A connected product is rarely a single test object. The scope covers the hardware (debug and memory interfaces, component population), the firmware (boot chain, file system, embedded secrets), the radio interfaces (including Wi-Fi, Bluetooth Low Energy, Zigbee, Thread, LoRaWAN, cellular and proprietary sub-GHz protocols), the cloud backend with its APIs, and the accompanying mobile or web app. This breakdown is mirrored exactly in the five requirement categories of the OWASP ISVS – IoT Ecosystem, User Space Application, Software Platform, Communication and Hardware Platform. Testing individual layers in isolation typically misses the transitions between them, such as the onboarding of a device into a user account.
IoT Penetration Testing: Attack Surfaces of Connected Devices
Connected products are not pure software systems: they consist of a circuit board, firmware, radio links, a cloud backend and an app. An IoT penetration test examines these layers as a coherent whole – exactly where attackers take hold.
5attack surfaces: board, firmware, radio links, cloud backend, app
13topic areas in the consumer IoT baseline ETSI EN 303 645
9phases in the OWASP FSTM – from information gathering to verification
1device is enough: extracted keys frequently affect the entire fleet
With connected devices, the attack surface is not limited to the network – it extends to the hardware itself: anyone holding a device physically can probe debug interfaces, read out flash memory and analyse the firmware. Credentials or signing keys extracted from a single device frequently affect the entire fleet. Established catalogues exist for structuring such assessments – the OWASP IoT Security Verification Standard (ISVS) for requirements, the OWASP IoT Security Testing Guide (ISTG) for test execution and ETSI EN 303 645 as a baseline for consumer IoT. On the regulatory side, the topic has been binding since August 1, 2025 through the Delegated Act under the Radio Equipment Directive and will be absorbed into the Cyber Resilience Act from December 11, 2027.
From Test Catalogue to Legal Obligation
Five dates set the frame — tap a milestone for details.
Mar 2024
OWASP ISTG 1.0 published
The IoT Security Testing Guide adds a pentest methodology with a device and attacker model plus a test case catalogue – from radio interfaces to the update mechanism.
Jan 2025
EN 18031 listed in the Official Journal
Implementing Decision (EU) 2025/138 lists EN 18031-1, -2 and -3 as harmonised standards – with restrictions, including where users can choose not to set a password; on these points, the presumption of conformity does not apply.
Aug 2025
RED Delegated Act applies
The cybersecurity requirements of Article 3(3) of the Radio Equipment Directive apply – after Delegated Regulation (EU) 2023/2444 postponed the original date by twelve months.
Sep 2026
CRA reporting obligations
From this date, the Cyber Resilience Act's reporting obligations for actively exploited vulnerabilities and severe incidents apply.
Dec 2027
CRA in full, RED DA repealed
The remaining CRA obligations apply; with effect from this date, the Commission has decided to repeal Delegated Regulation (EU) 2022/30 to avoid double regulation.
The Essentials at a Glance
Six topic blocks — tap to expand.
Five Attack Surfaces, One Ecosystem
Each layer maps to an OWASP ISVS requirement category — pick a tab.
- In practice, serial consoles (UART) frequently expose boot logs, bootloader access or an inadequately protected shell.
- Debug interfaces such as JTAG or SWD allow, depending on the controller's lock state, halting the CPU as well as read and write access to memory.
- The assessment checks whether debug ports are disabled or authenticated in production, whether secure boot is enforced and whether sensitive parameters are stored encrypted or in a secure element.
UARTJTAGSWDSPII2CSecure Boot
- Obtained via vendor downloads, captured update processes or a memory dump – followed by static and dynamic analysis.
- Static analysis looks for hard-coded credentials, private keys and outdated components, matched via a software bill of materials (SBOM).
- The OWASP FSTM structures the approach in nine phases; the central test question remains updateability, including downgrade protection.
SBOMFSTMEmulationDowngrade
- In scope are Wi-Fi, Bluetooth Low Energy, Zigbee, Thread, LoRaWAN, cellular and proprietary sub-GHz protocols, among others.
- Testing individual layers in isolation typically misses the transitions between them.
Wi-FiBluetooth Low EnergyZigbeeThreadLoRaWANCellularSub-GHz
- The cloud backend with its APIs is a distinct part of the scope – a connected product is rarely a single test object.
- Typically missed: transitions such as the onboarding of a device into a user account.
APIsOnboarding
- The accompanying mobile or web app belongs to the ecosystem and therefore to the test scope.
- This breakdown is mirrored exactly in the five requirement categories of the OWASP ISVS.
Mobile AppWeb App
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ETSI EN 303 645 V3.1.3 (2024-09), CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements
Current baseline for consumer IoT with 13 topic areas and an additional chapter on data protection provisions; reference for device requirements in the pentest.
ETSI TS 103 701 V2.1.1 (2025-05), Cyber Security (CYBER); Cyber Security for Consumer Internet of Things: Conformance Assessment of Baseline Requirements
Assessment methodology with test cases per provision of EN 303 645; used by the BSI, together with the standard, as the basis for the IT Security Label.
OWASP IoT Security Verification Standard (ISVS), Pre-Release 1.0RC
Requirements catalogue in five categories (IoT Ecosystem, User Space Application, Software Platform, Communication, Hardware Platform); basis for test scope and self-assessment.
OWASP IoT Security Testing Guide (ISTG) 1.0
Pentest methodology with a device and attacker model plus a test case catalogue per device component; published on March 1, 2024.
Delegierte Verordnung (EU) 2022/30 zur Ergänzung der Richtlinie 2014/53/EU
Makes Article 3(3), points (d), (e) and (f) of the Radio Equipment Directive applicable; in effect since August 1, 2025 after postponement by Delegated Regulation (EU) 2023/2444.
Verordnung (EU) 2024/2847 (Cyber Resilience Act)
Annex I requires, among other things, regular security testing and a bill of materials; reporting obligations from September 11, 2026, remaining obligations from December 11, 2027.
Related Services
Putting your connected product to the test?
We map test depth, standards alignment and evidence requirements to your product context – from the circuit board to the cloud backend. Talk to us about an initial consultation.