5.4: Securely store sensitive security parameters and the hardware replaceable. 5.3-16: M The model designation of the consumer IoT device shall be clearly recognizable, either by labelling on the device or via a physical interface. 5.4-1: R Sensitive security parameters in persistent storage shall be stored securely by the device. 5.4-2: RC Where a hard-coded (10) unique per device identity is used in a device for security purposes, it shall be implemented in such a way that it resists tampering by means such as physical, electrical or software. 5.4-3: R Hard-coded critical security parameters in device software source code shall not be used. 5.4-4: R Any critical security M M M Supporting evidence shall state where the consumer can find the model designation of the consumer IoT device. R R M Supporting evidence (technical specifications, security architecture, key lifecycle diagrams, etc.) shall describe how the sensitive security parameters are stored and communicated securely. RC (10) RC (10) MC (10) R M M R M M Please also state and list down all sensitive security parameters, hardcoded unique per device identities that are available on the device (stored in firmware, secure storage mechanisms, use of a certified IoT platform, etc.), and the secure storage mechanism used for each of them. CLS Publication #2 | Page 32 of 49

Select target paragraph3