General Information

Abstract

RTS/CYBER-00178

Status
Not Published
Technical Committee
CYBER - Cyber Security
Current Stage
12 - Citation in the OJ (auto-insert)
Due Date
31-Aug-2026
Completion Date
19-Aug-2026

Buy Documents

Standard

ETSI TS 103 815 V2.1.1 (2026-08) - Cyber Security (CYBER); Cyber Security for Consumer Internet of Things; Requirements for Residential Smart Door Locking Devices

English language (29 pages)
sale 15% off
Preview
sale 15% off
Preview

Buy Documents

Standard

ETSI TS 103 815 V2.1.1 (2026-08) - Cyber Security (CYBER); Cyber Security for Consumer Internet of Things; Requirements for Residential Smart Door Locking Devices

English language (29 pages)
sale 15% off
Preview
sale 15% off
Preview

Frequently Asked Questions

ETSI TS 103 815 V2.1.1 (2026-08) is a standard published by the European Telecommunications Standards Institute (ETSI). Its full title is "Cyber Security (CYBER); Cyber Security for Consumer Internet of Things; Requirements for Residential Smart Door Locking Devices". This standard covers: RTS/CYBER-00178

RTS/CYBER-00178

ETSI TS 103 815 V2.1.1 (2026-08) is available in PDF format for immediate download after purchase. The document can be added to your cart and obtained through the secure checkout process. Digital delivery ensures instant access to the complete standard document.

Standards Content (Sample)


TECHNICAL SPECIFICATION
Cyber Security (CYBER);
Cyber Security for Consumer Internet of Things;
Requirements for Residential Smart Door Locking Devices

2 ETSI TS 103 815 V2.1.1 (2026-08)

Reference
RTS/CYBER-00178
Keywords
cybersecurity, IoT, security, smart appliance

ETSI
650 Route des Lucioles
F-06921 Sophia Antipolis Cedex - FRANCE

Tel.: +33 4 92 94 42 00  Fax: +33 4 93 65 47 16

Siret N° 348 623 562 00017 - APE 7112B
Association à but non lucratif enregistrée à la
Sous-Préfecture de Grasse (06) N° w061004871

Important notice
The present document can be downloaded from the
ETSI Search & Browse Standards application.
The present document may be made available in electronic versions and/or in print. The content of any electronic and/or
print versions of the present document shall not be modified without the prior written authorization of ETSI. In case of any
existing or perceived difference in contents between such versions and/or in print, the prevailing version of an ETSI
deliverable is the one made publicly available in PDF format on ETSI deliver repository.
Users should be aware that the present document may be revised or have its status changed,
this information is available in the Milestones listing.
If you find errors in the present document, please send your comments to
the relevant service listed under Committee Support Staff.
If you find a security vulnerability in the present document, please report it through our
Coordinated Vulnerability Disclosure (CVD) program.
Notice of disclaimer & limitation of liability
The information provided in the present deliverable is directed solely to professionals who have the appropriate degree of
experience to understand and interpret its content in accordance with generally accepted engineering or
other professional standard and applicable regulations.
No recommendation as to products and services or vendors is made or should be implied.
No representation or warranty is made that this deliverable is technically accurate or sufficient or conforms to any law
and/or governmental rule and/or regulation and further, no representation or warranty is made of merchantability or fitness
for any particular purpose or against infringement of intellectual property rights.
In no event shall ETSI be held liable for loss of profits or any other incidental or consequential damages.

Any software contained in this deliverable is provided "AS IS" with no warranties, express or implied, including but not
limited to, the warranties of merchantability, fitness for a particular purpose and non-infringement of intellectual property
rights and ETSI shall not be held liable in any event for any damages whatsoever (including, without limitation, damages
for loss of profits, business interruption, loss of information, or any other pecuniary loss) arising out of or related to the use
of or inability to use the software.
Copyright Notification
No part of this document may be reproduced in any form, by any means and in any media, without the prior written
authorization of ETSI and except as expressly permitted below.
By way of exception and when the document is a normative deliverable (European Standard (EN),
Technical Specification (TS), Group Specification (GS) or ETSI Standard (ES)), ETSI authorizes to reproduce
and incorporate into products, services and technical documentation only those extracts (e.g. templates) that are strictly
necessary for the technical implementation of the normative deliverable, to ensure compliance with the latter.
Nothing in this notice shall be construed as limiting any mandatory exceptions to copyright provided by applicable law.

