1 INTRODUCTION 1.0.1 This document aims to provide an overview of Cybersecurity Labelling Scheme (CLS) scheme. It outlines the four (4) tiers of assessment, the conformance checklist, testing activities, acceptance criteria, and the expected deliverables of each of the tiers. 1.0.2 The intended audience for this document is the developers who are interested in getting their Internet-Connected Devices labelled under CLS and testing laboratories who are responsible for testing the devices in accordance to the requirements of the CLS. 1.0.3 This document is organised in the following manner: a. Chapter 2 provides a broad overview of the 4 tiers of assessment required under the different labelling levels of the CLS. b. Chapter 3 elaborates on Assessment Tier 1 – Declaration of Conformance to Security Baseline Requirements. It lists the objective, requirements, and the acceptance criteria. c. Chapter 4 elaborates on Assessment Tier 2 – Declaration of Conformance to Lifecycle Process Requirements. It lists the objective, requirements, and the acceptance criteria. d. Chapter 5 elaborates on Assessment Tier 3 – Software Binary Analysis. It lists the requirements, test scope, pass criteria, and the test deliverables expected by CCC. e. Chapter 6 elaborates on Assessment Tier 4 – Penetration Testing. It lists the requirements, test scope, pass criteria, and the test deliverables expected by CCC. f. Chapter 7 contains the Conformance Checklist that is required for Assessment Tier 1 and 2. 1.0.4 The following roles are commonly referred in this document: 1. Developer of the Device Under Test (DUT) 2. Testing Laboratory (TL) that performs the Assessment Tier 3 and 4 3. Cybersecurity Certification Centre (CCC) that oversees the CLS 1.0.5 The CLS references the following documents: 1. The ETSI EN 303 645 – Cyber Security for Consumer Internet of Things [1] produced by the European Telecommunications Standards Institute (ETSI). The document outlines a set of outcome-focused security provisions to support developers in ensuring that their IoT products are secure by focusing on technical controls and organizational policies that matter most in addressing the most significant and widespread security CLS Publication #2 | Page 4 of 49

Select target paragraph3