US Cyber Trust Mark: IoT Security Labeling Guide
The US Cyber Trust Mark is a voluntary cybersecurity labeling program for consumer Internet of Things (IoT) devices, established by the FCC in partnership with NIST. Similar to the Energy Star label for energy efficiency, the Cyber Trust Mark provides consumers with a recognizable shield logo indicating that a connected device meets baseline cybersecurity standards. The program aims to improve IoT security across the consumer market by creating market incentives for manufacturers to build secure products.
What the Cyber Trust Mark Is and Who Issues It
The US Cyber Trust Mark program was established by the Federal Communications Commission (FCC) through a rulemaking process that concluded in early 2024. The FCC administers the labeling program and authorizes use of the Cyber Trust Mark shield logo. NIST provides the technical underpinning: the security criteria are based on NIST Internal Report 8425 (Profile of the IoT Core Baseline for Consumer IoT Products), which adapts NIST's foundational IoT cybersecurity guidance to the consumer product context.
The program's conceptual model is drawn from successful consumer labeling programs in other domains: Energy Star for energy efficiency, UL safety marks for product safety, and Nutrition Facts labels for food products. These programs work because they give consumers simple, recognizable signals about complex underlying attributes. The Cyber Trust Mark applies the same approach to cybersecurity — an area where consumer understanding is limited but risk is significant.
The voluntary nature of the program is deliberate. Rather than mandating compliance through regulation (which would require extensive rulemaking and face industry opposition), the FCC and NIST chose to create market incentives. Retailers are expected to prefer labeled products; consumers who understand the mark will favor labeled devices; enterprise IT departments procuring IoT devices for corporate networks will require the label in purchasing specifications.
The program launched officially in early 2024, with the first certified products appearing in the market in 2024-2025. As of 2026, the label has gained significant recognition, particularly in the smart home, consumer networking, and wearable technology segments.
Who Should Pursue Cyber Trust Mark Certification
The primary audience is manufacturers of consumer IoT devices. The program currently covers wireless consumer IoT products — devices that connect to the internet or home networks and are primarily used in residential settings. Product categories include:
- Smart home devices: Smart speakers, smart displays, home assistants, smart plugs, smart lighting systems
- Home security: Security cameras (indoor and outdoor), video doorbells, smart locks, alarm systems
- Network equipment: Consumer routers, mesh Wi-Fi systems, network access points
- Wearables: Fitness trackers, smartwatches, health monitoring devices
- Connected appliances: Smart thermostats, connected home appliances with network interfaces
- Entertainment devices: Smart TVs, streaming devices, gaming peripherals with network connectivity
Products must be consumer-facing wireless IoT products. Enterprise IoT, industrial IoT, and medical devices are outside the current scope, though the program may expand to additional categories.
The business case for certification comes from multiple directions. Retail channel requirements — major retailers including big-box electronics stores are incorporating Cyber Trust Mark status into product selection decisions. Insurance and liability benefits — manufacturers that can demonstrate certified security posture may gain favorable treatment in product liability and cyber insurance markets. Federal and state procurement — government purchasing is likely to favor or require labeled products for consumer-grade IoT in government facilities. Competitive differentiation — in a market where consumers are increasingly security-aware, the label provides a visible, credible differentiator.
Security Requirements: NIST IR 8425 in Depth
The Cyber Trust Mark criteria are based on NIST IR 8425's Profile of the IoT Core Baseline for Consumer IoT Products. The baseline establishes foundational cybersecurity capabilities that every certified product must demonstrate:
Unique Device Identification Each device must have a unique identifier (such as a serial number, hardware address, or device certificate) that distinguishes it from all other devices. This enables asset tracking, network management, and incident investigation. The identifier must be accessible to the device owner and to authorized management systems.
Secure Default Configuration Devices must ship in a secure-by-default state. This specifically means that default passwords are either unique per device (not shared across a product line) or force the user to create a password before the device becomes operational. Common attack vectors against consumer IoT devices exploit identical default credentials across millions of deployed units — the Cyber Trust Mark requirement closes this vulnerability.
Software and Firmware Update Capability Certified devices must support the ability to receive, verify, and install software and firmware updates from the manufacturer. Updates must be cryptographically signed to prevent tampering. The device must be designed to receive security updates for the manufacturer's defined support period, and that period must be clearly communicated to consumers (including end-of-support dates visible through the QR code).
Strong Authentication and Access Control Access to device management interfaces and sensitive functions must require authentication. Default credentials that are widely known or easy to guess are prohibited. Where devices support remote access, additional authentication factors should be supported. The standard does not prescribe specific authentication technologies but requires that the authentication mechanism be appropriate to the risk level.
Data Protection Data stored on the device and transmitted over networks must be protected. Sensitive data at rest should be encrypted. Data in transit must use current secure protocols — outdated protocols like unencrypted HTTP for configuration or management are non-compliant. The standard addresses both the device's data and any data transmitted to manufacturer cloud services.
Vulnerability Disclosure and Incident Logging Manufacturers must maintain a vulnerability disclosure program enabling security researchers and users to report discovered vulnerabilities. The program must include a defined response process and timeline. Devices must be capable of logging security events sufficient to support incident investigation — not necessarily a full SIEM-grade log, but meaningful security-relevant events.
The Certification Process
Step 1 — Determine eligibility Confirm that your product falls within the Cyber Trust Mark program scope. Current scope covers wireless consumer IoT products. Review the FCC's program rules for current eligibility criteria, as the program has been expanding.