© ETSI 2026.
All rights reserved.
ETSI
3 ETSI TS 103 815 V2.1.1 (2026-08)
Contents
Intellectual Property Rights . 5
Foreword . 5
Modal verbs terminology . 5
Introduction . 5
1 Scope . 7
2 References . 7
2.1 Normative references . 7
2.2 Informative references . 8
3 Definition of terms, symbols and abbreviations . 8
3.1 Terms . 8
3.2 Symbols . 8
3.3 Abbreviations . 8
4 Methodology and general requirements . 9
4.1 Introduction . 9
4.2 Handling of provisions . 9
4.3 Naming conventions . 10
5 Adapted cyber security provisions for Residential Smart Door Locking Devices . 10
5.0 Reporting implementation . 10
5.1 No universal default passwords . 10
5.2 Implement a means to manage reports of vulnerabilities . 11
5.3 Keep software updated . 11
5.4 Securely store sensitive security parameters . 12
5.5 Communicate securely . 12
5.6 Minimize exposed attack surfaces . 12
5.7 Ensure software integrity . 12
5.8 Ensure that personal data is secure . 13
5.9 Make systems resilient to outages . 13
5.10 Examine system telemetry data . 13
5.11 Make it easy for users to delete user data . 13
5.12 Make installation and maintenance of devices easy . 14
5.13 Validate input data. 14
6 Adapted data protection provisions for Residential Smart Door Locking Devices. 14
7 Additional cyber security provisions for Residential Smart Door Locking Devices . 14
7.1 Storing personal data securely . 14
7.2 System failure documentation . 14
7.3 Web and SDL mobile applications . 14
Annex A (informative): Basic concepts, threat models, risk analysis . 15
A.1 Drawing/overview of a Residential Smart Door Locking Devices . 15
A.1.1 General . 15
A.1.2 Interfaces . 15
A.2 Components of a Residential Smart Door Locking Devices solution . 16
A.2.1 Components in a Residential Smart Door Locking Devices . 16
A.2.2 Interfaces . 17
A.3 Use cases/applications . 18
A.4 Threat methodology based on use cases or interface . 19
A.5 Security levels of Smart Door Locking Devices . 19
Annex B (informative): Implementation conformance statement pro forma . 21
ETSI
4 ETSI TS 103 815 V2.1.1 (2026-08)
B.1 The right to copy . 21
B.2 Implementation conformance statement. 21
Annex C (normative): Non-cyber security aspects for Residential Smart Door Locking
Devices . 25
C.1 Mechanical security . 25
C.2 Electromechanical security . 26
C.3 Credential security . 26
Annex D (informative): Bibliography . 28
History . 29

