days on Freeform Penetration Testing. The objective of this freeform testing is to serve as a feedback loop for the continuous refinement of the minimum test specification so to align with the current threat landscape. 6.3.4 The developer shall facilitate the testing by the testing laboratory. For example, by providing sufficient units of the devices to the testing laboratory and responding to queries. The developer shall note that certain tests might render the device to be unusable (e.g. physically damaged). Device setup and verification of guidance documents 6.3.5 The objective of analysing the guidance document provided alongside the DUT is to ensure that the user guidance does not mislead the user into installing or operating the DUT in an insecure manner, and to minimise the risk of human or other errors in operation that may affect the security of the DUT. 6.3.6 The guidance document (i.e. user manual, installation guide, operation guide, etc.) shall consist of clear steps that guides the end-user to install and operate the DUT in a secure manner. The guidance document shall be written in a manner that is easily understood by the typical user of the DUT. As an example, for a smart home appliance, it can be assumed that the typical user has little to no knowledge of cybersecurity. If the DUT functions are configurable, the guidance document shall indicate secure values as appropriate. The guidance document shall also describe possible modes of operation of the DUT, their consequences and procedures for returning the DUT back into a secure configuration. 6.3.7 The testing laboratory shall examine the guidance document(s) provided to ensure that the guidance document provided meets the requirements stated above. ESTI Conformance Verification 6.3.8 As part of the application, the developer is required to declare against the provisions specified in the checklist and provide evidence and descriptions of how these requirements have been implemented by the device. 6.3.9 The testing laboratory examines that these security measures are indeed being implemented and that such implementation are appropriate to fulfil to the requirements. Scheme-mandated Minimum Test Specifications 6.3.10 In order to ensure consistent penetration testing of connected products across different testing laboratories, minimum test specifications for the different categories of connected products are defined. 6.3.11 The testing laboratory shall ensure that the test objectives in the test specifications are achieved prior to the conduct of independent vulnerability analysis and penetration testing. CLS Publication #2 | Page 16 of 49

Select target paragraph3