Step 2 — Select a CyberLAB The FCC maintains a list of recognized CyberLABs — accredited testing laboratories authorized to conduct Cyber Trust Mark testing. CyberLABs are accredited by recognized national accreditation bodies (such as NVLAP, A2LA, or equivalent) and must demonstrate competence in consumer IoT cybersecurity testing. Select a lab with relevant product experience.
Step 3 — Product testing The CyberLAB evaluates the product against all NIST IR 8425 criteria. Testing includes technical testing of device capabilities (authentication, encryption, update mechanisms) and documentation review (vulnerability disclosure policy, support lifetime commitment). The lab issues a certification report documenting test results.
Step 4 — FCC application Submit the certification report to the FCC with the program application. The FCC reviews the submission and, upon approval, grants authorization to use the Cyber Trust Mark shield logo.
Step 5 — Product labeling and QR code Affix the Cyber Trust Mark shield logo to the product and packaging. Each labeled product must include a scannable QR code linking consumers to a product-specific page with current security information — manufacturer support status, patch history, end-of-life date, and links to the vulnerability disclosure program.
Step 6 — Annual renewal Products must be reassessed annually. This primarily addresses whether the manufacturer has maintained the security properties of the product through software updates and continued vulnerability management. Products that are no longer receiving security updates cannot maintain the label.
Costs and Timeline
| Activity | Typical Cost | Timeline |
|---|---|---|
| Pre-assessment gap analysis | $2,000 – $8,000 | 1–2 weeks |
| Product security hardening (if needed) | $5,000 – $30,000 | 1–3 months |
| CyberLAB testing (simple product) | $5,000 – $20,000 | 2–4 weeks |
| CyberLAB testing (complex product) | $15,000 – $50,000 | 4–8 weeks |
| FCC application fee | Nominal | 1–2 weeks review |
| QR code infrastructure setup | $2,000 – $10,000 | 2–4 weeks |
| Annual renewal per product | $5,000 – $20,000 | 2–4 weeks |
| Full certification (simple product) | $10,000 – $30,000 | 2–4 months |
| Full certification (complex product) | $25,000 – $75,000 | 4–6 months |
Comparison with Related Frameworks
NIST IR 8425 (90% overlap): The Cyber Trust Mark criteria are directly based on NIST IR 8425, which is in turn derived from NIST's foundational IoT cybersecurity work (NISTIR 8259 series). Manufacturers who have previously aligned their products to NISTIR 8259 will find the Cyber Trust Mark criteria familiar. NIST IR 8425 is the technical document; the Cyber Trust Mark is the labeling program based on it.
NIST CSF (35% overlap): The NIST Cybersecurity Framework provides a broader enterprise security governance framework. The Cyber Trust Mark's product-level security requirements overlap with CSF's Protect and Detect functions where they apply to product security. Manufacturers with mature CSF-aligned security programs have the governance foundation needed to produce Cyber Trust Mark-certifiable products.
IEC 62443: IEC 62443 addresses industrial automation and control system security — a different domain from consumer IoT, but with overlapping technical concepts. Manufacturers producing both industrial and consumer IoT products may find value in coordinating their security engineering across both standards, though the compliance pathways are entirely separate.
How Automation Helps
Maintaining Cyber Trust Mark certification across a product line requires tracking product security status, managing vulnerability disclosure programs, monitoring for new vulnerabilities affecting certified products, and coordinating annual reassessments. LowerPlane supports product security compliance programs across 50+ frameworks with evidence management and monitoring features. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users. Compare options at our best compliance automation platforms guide.
Frequently Asked Questions
Is the Cyber Trust Mark mandatory for selling IoT devices in the US? No. The program is voluntary. Manufacturers are not legally required to obtain the label. However, market forces are creating practical pressure: major retailers are signaling preference for labeled products, and government procurement is expected to require the label for IoT devices purchased for government use.
How does the Cyber Trust Mark QR code work for consumers? Each certified product's QR code links to a product-specific page on a CSA-managed registry. The page shows the product's certification status, the manufacturer's support commitment including the end-of-life date for security updates, recent security patch information, and a link to the manufacturer's vulnerability disclosure program. Consumers can scan the QR code before purchase or at any time to check current security status.
Can a product lose its Cyber Trust Mark certification? Yes. If the manufacturer fails the annual reassessment — for example by ceasing to provide security updates — the certification lapses and the product must remove the label from new units. Products sold before certification lapse can retain the label, but the registry entry will reflect the lapsed status. The FCC can take enforcement action against manufacturers falsely displaying the label.
What happens to products that reach end-of-support during the certification period? Products must receive security updates throughout the certification period. When a product approaches its manufacturer-defined end-of-life date for security support, the manufacturer must communicate that clearly through the QR code-linked page. Products beyond their end-of-support cannot maintain certification for new production. The transparency about end-of-support dates is a key consumer protection feature of the program.
Are there equivalent programs in other countries that recognize the Cyber Trust Mark? The FCC has engaged in discussions with international partners about mutual recognition. Singapore's Cybersecurity Labeling Scheme (CLS) and the EU's proposed Cyber Resilience Act (CRA) are the most directly comparable programs. Full mutual recognition has not been established, but the underlying technical criteria share significant alignment through their common NIST and ETSI reference documents, which may facilitate future harmonization.