
Smart Devices, Smarter Security
Connected devices are now part of everyday life, and their rapid growth raises important questions about how to secure them and protect the networks and data they rely on. The FCC’s voluntary Cyber Trust Mark program introduces a recognizable label and QR code system designed to give consumers clearer insight into the security of wireless IoT products. As adoption increases, the program aims to make security information more accessible and encourage stronger security practices across the consumer IoT market.
To support that goal, the following Q&A outlines the key elements of the FCC’s voluntary Cyber Trust Mark program for consumer IoT products.
1. What is the FCC Cyber Trust Mark?
The FCC Cyber Trust Mark is a voluntary U.S. cybersecurity labeling program for consumer wireless IoT devices. It provides a government-backed signal that a product meets baseline cybersecurity requirements defined by NIST IR 8425 and has been evaluated by accredited testing and certification bodies.
2. Why was the Cyber Trust Mark program created?
The program was established to reduce cybersecurity risks associated with insecure consumer IoT devices. By introducing a standardized security label, the FCC aims to help consumers identify safer products and encourage manufacturers to adopt secure-by-design practices.
3. Which products are covered by the Cyber Trust Mark?
The Cyber Trust Mark applies to wireless consumer IoT devices commonly used in residential and light commercial environments.
Products covered include:
- Smart home devices
- Wearables and fitness trackers
- Connected appliances
- Home security cameras
- Smart speakers and consumer robotics
Industrial IoT, medical devices, automotive systems, enterprise networking equipment, and heavy industrial devices are not included.
4. What does the Cyber Trust Mark label look like?
The label consists of a shield icon paired with a QR code. The shield indicates that the device meets the program’s baseline cybersecurity requirements, while the QR code links to a registry page containing detailed security information specific to that product.
5. What is the role of NIST IR 8425 in the program?
NIST IR 8425 serves as the technical foundation for the Cyber Trust Mark. It defines the minimum cybersecurity capabilities required for consumer IoT devices, and compliance with IR 8425 is mandatory for eligibility.
Key capabilities include:
- Secure default configuration
- Unique device identifiers
- Secure update mechanisms
- Encryption of data in transit and at rest
- Documented support period
- Vulnerability disclosure processes
- Basic event logging
6. Who oversees certification and governance?
The ioXt Alliance is the current Lead Administrator for the Cyber Trust Mark program. As Lead Administrator, ioXt coordinates program governance, supports label design, recommends testing procedures, and acts as liaison between the FCC and Cybersecurity Labeling Administrators (CLAs). Accredited CyberLABs perform technical testing, and all participating bodies must meet relevant ISO/IEC accreditation requirements.
7. Is participation in the Cyber Trust Mark program mandatory?
No. Participation is voluntary. However, retailers, distributors, and procurement programs may prefer or require labeled devices, creating strong market incentives for manufacturers to pursue certification.
8. What information is provided through the QR code registry?
The QR code links to a registry entry containing manufacturer-supplied security information for the device.
Registry information typically includes:
- Manufacturer identification
- Device model and version
- Security support period
- Software and firmware update policy
- Implemented security features
- Vulnerability disclosure and reporting processes
The registry does not function as a real-time vulnerability or CVE database.
9. How does a manufacturer obtain the Cyber Trust Mark?
Manufacturers follow a structured certification process.
Typical steps include:
- Internal assessment against NIST IR 8425 requirements
- Testing at an accredited CyberLAB
- Submission of documentation to a Cybersecurity Labeling Administrator
- Approval to use the Cyber Trust Mark label and QR code
- Ongoing compliance and registry updates throughout the product’s support period
10. What is the current status of the Cyber Trust Mark program?
The FCC adopted the Cyber Trust Mark rules in March 2024. The program is currently in the stand-up phase, with administrators and labs being accredited and the registry infrastructure being finalized. Full operational rollout will begin once these elements are complete.
11. How does the Cyber Trust Mark compare to international requirements?
The Cyber Trust Mark aligns with global IoT security trends but differs in scope and mandatory status.
Key comparisons include:
- EU Cyber Resilience Act (CRA): Mandatory, broader in scope, covering hardware and software.
- UK PSTI Act: Mandatory for consumer IoT, focused on passwords, updates, and disclosure.
- FCC Cyber Trust Mark: Voluntary, focused on baseline cybersecurity for consumer IoT devices.
12. What is the expected impact on the IoT industry?
The Cyber Trust Mark is expected to accelerate adoption of secure-by-design practices, increase transparency for consumers, and create competitive differentiation for manufacturers who adopt the label early. Over time, labeled devices may become preferred by retailers, procurement programs, and security-conscious customers.
Together, these efforts help make connected products easier to trust and safer to bring into everyday life.
The information provided in this FAQ is for general informational purposes only and is not intended to replace official codes, standards, or project specifications. Winnie Industries products must always be installed and used in accordance with our product instruction sheets or designated training. Products should never be applied beyond their intended purpose or in a manner that exceeds specified load ratings. Proper fastening is critical to system integrity and functionality, requiring secure attachment to structurally sound components capable of supporting imposed loads. All installations must comply with governing codes, regulations, and job site requirements. Always consult your Authority Having Jurisdiction (AHJ) for specific regulatory guidance.

