EU Declaration of Conformity

Articles, guides, and products tagged "EU Declaration of Conformity" — a combined view of every catalogue resource on this topic.

User guide

E-scooter cybersecurity engineering: ETSI EN 303 645 V3.2.0:2024-12 baseline (13 provisions for consumer IoT — no default password, vulnerability disclosure RFC 9116, secure update, secure storage, secure communication), ISO/SAE 21434:2021 road-vehicle cybersecurity engineering (TARA threat analysis + risk assessment), ISO/SAE 24089:2023 software update engineering, UNECE R155 CSMS (Cybersecurity Management System) mandatory for new vehicle type-approvals from 07-2022, UNECE R156 SUMS (Software Update Management System), EU Cyber Resilience Act 2024/2847 (Regulation 2024-10-23, applicability 2027-12-11 + reporting obligations 2026-09-11), NIST SP 800-193:2018 Platform Firmware Resilience Guidelines (Protection-Detection-Recovery RoT), NIST SP 800-183 IoT Networks of Things, IEC 62443-4-1/-4-2 secure product development lifecycle, Bluetooth Core 5.4 LE Secure Connections with ECDH P-256 (replacing Just Works as baseline), IEEE 802.11i WPA3-Personal SAE Dragonfly key exchange, RFC 9116 security.txt responsible-disclosure, attack surface (BLE pairing Just Works/Numeric Comparison/Passkey Entry/OOB, Bluetooth protocol attacks KNOB CVE-2019-9506 + BIAS CVE-2020-10135 + BLURtooth CVE-2020-15802 + BLESA CVE-2020-9770, firmware via JTAG/SWD/USB DFU, motor controller CAN bus, mobile app↔cloud TLS, OTA update channel signing, GPS spoofing, smart-battery BMS handshake, hardware UART debug eFuse), mitigation (LE Secure Connections ECDH P-256 + mutual TLS certificate pinning + secure boot signed bootloader + signed firmware AES-256 + anti-rollback monotonic counter + HSM/secure element ATECC608B/NXP A1006/SE050 + SBOM SPDX CycloneDX + RFC 9116 security.txt + Coordinated Vulnerability Disclosure ISO/IEC 29147:2018 + penetration testing ISTQB), incidents (Xiaomi M365 BLE anti-lock bypass 2019 Zimperium Rani Idan, Lime BLE replay attack 2019, Bird/Lime API IDOR 2020, Ninebot ES1/ES2/ES4 BLE pwd 888888 vulnerability, Tier/Voi unauthorized unlock 2022, hoverboard CVE catalogue 2018)

Engineering deep-dive into e-scooter cybersecurity as the fourth cross-cutting infrastructure axis — parallel to [fastener engineering as joining-axis](@/guide/fastener-and-bolted-joint-engineering.md), [thermal management as heat-dissipation axis](@/guide/thermal-management-engineering.md), and [EMC/EMI as interference-mitigation axis](@/guide/emc-emi-engineering.md). Covers: 10-row standards matrix (ETSI EN 303 645 V3.2.0:2024-12 consumer IoT baseline, ISO/SAE 21434:2021 road-vehicle TARA, ISO/SAE 24089:2023 SW update engineering, UNECE R155 CSMS, UNECE R156 SUMS, EU CRA 2024/2847, NIST SP 800-193 firmware RoT, IEC 62443-4-1 secure SDLC, Bluetooth Core 5.4 LE Secure Connections, IEEE 802.11i WPA3-SAE); 7-row attack-surface matrix (BLE pairing methods + KNOB/BIAS/BLURtooth/BLESA + firmware JTAG/SWD/DFU + mobile↔cloud TLS + OTA signing + GPS spoofing + smart-battery handshake); 6-row mitigation matrix (LE Secure Connections + mutual TLS + secure boot + signed firmware + anti-rollback + HSM/SE); 6-row real-incident matrix (Xiaomi M365 2019 + Lime BLE 2019 + Bird IDOR 2020 + Ninebot pwd 888888 + Tier/Voi 2022 + hoverboard catalogue); 8-step DIY security check; 6-step DIY remediation; EU Cyber Resilience Act timeline (2024-12-10 entry into force, 2026-09-11 reporting obligations, 2027-12-11 full applicability); 16 numbered sections.

17 min read

User guide

Electric scooter regulatory map: PLEV classification, 22 jurisdictions, safety certification (EN 17128 / UL 2272 / UL 2849 / EN 15194), EMC + radio (ECE R10 / FCC Part 15B / CISPR 12/25) — complete reference as of May 2026

Regulatory reference in three dimensions: (1) classification frameworks — EU PLEV (Personal Light Electric Vehicle) per EN 17128:2020 with max 25 km/h / 250 W continuous nominal / not subject to motor-vehicle type approval, versus US «no federal class» (CPSC 16 CFR Part 1500 consumer-product oversight without preemption), UK «PLEV trial-only» (legal only via approved rental schemes through 31 May 2026 per DfT), Canada provincial pilots (Ontario MTO Pilot Project per O. Reg. 389/19), Australia state-by-state (NSW «road use» trial + VIC trial + QLD legal since 2018); (2) detailed rules across 22 jurisdictions — Germany eKFV (BMVI / Bundesrat 2019, Versicherungsplakette mandatory, ≥14 years, 0.5 ‰ alcohol limit), France EDPM (Loi d'orientation des mobilités Loi 2019-1428, ≥12-14 years depending on municipality, 25 km/h), Spain DGT (Real Decreto 970/2020, max 25 km/h, helmet required under 18), Italy (Legge 160/2019 + Decreto 2022), Netherlands (RDW model-approval required, more restrictive), Sweden (Lag 2001:559 — allowed on bike paths since 2018), US 5 states (CA CVC 21229, NY NYS VTL § 1280-a + NYC Local Law 39/2023 with UL 2272/2849 mandate, FL HB 453, TX Transportation Code 551.401, WA RCW 46.04.336), Canada 3 provinces (ON Pilot 389/19, BC Pilot OIC 2020, QC trial since 2024), Australia 3 states (NSW shared trial Order 2023, VIC Trial regulations 2022, QLD Transport Operations 2018), Japan 特定小型原動機付自転車 special small mobility vehicle (Road Traffic Act amendment July 2023), Singapore Active Mobility Act 2017 with UL 2272 mandate June 2019, Ukraine Law №2956-IX «On Road Traffic» (ПЛЕТ, ≥16 years, 25 km/h); (3) safety + EMC certification — UL 2272:2019 vehicle-level electrical (NYC mandate per Local Law 39/2023, Singapore LTA mandate), UL 2849:2020 e-bike specific, EN 17128:2020 EU PLEV harmonized standard, EN 15194:2017+A1:2023 EPAC e-bike, IEC 62133-2:2017 battery cell safety mandatory globally, IEC 62619 industrial battery, ECE Regulation 10 Rev 6 (2017) automotive EMC, FCC Part 15 Subpart B § 15.101-15.107 unintentional radiators, CISPR 12:2018 vehicle EMI, CISPR 25:2021 vehicle in-band radio, CE marking + RoHS Directive 2011/65/EU + WEEE Directive 2012/19/EU.

19 min read