains nearly impossible for consumers to assess how secure – or insecure – their IoT devices truly are.
User authentication, software update mechanisms, communication safeguards, and data protection must become standard features. This is precisely the objective of TS 103 701 – the test specification built upon EN 303 645 – which expands the standard with test cases to support a harmonized conformity assessment process and a unified label. TS 103 701 serves as the framework for evaluating compliance with the new standard. The document remains open for public comments until the end of April at the ETSI CYBER Open Drafts portal.
IT Security Act 2.0 to Strengthen IoT Security
IoT devices will be subject to regular security assessments going forward. Source: iStock / hakule
Building on these standards, a German IoT security label is expected to further improve transparency for consumers. Its legal foundation and regulatory framework will be provided by the upcoming IT Security Act 2.0. The BSI (Federal Office for Information Security) should mandate periodic reassessments of products and services bearing the IT security label – to verify that security requirements continue to be met.
To ensure this process is fair and transparent, IoT security experts within the eco Association formulated five core demands during a March 2021 roundtable hosted by its IoT and Security competence groups:
1.Integrate Existing Labels and Certifications
Certification schemes already established in the market must not be sidelined by the new standard or the planned German IT security label. Vendors must be more actively involved in the process to achieve the goal of a clear, unified testing standard.
2.Traceability of the Label
The German IT security label must maintain strong real-world relevance – and be fully traceable for both manufacturers and consumers. Only then can the label evolve into a competitive advantage, gain market acceptance, and instill confidence in users purchasing IoT devices.
3.Independent Testing
Independent testing laboratories must assess IoT devices against defined security requirements – especially for the national IT security label. This ensures transparency for consumers, upholds the label’s credibility, and verifies actual compliance with security standards – strengthening trust on both manufacturer and user sides.
4.Consider the Full IoT Device Lifecycle
Security must be considered from day one – and embedded directly into IoT device development. Security must be maintained throughout the entire product lifecycle via timely updates. The “Security by Design” principle must be moved earlier into development processes. To build foundational understanding of Security by Design principles, TeleTrust’s guidance document “Security by Design – A Handbook for Decision-Makers” is recommended.
5.Enhance Sustainability
Security by Design significantly contributes to IoT device sustainability. With long-term availability of security updates and bug fixes – far beyond what most current devices offer – devices need no longer be prematurely discarded. Legacy devices would cease to pose security risks, and consumers could use their devices much longer – and safely.
“While the EN 303 645 standard, TS 103 701, and a future German IT security label point in the right direction, it remains to be seen how implementation and real-world adoption will unfold in the market,” says Schaffrin. The relevant documents are still under coordination and may be reviewed and commented on via the link above – before ratification is expected around mid-2021.
This article is based on a press release issued by the eco Association of the German Internet Industry.
Key Facts
IoT Attacks: In 2024, attacks targeting IoT devices rose by 400 percent year-on-year.
Unprotected Devices: 57 percent of enterprise IoT devices harbor known vulnerabilities.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Why are IoT devices especially vulnerable to cyberattacks?
Many IoT devices possess limited computing power for security functions, rely on default passwords, receive firmware updates infrequently – if at all – and often remain invisible to security monitoring tools. Basic encryption and authentication mechanisms are frequently absent.
How do you protect an enterprise network from IoT-related risks?
Implement network segmentation (placing IoT devices in dedicated VLANs), apply firmware updates regularly, change all default passwords, monitor IoT traffic, and maintain an up-to-date inventory of all connected devices.
What does the Cyber Resilience Act require of IoT manufacturers?
Starting in 2027, all EU-based manufacturers of connected products must guarantee Security by Design, report vulnerabilities, and provide security updates over the full product lifecycle. Non-compliance may trigger fines of up to 15 million Euro.
Related Articles
- Cybersecurity Trends 2026: The 7 Most Important Developments for Enterprises
- Cybersecurity 2025: A Year in Review – Incidents, Trends, Lessons Learned
- Post-Quantum Cryptography: Why Companies Must Act Now
More from the MBF Media Network