FCC Cyber Trust Regulatory Compliance Testing

The FCC created it for consumer Internet of Things (IoT) devices like smart cameras, thermostats, locks, lights, wearables, baby monitors, and similar connected products.

The FCC U.S. Cyber Trust Mark will become mandatory on January 4, 2027, but only for vendors supplying consumer Internet of Things (IoT) products to the U.S. federal government. For the general consumer marketplace and retail stores, the labeling program remains entirely voluntary.

Summary of the FCC Cyber Trust Testing Standard

The FCC Cyber Trust Mark program is designed to create a more consistent way to evaluate connected consumer products. Instead of each company defining cybersecurity in its own way, the program gives manufacturers a shared set of expectations to work toward before a product can be labeled.

This makes the standard useful because many smart products depend on more than just hardware. A connected device may rely on accounts, apps, remote servers, and update systems to operate safely. The Cyber Trust process helps make sure those supporting pieces are considered as part of the overall cybersecurity picture.

A manufacturer can apply to use the U.S. Cyber Trust Mark on an eligible connected product. To earn the mark, the product must meet FCC-approved cybersecurity requirements that are meant to show the device has been reviewed for baseline security protections. If you think you can benefit from this category of compliance testing, contact us today!

The label is binary, meaning the product either qualifies or it does not. It is not a 1-to-5-star rating, a grade, or a ranking against other products.

The label includes two main parts:

  1. The Cyber Trust Mark logo — This gives shoppers a quick visual signal that the product has gone through the FCC Cyber Trust Mark process.
  1. A QR code — The QR code links shoppers to a registry with plain-language cybersecurity information about that specific product. This helps users look beyond the logo and review details about the product’s security support, setup, and certification information.

Scope of the Cybersecurity Areas Reviewed

The FCC based the program on NIST IR 8425, a NIST baseline for consumer IoT cybersecurity. The product should be designed so it can be identified, configured securely, protect data, control access, receive secure updates, detect cybersecurity issues, and give users useful security information.

Examples include:

  • Avoiding insecure default credentials.
  • The device should support secure software updates.
  • Access should be limited to authorized users/services.
  • Data should be protected at rest and in transit.
  • The company should have a way to receive and share security info.
  • Users should receive instructions from the manufacturer for secure setup and usage.

What the QR code is supposed to tell you

The QR registry is meant to answer practical questions like:

  • Who made the product?
  • Who certified it?
  • What lab tested it?
  • Can you change the default password?
  • How do you set it up securely?
  • Are software/security updates automatic?
  • How long will the manufacturer support the product with security fixes?
  • Does the manufacturer maintain a software bill of materials (SBOM) or hardware bill of materials (HBOM)?

This QR code support period is important because the FCC specifically wants buyers to see how long the maker promises to identify critical vulnerabilities and issue updates. For example, a smart camera that stops getting patches can become risky even if it worked fine when a user bought it.

What kinds of products are covered in the FCC standard?

The program initially focuses on wireless consumer IoT products. “Consumer” means normal home/consumer use, not industrial or enterprise gear. The FCC gives examples of “smart” products including:

  • thermostats
  • lights
  • locks
  • cameras
  • watches
  • fitness trackers

Additionally, the FCC Cyber Trust standard excludes some categories, including FDA regulated medical devices and motor vehicles/motor vehicle equipment, because those are already handled by other regulators. Products tied to certain national security risk lists are also excluded from using the label.

How Can A Company Receive The FCC Mark?

The compliance program goes as follows:

  1. Check that the product is eligible.
  2. Get the product tested by an accredited/recognized lab.
  3. Get a conformity/compliance report.
  4. Submit an application to an FCC-recognized Cybersecurity Label Administrator.
  5. If approved, the company can put the FCC IoT Label/Cyber Trust Mark on the product.

The FCC oversees the program, but third-party administrators and labs such as Applus+ Keystone do much of the day-to-day reviewing and testing.

Program status: The FCC has selected ioXt Alliance as Lead Administrator to help finalize implementation, including technical standards, testing procedures, and label design.

Is FCC Cyber Trust Testing Mandatory?

For regular consumer sales, it is voluntary. A company does not have to participate, but if it uses the mark, it has to follow the program rules.

For federal government buying, there is a major twist: a June 2025 Executive Order directed FAR Council agencies to work toward requiring federal vendors of consumer IoT products to carry the U.S. Cyber Trust Mark by January 4, 2027, where appropriate and lawful.

What it does not mean

The mark does not mean “unhackable.” It means the product met a baseline program standard at the time of authorization and has certain support/disclosure obligations.

It also does not replace best practices. You still want to update devices, change default passwords, use strong Wi-Fi security, remove unused devices, and avoid sketchy apps.

Why Does FCC Cybersecurity Testing Matter?

For Consumers

FCC Cyber Trust testing makes it easier to compare connected devices using cybersecurity criteria, not just price, features, or brand recognition. This gives buyers more visibility into whether a product has been reviewed against a recognized security standard.

For Manufacturers

The U.S. Cyber Trust Mark can help show that cybersecurity was considered as part of the product’s design and support process. As connected device security becomes more important, the mark may help products stand out to retailers, business buyers, and government purchasers looking for added confidence.

Marketing and Compliance Teams,

Lastly, marketing teams use testing to support stronger product messaging, but the language still needs to stay accurate. Instead of making broad claims like “hack proof” or “fully secure,” a safer approach is to say the product is “certified to meet FCC U.S. Cyber Trust Mark program requirements.”

Expert Cyber Security Testing for IoT manufacturers

Applus+ Keystone is ready to support your FCC cybersecurity testing and compliance needs. As an ISO/IEC 17025 accredited laboratory with extensive experience in wireless, EMC, and regulatory testing, we are expanding our capabilities to help manufacturers evaluate connected devices against evolving FCC cybersecurity requirements. Our team provides comprehensive testing support to help identify vulnerabilities, verify compliance, and prepare products for market.

Whether you are pursuing the FCC Cyber Trust Mark, validating the cybersecurity of IoT devices, or preparing connected products for regulatory approval, our experts deliver accurate, reliable results backed by decades of testing experience. From product development through certification, we help manufacturers navigate changing cybersecurity requirements with confidence. Contact Applus+ Keystone today to discuss your FCC cybersecurity testing needs and learn how our expanded cybersecurity testing capabilities can support your next project.

Additional FCC Cyber Trust Testing and Related Standards