Program Overview and Technical Scope
The Federal Communications Commission (FCC) has circulated a draft Report and Order in PS Docket No. 23-239 outlining the framework for a voluntary cybersecurity labeling program for smart devices, known as the U.S. Cyber Trust Mark program. The initiative is designed to provide consumers with clear indicators of baseline cybersecurity for connected products and to encourage manufacturers to implement security-by-design principles.
Under the draft framework, the program focuses initially on wireless consumer IoT products, defined as intentional radio frequency (RF) radiators combined with necessary product components such as companion mobile apps, gateways, and cloud backends. Enterprise IoT products, wired-only devices, and medical devices regulated by the U.S. Food and Drug Administration (FDA) are excluded from the initial scope.
- Targeted at wireless consumer IoT products that intentionally emit RF energy.
- Adopts the NIST definition of an IoT product, encompassing devices and associated components like companion apps and backends.
- Excludes FDA-regulated medical devices, enterprise-only equipment, and wired-only IoT devices from the initial deployment.
Administrative Architecture and Oversight
The FCC will retain ultimate ownership and authority over the program, while delegating day-to-day management to independent, neutral third-party Cybersecurity Label Administrators (CLAs). The Commission's Public Safety and Homeland Security Bureau (PSHSB) will oversee the program and select a Lead Administrator from among the qualified CLA applicants.
The Lead Administrator will coordinate stakeholder consensus to recommend specific technical standards, testing procedures, label formatting, and renewal cadences to the FCC within 90 days of selection. Conformance testing must be conducted by laboratories accredited to ISO/IEC 17025 standards, which may include independent Cybersecurity Testing Laboratories (CyberLABs), CLA-run laboratories, or qualified manufacturer in-house laboratories.
- Program owner: Federal Communications Commission, with delegated authority to PSHSB.
- CLAs must be accredited to ISO/IEC 17065 standards by recognized accreditation bodies adhering to ISO/IEC 17011.
- Testing laboratories (CyberLABs, CLA labs, or in-house labs) must maintain ISO/IEC 17025 accreditation.
- Lead Administrator tasked with submitting initial standard and testing recommendations within 90 days of designation.
National Security Exclusions and Eligibility Protections
To protect national security and the supply chain, the draft order bars equipment and entities subject to specific federal restrictions from participating in the labeling program or serving as administrators or testing facilities.
Applicants seeking authorization to display the Cyber Trust Mark must submit an unsworn declaration under penalty of perjury certifying compliance with program criteria and confirming they are not affiliated with restricted lists.
- Prohibits products and entities listed on the FCC Covered List under the Secure and Trusted Communications Networks Act.
- Excludes entities listed on the Department of Commerce Entity List and Department of Defense List of Chinese Military Companies.
- Prohibits participants and entities suspended or debarred in the GSA System for Award Management (SAM).
- Disqualifies CLAs and CyberLABs owned or controlled by foreign adversary jurisdictions defined in 15 CFR ยง 7.4.
Label Design, Public Registry, and Post-Market Surveillance
The FCC IoT Label will use a binary format featuring the Cyber Trust Mark certification logo alongside a machine-readable QR code. Scanning the QR code will direct consumers to a decentralized public registry powered by a common Application Programming Interface (API).
The registry will present essential product information, including the manufacturer name, date of authorization, testing laboratory, password management instructions, automatic update details, guaranteed minimum support period, and whether a Software Bill of Materials (SBOM) is maintained. Grantees will be subject to ISO/IEC 17065-compliant post-market surveillance, random sampling, and a 20-day cure period for identified non-compliance before authorization termination.
- Binary label design includes the Cyber Trust Mark mark and a direct QR code link to product registry data.
- Registry discloses support lifespans, secure configuration guides, update mechanisms, and SBOM maintenance status.
- CLAs will conduct ongoing post-market surveillance and auditing with a mandatory 20-day response window for reported defects.
- Rule changes codified in Part 8 of Title 47 of the Code of Federal Regulations.