2 OVERVIEW 2.1 CYBERSECURITY LABELING SCHEME (CLS) 2.1.1 The following table provides an overview of the broad requirements for each labelling level of the CLS. Cybersecurity Levels Level 1 Level 2 Level 3 Level 4 Table 1 - Cybersecurity Levels and Assessment Tiers 3 ASSESSMENT TIER REQUIREMENTS 3.1 OBJECTIVE #1 – SECURITY BASELINE 3.1.1 The objective of this assessment tier is to ensure that the Device Under Test (DUT) conforms to a minimal set of security baseline requirements. 3.1.2 Assessment Tier #1 is based solely on declaration of conformance by the developer. 3.1.3 Devices that have completed Assessment Tier 1 would entail that the developer has taken steps to mitigate against common basic attacks and IoT security problems, namely, avoiding the use of universal default password, by keeping device software updated, and by having a vulnerability disclosure policy to manage vulnerability reporting. 3.2 REQUIREMENTS 3.2.1 Assessment Tier #1 references the set of outcome-focused security categories specified within the ETSI EN 303 645 – Cyber Security for Consumer Internet of Things [1]. 3.2.2 Depending on the level of the Cybersecurity Label that the developer wishes to attain, the number of provisions that are mandatory increases. Non-conformance to provisions categorised as “Mandatory” shall lead to the failure of this activity. CLS No. of Mandatory Format CLS Publication #2 | Page 6 of 49

Select target paragraph3