ETSI
5 ETSI TS 103 815 V2.1.1 (2026-08)
Intellectual Property Rights
Essential patents
IPRs essential or potentially essential to normative deliverables (European Standard (EN), Technical Specification (TS),
Group Specification (GS) or ETSI Standard (ES)) may have been declared to ETSI. The declarations pertaining to these
essential IPRs, if any, are publicly available for ETSI members and non-members, and can be found in
ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in
respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the
ETSI IPR online database.
Pursuant to the ETSI Directives including the ETSI IPR Policy, no investigation regarding the essentiality of IPRs,
including IPR searches, has been carried out by ETSI. No guarantee can be given as to the existence of other IPRs not
referenced in ETSI SR 000 314 (or the updates on the ETSI Web server) which are, or may be, or may become,
essential to the present document.
Trademarks
The present document may include trademarks and/or tradenames which are asserted and/or registered by their owners.
ETSI claims no ownership of these except for any which are indicated as being the property of ETSI, and conveys no
right to use or reproduce any trademark and/or tradename. Mention of those trademarks in the present document does
not constitute an endorsement by ETSI of products, services or organizations associated with those trademarks.
DECT™, PLUGTESTS™, UMTS™ and the ETSI logo are trademarks of ETSI registered for the benefit of its
Members. 3GPP™, LTE™ and 5G™ logo are trademarks of ETSI registered for the benefit of its Members and of the
3GPP Organizational Partners. oneM2M™ logo is a trademark of ETSI registered for the benefit of its Members and of ®
the oneM2M Partners. GSM and the GSM logo are trademarks registered and owned by the GSM Association. ®
BLUETOOTH is a trademark registered and owned by Bluetooth SIG, Inc.
Foreword
This Technical Specification (TS) has been produced by ETSI Technical Committee Cyber Security (CYBER).
Modal verbs terminology
In the present document "shall", "shall not", "should", "should not", "may", "need not", "will", "will not", "can" and
"cannot" are to be interpreted as described in clause 3.2 of the ETSI Drafting Rules (Verbal forms for the expression of
provisions).
"must" and "must not" are NOT allowed in ETSI deliverables except when used in direct citation.
Introduction
As more Smart Door Locking Devices (SDLs) in the home connect to the internet, the cyber security of the Internet of
Things becomes a growing concern. People entrust their personal data to an increasing number of online devices and
services. Products and appliances that have traditionally been offline are now connected and need to be designed to
withstand cyber threats.
The present document brings together widely considered good practise in security for Internet-connected consumer
devices in a set of high-level outcome-focused provisions. The objective of the present document is to support all
parties involved in the development and manufacturing of consumer IoT with guidance on securing their products.
ETSI
6 ETSI TS 103 815 V2.1.1 (2026-08)
The present document is a vertical standard of ETSI EN 303 645 [1], which describes and uses a corresponding
methodology to modify existing and add new security and data protection requirements specifically for Residential
Smart Door Locking Devices. The present document also includes reference to security characteristics defined for
building hardware in CEN EN standards.
A separate document will provide guidance on how to assess and assure Residential Smart Door Locking Devices
against provisions within the present document.

