News

FCC Adopts Rules Establishing Voluntary U.S. Cyber Trust Mark Program for Consumer IoT Products

The Federal Communications Commission has adopted a Report and Order and Further Notice of Proposed Rulemaking creating a voluntary cybersecurity labeling program for wireless consumer Internet of Things (IoT) products.

Establishment of the U.S. Cyber Trust Mark Program

On March 14, 2024, the Federal Communications Commission adopted a Report and Order and Further Notice of Proposed Rulemaking (FCC 24-26) in PS Docket No. 23-239, establishing a voluntary cybersecurity labeling program for wireless consumer Internet of Things (IoT) products. Released on March 15, 2024, the program establishes the 'U.S. Cyber Trust Mark' as a government-backed visual certification mark to assure consumers that qualifying smart devices meet core cybersecurity standards.

Under the newly established framework, qualifying consumer IoT products may display the FCC IoT Label, which pairs the Cyber Trust Mark visual indicator with a scannable QR code linking to a dynamic, publicly accessible product registry. The Commission acts as the overall program owner, retaining regulatory authority and decision-making control over the program's administration and enforcement.

Scope of Eligible Products and Explicit Exclusions

The IoT Labeling Program applies initially to consumer IoT products, defined as an IoT device together with any additional product components (such as backends, specialty gateways, or mobile companion apps) necessary to use the device beyond basic operational features. The scope targets intentional radiators that emit radio frequency energy under Section 302 of the Communications Act, excluding wired-only IoT products at this initial stage.

The Commission explicitly excluded several categories of devices and entities from participating in the labeling program to manage complexity and safeguard national security:

  • Medical devices regulated by the U.S. Food and Drug Administration (FDA).
  • Motor vehicles and motor vehicle equipment regulated by the National Highway Traffic Safety Administration (NHTSA).
  • Enterprise or industrial IoT products primarily intended for manufacturing, healthcare, or industrial control.
  • Communications equipment identified on the Commission's Covered List maintained pursuant to Section 2 of the Secure and Trusted Communications Networks Act.
  • Entities identified on the Department of Commerce's Entity List (15 CFR part 744, supplement no. 4) or the Department of Defense's List of Chinese Military Companies.
  • Persons or entities suspended or debarred from federal procurements or financial awards on the General Services Administration's System for Award Management (SAM).
  • Entities, subsidiaries, or affiliates owned or controlled by a foreign adversary country defined under 15 CFR § 7.4 (including China, Cuba, Iran, North Korea, Russia, and the Maduro Regime).

Administrative Architecture and Two-Step Authorization Process

The program framework relies on a public-private structure overseen by the FCC's Public Safety and Homeland Security Bureau (PSHSB). The Commission will recognize qualified third-party Cybersecurity Label Administrators (CLAs) accredited to ISO/IEC 17065, and designate one CLA to serve as Lead Administrator to coordinate program activities, interface with the FCC, and facilitate standards recommendations.

To obtain authorization to affix the FCC IoT Label, manufacturers must complete a two-step compliance process:

  • Step 1 (Testing): The product must undergo technical conformity testing by an ISO/IEC 17025 accredited laboratory recognized by the Lead Administrator—which may include an independent Cybersecurity Testing Laboratory (CyberLAB), a CLA-run lab, or a manufacturer's accredited in-house testing lab.
  • Step 2 (Certification): The applicant must submit a formal written application and test report to an FCC-recognized CLA, which reviews the record and issues a grant of cybersecurity labeling authorization if all requirements are satisfied.

Technical Baselines and Required Applicant Declarations

The technical requirements for the program are anchored in the National Institute of Standards and Technology (NIST) Core Baseline criteria set forth in NISTIR 8425. Technical outcome areas include asset identification, product configuration, data protection, interface access control, software updates, and cybersecurity state awareness, as well as developer supporting activities such as documentation, query reception, information dissemination, and education.

Applicants seeking authorization must submit a declaration under penalty of perjury attesting to the following requirements:

  • The product conforms to all program rules and technical requirements.
  • Neither the applicant nor the product components are listed on the FCC Covered List, Commerce Entity List, DoD List of Chinese Military Companies, or SAM debarment list.
  • The applicant has taken every reasonable measure to create a securable product.
  • The applicant will diligently identify critical vulnerabilities and promptly issue software updates through the stated support period end date.
  • The applicant will not elsewhere disclaim or attempt to limit the enforceability of these representations.
  • The applicant designates a U.S.-based agent for service of process maintained for at least one year following permanent termination of marketing.

The FCC IoT Registry and Post-Market Oversight

The FCC IoT Label must be displayed conspicuously (such as on retail packaging) with a QR code directing consumers to a dynamic, decentralized registry fed by a common Application Programming Interface (API). The registry will display key consumer disclosures including product and manufacturer names, authorizing CLA and testing lab, instructions for secure configuration and changing default passwords, whether security patches are automatic, the minimum support period expiration date, and disclosure of whether the manufacturer maintains a Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM).

CLAs are mandated to perform post-market surveillance and random auditing under ISO/IEC 17065. If a certified product is found non-compliant, the grantee receives written notice and has a 20-day cure period to submit a corrective action report. Failure to remedy deficiencies or make required disclosures will result in termination of authorization to use the label, alongside potential administrative remedies under the Communications Act or civil actions for trademark infringement and deceptive practices.

Further Notice of Proposed Rulemaking

Alongside the Report and Order, the Commission issued a Further Notice of Proposed Rulemaking seeking comment on potential national security disclosure requirements. Specifically, the FCC seeks feedback on whether manufacturers should be required to declare whether software or firmware was developed or deployed from foreign adversary jurisdictions (15 CFR § 7.4), whether customer data is stored in or transits high-risk countries, or whether products containing such components should be prohibited from the Cyber Trust Mark program entirely.

Source documents

This article is based on an official Federal Communications Commission publication released March 15, 2024.

FCC release date: 2024-03-15. Article last updated: 2026-08-17.