7
CONFORMANCE CHECKLIST
7.1.1 The checklist defines the provisions that shall be met at each tier of the CLS. The requirements (and corresponding checklist)
may vary from time-to-time. Developers are encouraged to refer to the latest checklist before applying.
7.1.2 The checklist is intended to be used in tandem with ETSI EN 303 645 – Cyber Security for Consumer Internet of Things [1] and
IMDA IoT Cyber Security Guide [2] published by IMDA. Please refer to the respective documents for the detailed description of
the provisions.
7.1.3 The provisions (5.1-1 to 5.13-1, 6-1 to 6-5) within this document are reproduced from the ETSI EN 303 645 © European
Telecommunications Standards Institute 2020. Further use, modification, copy and/or distribution are strictly prohibited.
7.1.4 The mandatory clauses for each CLS Level are marked in green.
7.1.5 The developer is required to complete and submit the following checklist for all levels for CLS. The developer is required to
declare against ALL clauses even if the clauses may not be mandatory for the level the developer is applying. “M” refers to
Mandatory, whereas “R” refers to “Recommended”. “C” refers to “Conditional” should a dependent provision is being
implemented.
7.1.6 The checklist states the required supporting evidence (to show how the developer fulfils the respective provisions) under the
‘Description of how the provision is fulfilled’ column. Depending on the provisions, the developer shall provide supporting
evidences which can include the following:
•
•
Process-related provisions: Quality manual, process documents, work instructions, checklist, and policy documents
Technical provisions: Technical/design overview/specifications/diagrams, accompanying user guidance documents, user
interface screenshots that helps to depict the implemented technical requirements
7.1.7 The developer is required to note down/state the page number of the content that fulfils the respective points within the provision.
CLS Publication #2 | Page 20 of 49