The Federal Communications Commission voted to create a voluntary cybersecurity labeling program for wireless consumer Internet of Things (IoT) products. Under the program, qualifying consumer smart products that meet robust cybersecurity standards will bear a label — including a new “U.S Cyber Trust Mark” — that is intended to help consumers make informed purchasing decisions, differentiate trustworthy products in the marketplace, and create incentives for manufacturers to meet higher cybersecurity standards.
The U.S. Cyber Trust Mark logo will initially appear on wireless consumer IoT products that meet the program’s cybersecurity standards. The logo will be accompanied by a QR code that consumers can scan for easy-to-understand details about the security of the product, such as the support period for the product and whether software patches and security updates are automatic.
Examples of eligible products may include home security cameras, voice-activated shopping devices, internet-connected appliances, fitness trackers, garage door openers and baby monitors.
Among other program highlights:
- The voluntary program will rely on public-private collaboration, with the FCC providing oversight and approved third-party label administrators managing activities such as evaluating product applications, authorizing use of the label, and consumer education.
- Compliance testing will be handled by accredited labs.
The FCC is seeking public comment on additional potential disclosure requirements, including whether software or firmware for a product is developed or deployed by a company located in a country that presents national security concerns and whether customer data collected by the product will be sent to servers located in such a country.
It’s been estimated that there were more than 1.5 billion attacks against IoT devices in the first six months of 2021 alone. Other estimates forecast there will be more than 25 billion connected IoT devices in operation by 2030. The cybersecurity labeling program is said to build on the significant public and private sector work already underway on IoT cybersecurity and labeling, emphasizing the importance of continued partnership so that consumers can enjoy the benefits of this technology with greater confidence and trust.
The FCC voted to create the new program on March 14, culminating years of work by the Biden Administration, the National Institute of Standards and Technology (NIST), government agencies and private stakeholders.