ETSI
7 ETSI TS 103 815 V2.1.1 (2026-08)
1 Scope
The present document specifies requirements for consumer residential Smart Door Locking Device (SDL) including
apps:
• cyber security;
• credential related security; and
• electromechanical security and/or mechanical security.
The present document builds on ETSI EN 303 645 [1] for cyber security requirements, adding additional provisions
specific to smart door locking devices.
The present document also builds on other EN standards for credential related security, electromechanical security and
mechanical security.
A description of the basic concepts of Residential Smart Door Locking Devices is given in Annex A.
2 References
2.1 Normative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
Referenced documents which are not found to be publicly available in the expected location might be found in the
ETSI docbox.
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long-term validity.
The following referenced documents are necessary for the application of the present document.
[1] ETSI EN 303 645 (V3.1.3): "CYBER; Cyber Security for Consumer Internet of Things: Baseline
Requirements".
[2] EN 1303:2026: "Building hardware - Cylinders for locks - Requirements and test methods"
(produced by CEN).
[3] EN 1906:2012: "Building hardware - Lever handles and knob furniture - Requirements and test
methods" (produced by CEN).
[4] EN 12209:2024: "Building hardware - Mechanically operated locks and locking plates -
Requirements and test methods" (produced by CEN).
[5] EN 14846:2008: "Building hardware - Locks and latches - Electromechanically operated locks and
striking plates - Requirements and test methods" (produced by CEN).
[6] EN 16867:2020 + Addendum 2:2024: "Building hardware - Mechatronic door furniture -
Requirements and test methods" (produced by CEN).
[7] EN 15684:2020: "Building hardware - Mechatronic cylinders - Requirements and test methods"
(produced by CEN).
[8] EN 15685:2024: "Building hardware - Requirements and test methods - Multipoint locks, latches
and locking plates - Characteristics and test methods".
[9] EN 1627:2021: "Pedestrian doorsets, windows, curtain walling, grilles and shutters - Burglar
resistance - Requirements and classification (produced by CEN)".
ETSI
8 ETSI TS 103 815 V2.1.1 (2026-08)
2.2 Informative references
References are either specific (identified by date of publication and/or edition number or version number) or
non-specific. For specific references, only the cited version applies. For non-specific references, the latest version of the
referenced document (including any amendments) applies.
NOTE: While any hyperlinks included in this clause were valid at the time of publication, ETSI cannot guarantee
their long-term validity.
The following referenced documents may be useful in implementing an ETSI deliverable or add to the reader's
understanding, but are not required for conformance to the present document.
[i.1] ETSI TS 103 645: "CYBER; Cyber Security for Consumer Internet of Things: Baseline
Requirements".
3 Definition of terms, symbols and abbreviations
3.1 Terms
For the purposes of the present document, the terms given in ETSI EN 303 645 [1] and the following apply:
cloud (cloud storage): saves data (coming from SDL) and files in an off-site location
home gateway/router: physical device that lies between the in-home network and the public network with a primary
purpose of managing traffic between these networks
input devices: device that allows a user to interact with the door unit
EXAMPLE: PIN pad, RFID reader or a biometric reader.
NOTE: The input device can be integrated with the door unit or can be a separate device.
SDL back-end on premise: cloud infrastructure (including pc-server, operating systems, pc-storage, etc.) physically
located at the customer site
SDL cloud-backend: function that powers front-end and enables users for making operations/configurations on the
SDL
SDL device: lock used in the context of the Smart Door Lock ecosystem
NOTE: Principles are described in Annex A.
SDL gateway: physical device that lies between the internal network (where SDL is located) and the public network
with a primary purpose of managing traffic between these networks
3.2 Symbols
For the purposes of the present document, the symbols given in ETSI EN 303 645 [1].
3.3 Abbreviations
For the purposes of the present document, the abbreviations given in ETSI EN 303 645 [1] and the following apply:
SDL Smart Door Locking device
ETSI
9 ETSI TS 103 815 V2.1.1 (2026-08)
4 Methodology and general requirements
4.1 Introduction
ETSI EN 303 645 [1] specifies high-level security and data protection provisions for consumer IoT and their
interactions with associated services. Residential Smart Door Locking devices are such consumer IoT devices, but due
to higher safety and security needs there is a need for modifications and new requirements specific for Residential
Smart Door Locking devices.
Therefore, the provisions from ETSI EN 303 645 [1] are adopted using a corresponding methodology, which is
described in clauses 4.2 and 4.3. The provisions are specified in clauses 5 to 7 of the present document.
4.2 Handling of provisions
The present document adopts the provisions of ETSI EN 303 645 [1] as a baseline for the Residential Smart Door
Locking Devices. The methodology used for the adoption is described in the present clause, which includes different
operations to modify provisions from ETSI EN 303 645 [1] and add new provisions specific to the Residential Smart
Door Locking Devices.
All provisions from ETSI EN 303 645 [1] shall apply in the present document, unchanged, to the consumer IoT
