Book an Appointment

IoT Penetration Testing: Attack Surfaces of Connected Devices

Connected products are not pure software systems: they consist of a circuit board, firmware, radio links, a cloud backend and an app. An IoT penetration test examines these layers as a coherent whole – exactly where attackers take hold.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

5attack surfaces: board, firmware, radio links, cloud backend, app
13topic areas in the consumer IoT baseline ETSI EN 303 645
9phases in the OWASP FSTM – from information gathering to verification
1device is enough: extracted keys frequently affect the entire fleet

With connected devices, the attack surface is not limited to the network – it extends to the hardware itself: anyone holding a device physically can probe debug interfaces, read out flash memory and analyse the firmware. Credentials or signing keys extracted from a single device frequently affect the entire fleet. Established catalogues exist for structuring such assessments – the OWASP IoT Security Verification Standard (ISVS) for requirements, the OWASP IoT Security Testing Guide (ISTG) for test execution and ETSI EN 303 645 as a baseline for consumer IoT. On the regulatory side, the topic has been binding since August 1, 2025 through the Delegated Act under the Radio Equipment Directive and will be absorbed into the Cyber Resilience Act from December 11, 2027.

From Test Catalogue to Legal Obligation

Five dates set the frame — tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Five Attack Surfaces, One Ecosystem

Each layer maps to an OWASP ISVS requirement category — pick a tab.

Hardware Platform
  • In practice, serial consoles (UART) frequently expose boot logs, bootloader access or an inadequately protected shell.
  • Debug interfaces such as JTAG or SWD allow, depending on the controller's lock state, halting the CPU as well as read and write access to memory.
  • The assessment checks whether debug ports are disabled or authenticated in production, whether secure boot is enforced and whether sensitive parameters are stored encrypted or in a secure element.
UARTJTAGSWDSPII2CSecure Boot

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ETSI · 2024

ETSI EN 303 645 V3.1.3 (2024-09), CYBER; Cyber Security for Consumer Internet of Things: Baseline Requirements

Current baseline for consumer IoT with 13 topic areas and an additional chapter on data protection provisions; reference for device requirements in the pentest.

ETSI · 2025

ETSI TS 103 701 V2.1.1 (2025-05), Cyber Security (CYBER); Cyber Security for Consumer Internet of Things: Conformance Assessment of Baseline Requirements

Assessment methodology with test cases per provision of EN 303 645; used by the BSI, together with the standard, as the basis for the IT Security Label.

OWASP Foundation · 2020

OWASP IoT Security Verification Standard (ISVS), Pre-Release 1.0RC

Requirements catalogue in five categories (IoT Ecosystem, User Space Application, Software Platform, Communication, Hardware Platform); basis for test scope and self-assessment.

OWASP Foundation · 2024

OWASP IoT Security Testing Guide (ISTG) 1.0

Pentest methodology with a device and attacker model plus a test case catalogue per device component; published on March 1, 2024.

Amtsblatt der EU / EUR-Lex · 2022

Delegierte Verordnung (EU) 2022/30 zur Ergänzung der Richtlinie 2014/53/EU

Makes Article 3(3), points (d), (e) and (f) of the Radio Equipment Directive applicable; in effect since August 1, 2025 after postponement by Delegated Regulation (EU) 2023/2444.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/2847 (Cyber Resilience Act)

Annex I requires, among other things, regular security testing and a bill of materials; reporting obligations from September 11, 2026, remaining obligations from December 11, 2027.

Putting your connected product to the test?

We map test depth, standards alignment and evidence requirements to your product context – from the circuit board to the cloud backend. Talk to us about an initial consultation.