5.5: Communicate securely parameters used for integrity and authenticity checks of software updates and for protection of communication with associated services in device software shall be unique per device and shall be produced with a mechanism that reduces the risk of automated attacks against classes of devices. 5.5-1: The consumer IoT device shall use best practice cryptography to communicate securely. 5.5-2: The consumer IoT device should use reviewed or evaluated implementations to deliver network and security functionalities, particularly in the field of cryptography. 5.5-3: Cryptographic algorithms and primitives should be updateable. R R R M R R R R R R R R Supporting evidence shall describe how the device communicates securely and state the best practice cryptography standards/guidelines that were referenced (if used). Supporting evidence shall list all reviewed or evaluated cryptographic implementations used for network and security functionalities. Supporting evidence shall describe how the cryptographic algorithms and primitives used are updateable (e.g., the cryptographic library and algorithms CLS Publication #2 | Page 33 of 49

Select target paragraph3