device in the Residential Smart Door Locking Devices domain, unless otherwise noted in the present document.
Consumer IoT devices in the Residential Smart Door Locking Devices domain are not constrained devices.
Consequently, all provisions from ETSI EN 303 645 [1] regarding constrained devices are adjusted accordingly.
There are different types of modifications indicated by a naming convention as described in clause 4.3. Within clauses 5
and 6 of the present document, the following modifications can be applied to the set of provisions defined in ETSI
EN 303 645 [1]:
• Information: Providing additional information (in the form of informative text) to an unmodified provision.
The original provision in ETSI EN 303 645 [1] is still valid.
• Promotion: Promoting a recommendation to a mandatory provision. The wording of the provision remains as
in the original provision, but the promoted modal verb is replaced by the new modal verb (e.g. "should" is
replaced by "shall"). The original provision in ETSI EN 303 645 [1] is replaced by the promotion and is not
valid anymore.
• Refinement: Refining a provision with additions or modifications to its normative definition text, including
stronger scoping of conditionality. The original scope and spirit remain in force. The original provision in
ETSI EN 303 645 [1] is replaced by the refinement and is not valid anymore.
NOTE: A refinement can be used to scope the conditionality of a provision, i.e. to remove one or more conditions
from the provision, as part of the clarification on the provision's constraints.
• Extension: Extending an existing provision with one or more new sub-provisions. The original provision in
ETSI EN 303 645 [1] is still valid.
• Substitution: Replacing a recommendation that is not applicable for the Residential Smart Door Locking
Devices with another recommendation of equivalent effect (that provides, possibly in combination with other
recommendations or provisions, the same security outcome as the replaced recommendation). The original
provision in ETSI EN 303 645 [1] is replaced by the substitution and is not valid anymore.
• Exclusion (only possible for recommendations and conditional provisions): Declaring a recommendation or
conditional provision as "not applicable" for the Residential Smart Door Locking Devices. The original
provision in ETSI EN 303 645 [1] is excluded and is not valid anymore.
The present document allows to define new provisions within clause 7 that are not covered in ETSI EN 303 645 [1].
There is one type of new provision, that is also covered by the naming convention in clause 4.3:
• Addition: Defining a new provision specific to the Residential Smart Door Locking Devices that cannot be
linked to any provision in ETSI EN 303 645 [1].
ETSI
10 ETSI TS 103 815 V2.1.1 (2026-08)
4.3 Naming conventions
The provisions in the present document are named following the naming conventions described in the present clause.
Each provision contains an acronym representing the Residential Smart Door Locking Devices. The acronym for the
Residential Smart Door Locking Devices is set to "SDL".
Names for provisions that are specific to the present document are constructed as follows:
• The name starts with the string "Provision" to which the acronym "SDL" is appended.
• A provision identifier (id) is appended. An example id is 5.1-1.
• One or more suffixes are appended (according to the types of provisions as described in clause 4.2).
NOTE: A provision can be at the same time promoted and refined, in which case the two suffixes are appended to
its name.
• For provisions that are extensions, an alphabetical index is appended, that is unique to the provision, for
example, "-a". The alphabetical index is appended only in cases where there is more than one extension to a
given provision.
The following list describes the suffixes depending on the type of the provision as described in clause 4.2:
• Information: The id is the id of the original provision in ETSI EN 303 645 [1] additional informative
information is provided for. The suffix is "(information)".
• Promotion: The id is the id of the original provision in ETSI EN 303 645 [1] that is promoted. The suffix is
"(promoted)".
• Refinement: The id is the id of the original provision in ETSI EN 303 645 [1] that is refined. The suffix is
"(refined)".
• Extension: The id is the id of the original provision in ETSI EN 303 645 [1] that is extended. The suffix is
"(extended)".
• Substitution: The id is the id of the original provision in ETSI EN 303 645 [1] that is substituted. The suffix is
"(substituted)".
• Exclusion: The id is the id of the original provision in ETSI EN 303 645 [1] that is excluded. The suffix is
"(excluded)".
• Addition: The id is a new and unique id added in clause 7 that reflects the clause in which it is defined. The
suffix is "(added)".
5 Adapted cyber security provisions for Residential
Smart Door Locking Devices
5.0 Reporting implementation
Provision SDL 5.0-1 (extended): A justification shall be recorded for each recommendation in the present document
that is considered to be not applicable for or not fulfilled by the SDL device.
5.1 No universal default passwords
Existing provisions from ETSI EN 303 645 [1], clause 5.1 are modified as follows:
Provision SDL 5.1-5 (refined): The SDL device shall have a mechanism available which makes successful brute force
attacks on authentication mechanisms via network interfaces impracticable.
ETSI
11 ETSI TS 103 815 V2.1.1 (2026-08)
EXAMPLE 1: The SDL device limits the number of authentication attempts within a certain time interval.
EXAMPLE 2: The SDL device introduces a delay after a failed authentication attempt. The delay increases after
