iot security standards

IoT Security Standards: A Guide to Compliance for Smart Buildings

IOT6 mins

For many years, the Internet of Things operated much like the Wild West. Manufacturers rushed to get smart sensors and connected devices to market as quickly and cheaply as possible. Security was rarely a priority. This led to a landscape filled with vulnerable devices, resulting in high-profile cyber attacks that compromised entire corporate networks.

Thankfully, those days are coming to an end. Governments and international regulatory bodies have stepped in, creating strict IoT security standards that mandate how devices must be built, deployed, and maintained.

For IT directors, facilities managers, and commercial real estate developers, understanding these standards is no longer optional. Deploying non-compliant hardware can result in hefty fines, voided insurance policies, and catastrophic data breaches.

At Concept13, we navigate this complex regulatory landscape daily. When we deploy commercial LoRaWAN networks, we ensure every piece of hardware and every stream of data meets the highest international benchmarks. If you are planning an IoT rollout, this guide breaks down the essential security standards you need to know.

The Quick Answer

What are the main IoT security standards businesses need to follow? In the UK and Europe, commercial IoT deployments are governed by several key pieces of legislation and industry frameworks.

  • UK PSTI Act: The UK law that bans universal default passwords and mandates transparent software update policies.

  • ETSI EN 303 645: The gold standard European baseline for IoT security, focusing on secure communication and data protection.

  • ISO/IEC 27400: The international standard specifically providing guidelines for IoT security and privacy within enterprise environments.

  • NIST IR 8259: The US government framework that heavily influences global enterprise IT policies regarding connected devices.

security standards uk

1. The Legal Baseline: The UK PSTI Act

In the United Kingdom, IoT security is now a matter of law. The Product Security and Telecommunications Infrastructure (PSTI) Act was designed to stop the flood of insecure devices entering the market. While heavily focused on consumer goods, it sets a hard baseline that bleeds directly into commercial procurement.

The PSTI Act enforces three critical rules for any connected device sold in the UK.

  • No Default Passwords: The days of unpacking a hundred sensors that all share the password “admin” are over. Every device must have a unique password out of the box, or it must force the user to create a strong password upon activation.

  • Vulnerability Disclosure Policy: Manufacturers must provide a public point of contact so that security researchers can report flaws and bugs easily.

  • Transparent Update Periods: The manufacturer must explicitly state the minimum length of time the device will receive vital security updates.

The Business Value: If your procurement team buys cheap, unbranded sensors online that do not comply with the PSTI Act, your business is introducing illegal and inherently insecure hardware into your corporate environment.

2. The European Standard: ETSI EN 303 645

If the PSTI Act is the legal floor, the European Telecommunications Standards Institute (ETSI) provides the technical blueprint. ETSI EN 303 645 is widely considered the most important foundational standard for IoT security globally.

It provides 13 specific provisions that manufacturers and system integrators must follow to achieve a “secure by design” network. The most relevant for commercial buildings include the following.

  • Keep Software Updated: Devices must support secure, over-the-air (OTA) firmware updates. If a vulnerability is found in a deployed temperature sensor, you must be able to patch it remotely without physically touching the device.

  • Communicate Securely: All telemetry data must be encrypted in transit. A sensor should never broadcast plaintext data that could be intercepted by a bad actor sitting in your car park.

  • Ensure Software Integrity: Devices must use secure boot mechanisms to ensure that malicious code has not been loaded onto the hardware.

legal baseline and European standard

3. Enterprise Frameworks: ISO/IEC 27400 and NIST

For large enterprises, hospitals, and national retailers, IoT security must integrate seamlessly with their broader IT security policies.

ISO/IEC 27400 is an extension of the famous ISO 27001 information security standard. It provides specific guidelines on managing the lifecycle of IoT systems. It forces organisations to think about the entire journey of a sensor, from secure provisioning and daily monitoring to safe decommissioning and data wiping when the device is retired.

Similarly, the NIST (National Institute of Standards and Technology) frameworks provide rigorous guidelines on how to isolate IoT networks from critical corporate infrastructure. They emphasise “Zero Trust” architecture, meaning an IoT device is never inherently trusted simply because it is connected to the network.

4. How Concept13 and LoRaWAN Guarantee Compliance

Navigating these standards can feel overwhelming. The easiest way to ensure compliance is to choose a network protocol that has security baked into its core DNA, rather than trying to patch security onto a vulnerable Wi Fi network.

When Concept13 deploys a commercial network, we utilise LoRaWAN technology. The LoRaWAN specification natively addresses the strictest requirements of ETSI, ISO, and NIST.

  • Mutual Authentication: Before a LoRaWAN sensor is allowed to join the network, both the device and the network must cryptographically prove their identities to each other. This prevents rogue devices from connecting.

  • Mandatory AES Encryption: LoRaWAN uses two separate layers of AES 128-bit encryption. The network layer ensures the connection is secure, while the application layer ensures the actual data payload remains encrypted until it reaches your specific dashboard.

  • Physical Network Isolation: Because LoRaWAN operates on a completely different frequency to your corporate Wi Fi, it satisfies the strict IT requirement for network segmentation. Your smart building sensors are physically incapable of communicating with your staff’s laptops.

enterprise networks

Conclusion

IoT security standards are not just bureaucratic red tape. They are the essential guardrails that allow businesses to reap the massive benefits of building automation without exposing themselves to devastating cyber risks.

By insisting on hardware that meets ETSI standards and deploying it on a secure, isolated LoRaWAN network, you future-proof your facility. You protect your data, your staff, and your corporate reputation.

At Concept13, we only supply enterprise-grade hardware that meets or exceeds all current UK and European security legislation. We design our networks to satisfy the most demanding IT departments and compliance auditors.

  • Need a secure IoT deployment? Explore our IoT Consultancy and Services to learn how we build compliant, secure networks from the ground up.

  • Concerned about your current hardware? Contact Concept13 today for an expert security audit of your existing smart building infrastructure.

Oliver WrightApril 2, 2026