The appliance is only one part
A connected oven may depend on device firmware, mobile app, account system, cloud API and third-party modules. Security and privacy failures can occur at any link. The commercial owner must know who maintains each component after shipment.
Put lifecycle duties in the RFQ
Define unique credentials or secure onboarding, protection of stored and transmitted data, secure update mechanisms, vulnerability reporting, logging, dependency management, factory-reset behavior and the security-support period. State what happens when cloud service ends and which functions remain locally available.
Treat remote heating as safety-relevant
IEC 60335-2-6:2024 includes requirements relating to remote operation of ovens. Cyber controls do not replace appliance safety controls. Remote commands, status feedback, child access, interrupted connections and failed updates need joint safety and security review.
Use recognized baselines
ETSI EN 303 645 provides baseline security provisions for consumer IoT. The EU Cyber Resilience Act addresses products with digital elements and emphasizes secure design, maintenance and timely updates. Applicability and transition dates should be checked for the exact product and placement date.
- ETSI EN 303 645 information: https://www.etsi.org/newsroom/press-releases/2457-etsi-releases-new-guidelines-to-enhance-cyber-security-for-consumer-iot-devices/
- EU Cyber Resilience Act: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
- IEC 60335-2-6: https://webstore.iec.ch/en/publication/65424