each subsequent failed authentication attempt.
5.2 Implement a means to manage reports of vulnerabilities
Existing provisions from ETSI EN 303 645 [1], clause 5.2 are modified as follows:
Provision SDL 5.2-2 (promoted) (information): Disclosed vulnerabilities shall be acted on in a timely manner.
NOTE: The manufacturer's policy provides the corresponding information.
EXAMPLE 1: The timeline for acting on a vulnerability can depend on factors such as the type of product, the
risk associated with the vulnerability, and the complexity of the mitigation plan.
Provision SDL 5.2-3 (promoted): Manufacturers shall continually monitor for, identify and rectify security
vulnerabilities within the SDL Device and security relevant SDL services they sell, produce, have produced and
services they operate during the defined support period.
EXAMPLE 2: The manufacturer performs security tests and vulnerability scans against public vulnerability
databases for devices, mobile apps and web services. This includes third party components used in
the product.
5.3 Keep software updated
Existing provisions from ETSI EN 303 645 [1], clause 5.3 are modified as follows:
Provision SDL 5.3-1 (promoted): All software components in SDL devices that are not immutable due to security
reasons shall be securely updateable.
Provision SDL 5.3-1 (extended)-a: All security relevant associated services of the SDL in control of the device
manufacturer shall be kept up to date.
Provision SDL 5.3-1 (extended)-b: An update of the SDL device shall not change the locking status of the SDL
device.
NOTE: A lock which was closed before an update is still closed during and after an update, unless changed by an
authorized user
Provision SDL 5.3-2 (excluded): The provision is covered by Provision SDL 5.3-1 (promoted) and shall not apply.
Provision SDL 5.3-6B (extended): The user shall have the option to be notified of updates for SDL mobile application.
Provision SDL 5.3-7 (extended)-a: The order of the algorithms offered in an algorithm negotiation should follow best
practice cryptography.
Provision SDL 5.3-7 (extended)-b: The SDL device shall prevent the installation of update versions older than the
currently installed version.
Provision SDL 5.3-9 (promoted): The SDL device shall verify the authenticity and integrity of software updates.
Provision SDL 5.3-12 (promoted): The SDL device shall notify the user when the application of a software update
will disrupt the basic functioning of the SDL device.
Provision SDL 5.3-12 (extended)-a: The notification shall include information about the criticality of the update, the
impact on the functioning of the SDL device, and the expected duration of the disruption.
Provision SDL 5.3-12 (extended)-b: The notification shall be displayed to the user in a recognizable and apparent
manner.
EXAMPLE: The notification is visible on a web interface or mobile app.
ETSI
12 ETSI TS 103 815 V2.1.1 (2026-08)
Provision SDL 5.3-12 (extended)-c: When the application of a software update will disrupt the basic functioning of the
SDL device, the user should be informed about the approximate expected duration for which the device will be offline.
Provision SDL 5.3-14 (excluded): The provision is not applicable for the Residential Smart Door Locking Devices and
shall not apply.
Provision SDL 5.3-15A (excluded): The provision is not applicable for the Residential Smart Door Locking Devices
and shall not apply.
Provision SDL 5.3-15B (excluded): The provision is not applicable for the Residential Smart Door Locking Devices
and shall not apply.
5.4 Securely store sensitive security parameters
Existing provisions from ETSI EN 303 645 [1], clause 5.4 are modified as follows:
Provision SDL 5.4-1 (information): Sensitive security parameters that are used for locking or unlocking need a secure
storage.
5.5 Communicate securely
Existing provisions from ETSI EN 303 645 [1], clause 5.5 are modified as follows:
Provision SDL 5.5-1 (extended)-a: The communications between separate components of a SDL device shall be
encrypted and authenticated using best practice cryptography.
Provision SDL 5.5-1 (extended)-b: The communications between a SDL device and its associated services shall be
encrypted and authenticated using best practice cryptography.
Provision SDL 5.5-5 (information): Enabling, disabling or postponing installation of security updates and changes in
audit trail is a security-relevant change.
5.6 Minimize exposed attack surfaces
Existing provisions from ETSI EN 303 645 [1], clause 5.6 are modified as follows:
Provision SDL 5.6-3 (promoted): SDL device hardware shall not unnecessarily expose physical interfaces to attack.
NOTE: See Annex C.
Provision SDL 5.6-5 (promoted): The manufacturer shall only enable software services that are used or required for
the intended use or operation of the SDL device.
Provision SDL 5.6-7 (promoted): Software on the SDL Device shall run with least necessary privileges, taking
account of both security and functionality.
Provision SDL 5.6-8 (promoted): The SDL device shall include a hardware-level access control mechanism for
memory.
Provision SDL 5.6-9 (promoted): The manufacturer shall follow secure development processes for software deployed
on the SDL device.
5.7 Ensure software integrity
No modifications to the provisions from ETSI EN 303 645 [1], clause 5.7 are defined in the present document.
ETSI
13 ETSI TS 103 815 V2.1.1 (2026-08)
5.8 Ensure that personal data is secure
Existing provisions from ETSI EN 303 645 [1], clause 5.8 are modified as follows:
Provision SDL 5.8-1 (promoted) (refined): The confidentiality of personal data transiting between a SDL device and a
