BSI IT Security Label: testing and evidence for your product
You want to apply for the IT Security Label of the BSI for your product and need traceable evidence? For connected consumer devices, we support you in applying ETSI EN 303 645 and test your device in our BSI evaluation facility.
IT Security Label: orientation for manufacturers of IoT devices.
Your situation
You want to apply for the IT Security Label of the BSI for your product?
With the IT Security Label of the BSI, manufacturers inform users about the security properties of their products and services, such as routers, email services, smartphones or wearables. The requirements depend on the product category. For connected consumer devices (consumer IoT), especially in the smart home sector, the basis is the European standard ETSI EN 303 645 with the test specification ETSI TS 103 701. In the application, you as the manufacturer plausibly demonstrate that your product meets the requirements; the BSI can check compliance on a random or case-by-case basis.
The open questions then usually are: Which requirements affect your device, how do you demonstrate that they are met, and where does development still need to make improvements? If the requirements are taken into account early, costly product changes after the fact can be avoided. If your device has a radio module, the cybersecurity requirements of the RED Delegated Act have also applied since 1 August 2025. According to the BSI, the label already allows you to prepare for the technical requirements of the Cyber Resilience Act.
We test your IoT device in our BSI evaluation facility according to ETSI EN 303 645. You receive a detailed test report containing exactly the evidence for your application to the BSI. Which evaluation is the right one for your product overall, we clarify in our consulting for product manufacturers.
Services & results
Evidence for your IT Security Label application
You know early on which requirements of ETSI EN 303 645 apply to the IT Security Label for your connected consumer device. Our BSI evaluation facility tests your device in the laboratory or via secured remote access, and you receive a detailed test report as evidence for your application to the BSI.
For connected consumer devices, we apply ETSI EN 303 645 to your device and test according to the test specification ETSI TS 103 701. You are responsible for the application and the manufacturer's declaration; our testing provides the technical evidence.
01
Applying the requirements to your device
Together we look at your device, its interfaces and associated services and clarify which requirements of ETSI EN 303 645 apply to the label you are aiming for. The earlier this happens in the development process, the easier it is to add missing security properties.
Test basis for your device
A clearly delimited test object and an agreed test basis.
02
Testing the IoT device
We test how your product meets the agreed requirements and document the findings in a traceable way. Depending on the device, we test in our laboratory or via secured remote access.
03
Test report for your application
We produce a detailed test report for your application. It contains the evidence with which you plausibly demonstrate to the BSI that the requirements are met. Open points show your development team where rework is still needed.
Your test report
A detailed report with the evidence for your application to the BSI for the IT Security Label.
04
Optional: covering RED and CRA as well
If your device has radio components, on request we develop individual test strategies for Article 3(3)(d)–(f) of the Radio Equipment Directive (RED) 2014/53/EU and test radio modules, interfaces and communication paths for vulnerabilities. For the CRA, we check which requirements are still open.
Our expertise
The secuvera evaluation facility was recognised by the BSI in 1992, is the longest-serving evaluation facility in Germany and is accredited by DAkkS (German national accreditation body) as a testing laboratory to ISO/IEC 17025. As a BSZ evaluation facility of the BSI, we are particularly qualified to carry out black-box product evaluations.
We also teach the assessment standards for connected products: the head of our evaluation facility, Sebastian Fritsch, covers ETSI EN 303 645 alongside Common Criteria, BSZ and IEC 62443 in the heise Events training course “Rechtskonform: IT-Produkte prüfen und zertifizieren” (in German).
In addition to the IT Security Label, we test connected products according to RED and CRA requirements and support manufacturers in building internal security testing capabilities.
Getting started
Bringing together product category and technical evidence
Present your product and development status
Bring a description of your IoT device, its interfaces and associated services. We clarify which label you are aiming for and which documents are already available.
Aligning testing and application
We agree on the scope and the required test access. As the manufacturer, you are responsible for the declaration and the application; our testing provides the technical evidence for them.
Evidence according to ETSI EN 303 645, brought together with a clear target.
Manufacturer's declaration and BSI approval
The IT Security Label is not a certificate. The BSI grants approval on the basis of the designated procedure; other product obligations are not replaced by it.
Questions about the IT Security Label of the BSI
Is the IT Security Label a certificate?
No. The label follows its own procedure with a manufacturer's declaration and approval by the BSI. Our technical testing can support the evidence required for this. It replaces neither the approval nor other product obligations.
What does the test report for our label application contain?
It documents the requirements examined and the results of the security testing. This enables you to plausibly demonstrate that the relevant requirements are met. Open points show your development team where rework is still needed.
Should we check the IoT requirements during development?
Early classification can help to identify missing security properties before the application. The later fundamental requirements are taken into account, the more costly product changes can become. We align the right time for testing with your development status.
Does secuvera take over the manufacturer's declaration?
The declaration and the application remain your responsibility as the manufacturer. secuvera provides the agreed technical test evidence. Scope, documents and access are tailored to your device and the desired label.
Which products is the IT Security Label available for?
The BSI awards the IT Security Label for defined product categories, such as routers, email services, smartphones or wearables. Depending on the category, the requirements are based on standards, Technical Guidelines or test specifications. For connected consumer devices, this is ETSI EN 303 645; we test your device according to this standard.