US Cyber Trust Mark / IoT Cybersecurity
The FCC named the ioXt Alliance Lead Administrator of the US Cyber Trust Mark on 13 April 2026, after UL Solutions withdrew from the role in December 2025. The program — a voluntary, NIST-based cybersecurity label for consumer IoT — is expected to start accepting certification applications from device makers this year.
Last updated 11 September 2026
UL Solutions withdrew as Lead Administrator effective 19 December 2025, reported amid scrutiny of its ties to China. The FCC opened a window for a replacement Lead Administrator from 7 January to 9 February 2026, and on 13 April 2026 named the ioXt Alliance — an independent, US-based nonprofit focused on IoT product security, privacy and transparency — as the new Lead Administrator. ioXt now owns operational integrity, coordination among Cybersecurity Labeling Administrators (CLAs), the public device registry, and implementation guidance for manufacturers.
Source: Cybersecurity Dive; Light Reading.
The program adopts NIST IR 8425, the Profile of the IoT Core Baseline for Consumer IoT Products (published September 2022). A product has to demonstrate ten capability areas: asset identification, product configuration, data protection, interface access control, software update, cybersecurity state awareness, documentation, information and query reception, information dissemination, and product education and awareness. The label itself is binary — certified or not, with no tier system — but every certified product carries a QR code linking to a public registry, so status can be checked as threats evolve and patches are pushed.
Source: NIST Consumer IoT Cybersecurity programme page.
Eligible: internet-connected consumer devices such as smart home security cameras, voice-activated devices, smart appliances, fitness trackers, garage door openers and baby monitors. Out of scope, by design: FDA-regulated medical devices and NHTSA-regulated motor vehicles, which are left to those agencies, plus personal computers, smartphones and routers, which fall outside the program's definition of an IoT product.
A voluntary FCC cybersecurity labeling program for consumer IoT products, announced by the White House on 18 July 2023. Certified products carry a binary label — there is no gold/silver/bronze tiering — plus a QR code linking to a public registry with detailed cybersecurity information, so the certification status can be checked as threats evolve and patches are issued.
UL Solutions withdrew as Lead Administrator effective 19 December 2025, reportedly amid scrutiny of its ties to China. The FCC opened applications for a new Lead Administrator from 7 January to 9 February 2026 and named the ioXt Alliance — an independent, US-based IoT security nonprofit — as the new Lead Administrator on 13 April 2026.
NIST IR 8425, the Profile of the IoT Core Baseline for Consumer IoT Products, published September 2022. It sets out ten capability areas products must demonstrate: asset identification, product configuration, data protection, interface access control, software update, cybersecurity state awareness, documentation, information/query reception, information dissemination, and product education and awareness.
In scope: internet-connected consumer IoT such as smart home security cameras, voice-activated devices, smart appliances, fitness trackers, garage door openers and baby monitors. Explicitly excluded: FDA-regulated medical devices, NHTSA-regulated motor vehicles, personal computers, smartphones and routers.
The program has said it expects to begin accepting certification applications from IoT device makers in 2026, though the Lead Administrator transition and the scrutiny that triggered UL's withdrawal could still affect that timeline. There is no confirmed fixed application-open date as of this writing.
Mapping a product against NIST IR 8425's ten capability areas, working out what firmware, documentation and configuration gaps exist, and coordinating with a CLA once applications open is exactly the kind of multi-step compliance programme that stalls without a single owner. We scope the gap against your product line now, so you're ready to file the moment ioXt opens applications — not scrambling afterward.
Book a scoping call