service, especially associated services, shall be protected, with best practice cryptography, appropriate to the properties
of the technology, operating environment, risk and usage.
Provision SDL 5.8-2 (information): SDL device audit logs are sensitive personal data.
Provision SDL 5.8-2 (extended)-a: The confidentiality of audit logs communicated between the SDL device and
associated services shall be protected by end-to-end encryption, appropriate to the properties of the technology,
operating environment, risk and usage.
5.9 Make systems resilient to outages
Existing provisions from ETSI EN 303 645 [1], clause 5.9 are modified as follows:
Provision SDL 5.9-1 (extended)-a: It shall be possible for the user to lock or unlock the SDL device in the event of a
loss of power.
EXAMPLE: The SDL device could operate on battery power or have a mechanical means to lock or unlock.
Provision SDL 5.9-1 (extended)-b: The SDL device shall operate in a defined state after a denial of service attack.
Provision SDL 5.9-1 (extended)-c: A DoS attack shall not change the locking status of the device.
NOTE: A lock which is closed before a DoS attack is still closed during and after the DoS attack, unless changed
by an authorized user.
Provision SDL 5.9-1 (extended)-d: In the case where the SDL device is permanently and directly connected to a
network, it shall locally store all data that it usually transmits through the network during a power loss of the network
and send this locally stored information once it regains network connectivity.
Provision SDL 5.9-2 (promoted) (refined): The SDL device shall remain operating and locally functional in the case
of a loss of network access and shall recover cleanly in the case of restoration of a loss of power.
Provision SDL 5.9-2 (information): Remaining operating and locally functional as well as recovering cleanly includes
the locking status of the lock to persist during outage of network or power in the status as it was before, unless changed
by an authorized user.
5.10 Examine system telemetry data
Existing provisions from ETSI EN 303 645 [1], clause 5.10 are modified as follows:
Provision SDL 5.10-1 (promoted) (refined): If telemetry data is collected from SDL device and services, such as
usage and measurement data, it shall be examined for security anomalies.
5.11 Make it easy for users to delete user data
Existing provisions from ETSI EN 303 645 [1], clause 5.11 are modified as follows:
Provision SDL 5.11-1 (substituted): The user shall be provided with functionality such that personal user data, except
for data required for security purposes including immutable audit logs, can be erased from the device in a simple
manner.
NOTE: Normal individual users that are authorized to unlock the door may not have the possibility to erase
themselves from all memories and databases because of immutable audit trail.
Provision SDL 5.11-3 (promoted): Users shall be given clear instructions on how to delete and where possible to erase
their personal data from the SDL device and associated services.
ETSI
14 ETSI TS 103 815 V2.1.1 (2026-08)
Provision SDL 5.11-4 (promoted): Users shall be provided with clear confirmation that personal data has been deleted
and where possible erased from services, devices and applications.
5.12 Make installation and maintenance of devices easy
Existing provisions from ETSI EN 303 645 [1], clause 5.12 are modified as follows:
Provision SDL 5.12-1 (information): Security best practice includes specifying default options that are appropriately
secure.
Provision SDL 5.12-2 (promoted): The manufacturer shall provide users with guidance on how to securely set up their
SDL device.
Provision SDL 5.12-2 (extended): Security options shall be explained during the installation procedure itself with all
advantages and disadvantages.
Provision SDL 5.12-3 (promoted): The manufacturer shall provide users with guidance on how to check whether their
SDL device is securely set up and maintained in a secure state.
5.13 Validate input data
No modifications to the provisions from ETSI EN 303 645 [1], clause 5.13 are defined in the present document.
6 Adapted data protection provisions for Residential
Smart Door Locking Devices
Existing provisions from ETSI EN 303 645 [1], clause 6 are modified as follows:
Provision 6-2 (extended): Collection and processing of telemetry data from the SDL device and services shall be based
on the user's consent.
7 Additional cyber security provisions for Residential
Smart Door Locking Devices
7.1 Storing personal data securely
Provision SDL 7.1-1 (added): Personal data in persistent storage of the SDL shall be stored securely by the device.
Provision SDL 7.1-2 (added): Personal data stored by the SDL and/or associated services shall only be accessible by
an authorized entity.
7.2 System failure documentation
Provision SDL 7.2-1 (added): Network and power losses shall be documented.
NOTE: Audit trail can be considered.
7.3 Web and SDL mobile applications
Provision SDL 7.3-1 (added): The manufacturer should follow the latest version of OWASP security verification
standard for web and SDL mobile applications.
ETSI
15 ETSI TS 103 815 V2.1.1 (2026-08)
Annex A (informative):
Basic concepts, threat models, risk analysis
A.1 Drawing/overview of a Residential Smart Door
Locking Devices
A.1.1 General
Residential Smart Door Locking Device is a lock designed to perform locking and unlocking a door when it receives
such instructions from an authorized device using a wireless protocol and cryptographic key to execute the
authorization process. Principles are described in Figure A.1.
A.1.2 Interfaces
Smart Door Locking Devices interfaces are in principle described in Figure A.1.

