Editorial standard

This brief translates recurring sourcing and production questions into RFQ and approval checkpoints. Project decisions should use the final model specification, applicable standard and current supplier evidence.

Security depends on the device, app, cloud service and update process. Define support periods, vulnerability handling and safe remote functions before nomination.

The appliance is only one part

A connected oven may depend on device firmware, mobile app, account system, cloud API and third-party modules. Security and privacy failures can occur at any link. The commercial owner must know who maintains each component after shipment.

Put lifecycle duties in the RFQ

Define unique credentials or secure onboarding, protection of stored and transmitted data, secure update mechanisms, vulnerability reporting, logging, dependency management, factory-reset behavior and the security-support period. State what happens when cloud service ends and which functions remain locally available.

Treat remote heating as safety-relevant

IEC 60335-2-6:2024 includes requirements relating to remote operation of ovens. Cyber controls do not replace appliance safety controls. Remote commands, status feedback, child access, interrupted connections and failed updates need joint safety and security review.

Use recognized baselines

ETSI EN 303 645 provides baseline security provisions for consumer IoT. The EU Cyber Resilience Act addresses products with digital elements and emphasizes secure design, maintenance and timely updates. Applicability and transition dates should be checked for the exact product and placement date.

Key takeaways

Quick checklist

Planning a connected oven platform?

Bring the device, app and cloud architecture into the product brief from the start.