Figure A.1: Smart Door Locking Device interfaces
ETSI
16 ETSI TS 103 815 V2.1.1 (2026-08)
A.2 Components of a Residential Smart Door Locking
Devices solution
A.2.1 Components in a Residential Smart Door Locking Devices
Typical components in a smart door locking solutions:
Door Unit/Smart Door Actuator: Enables the opening mechanism of a door lock. This can be a motor driving a key, a
thumb-turn or a clutch mechanism enabling the usage of the door handle or another opening element. The actuator gets
controlled by the door unit where the decision is taken to change the status of the lock.
Mobile Phone App (input devices): Application allows the user to interact with the Door unit. This can be commands
to change the status of the door (will activate the actuator) or for settings of the Smart Door Locking Device (like door
opening time, Autolock/unlock features, etc.).
Often is the user management also handled in the application (add user, delete user, send invitation to guest, etc.).
The communication between the mobile applications can be done via different protocols/interfaces. This can be
® ® ®
Bluetooth , NFC or Wi-Fi .
SDL Backend-Cloud: Server application allows the user(s) to store their user account details and settings/information
about one or multiple Smart Door Locking Devices dedicated to this user. The backend (cloud) is normally where a so
called cloud-to-cloud integration is made with another system, as an enabler. It is however, typically a decision made by
the SDL owner to activate such an integration or not.
The backend is also typically the source for providing new firmware for the SDL (also known as Firmware Over The
Air, (FOTA)).
It is also used for remote commands when the Door Unit has a connection to the backend. The connection can be made ®
via the mobile phone or via Wi-Fi with or without a bridge (depending on the capability of the door unit).
Differently from the cloud (storage), backend cloud enables users (owners of the SDL etc) to operate/configurate the
SDL.
Reading device (Input device): A reading device can be a PIN pad, RFID reader, Biometric reader or any devices
which allows the user to present a credential (non-mechanical key). The reading device may be integrated with the Door
Unit, or may be an entirely separate device that communicates with the door unit. This can be done wired or wireless.
Depending of the features of the Door Unit, and how it has been setup, it may (with a greater or lesser certainty) be used
to identify the user of such credential.
Gateway: Although often not strictly necessary for basic functionality, frequently to enjoy the full feature set
experience of an SDL, the user will benefit from a bridge device. For all remote use-cases (when the user is further
away from their SDL than the aforementioned radios will reach), or when additional features rely on backend (cloud) to
fulfil on their promise.
A bridge/gateway simply assists in bringing the SDL on-line and available to communicate with. With the exception of ®
SDLs with integrated Wi-Fi , all other radio technologies typically need to be transcoded (bridged) between the radio
technology used by the SDL and (most typically) the home Access Point (also known as internet router). This is true for
® ® ®
BLE, Zigbee , Z-Wave or other proprietary radios, all needing to transmit via Wi-Fi to the home Access Point. NFC
is so short range that it does not lend itself for this use-case.
Cloud storage: it saves data and files in an off-site location. It can be accessed through the public internet. Data
transferred in the off-site storage becomes the responsibility of a third-party cloud provider. The provider hosts, secures,
manages, and maintains the servers and associated infrastructure and ensures (usually guaranteeing a certain
QoS-Quality of service) the access to the data whenever it is needed.
Home Gateway/Router: It manages the data/traffic coming from the in-home networks (e.g. LAN) delivering the
data/traffic to the public networks (e.g. WAN). Typically, it has a dedicated software (firewall or similar) to protect
LAN from external cyber-attacks (possible coming from WAN).
ETSI
17 ETSI TS 103 815 V2.1.1 (2026-08)
SDL Back-end on Premise: Usually it is used on dedicated appliances, for instance wher
...