US Cyber Trust Mark / IoT Cybersecurity

ioXt Alliance now leads the US Cyber Trust Mark — certification applications expected in 2026

The FCC named the ioXt Alliance Lead Administrator of the US Cyber Trust Mark on 13 April 2026, after UL Solutions withdrew from the role in December 2025. The program — a voluntary, NIST-based cybersecurity label for consumer IoT — is expected to start accepting certification applications from device makers this year.

Last updated 11 September 2026

13 Apr2026 — FCC names ioXt Alliance Lead Administrator
10NIST IR 8425 capability areas a product must demonstrate
2026expected opening of certification applications for device makers

What changed in April 2026

UL Solutions withdrew as Lead Administrator effective 19 December 2025, reported amid scrutiny of its ties to China. The FCC opened a window for a replacement Lead Administrator from 7 January to 9 February 2026, and on 13 April 2026 named the ioXt Alliance — an independent, US-based nonprofit focused on IoT product security, privacy and transparency — as the new Lead Administrator. ioXt now owns operational integrity, coordination among Cybersecurity Labeling Administrators (CLAs), the public device registry, and implementation guidance for manufacturers.

Source: Cybersecurity Dive; Light Reading.

What certification actually tests

The program adopts NIST IR 8425, the Profile of the IoT Core Baseline for Consumer IoT Products (published September 2022). A product has to demonstrate ten capability areas: asset identification, product configuration, data protection, interface access control, software update, cybersecurity state awareness, documentation, information and query reception, information dissemination, and product education and awareness. The label itself is binary — certified or not, with no tier system — but every certified product carries a QR code linking to a public registry, so status can be checked as threats evolve and patches are pushed.

Source: NIST Consumer IoT Cybersecurity programme page.

Which products are in scope

Eligible: internet-connected consumer devices such as smart home security cameras, voice-activated devices, smart appliances, fitness trackers, garage door openers and baby monitors. Out of scope, by design: FDA-regulated medical devices and NHTSA-regulated motor vehicles, which are left to those agencies, plus personal computers, smartphones and routers, which fall outside the program's definition of an IoT product.

Questions

What is the US Cyber Trust Mark?

A voluntary FCC cybersecurity labeling program for consumer IoT products, announced by the White House on 18 July 2023. Certified products carry a binary label — there is no gold/silver/bronze tiering — plus a QR code linking to a public registry with detailed cybersecurity information, so the certification status can be checked as threats evolve and patches are issued.

Who administers the program now, and what changed in April 2026?

UL Solutions withdrew as Lead Administrator effective 19 December 2025, reportedly amid scrutiny of its ties to China. The FCC opened applications for a new Lead Administrator from 7 January to 9 February 2026 and named the ioXt Alliance — an independent, US-based IoT security nonprofit — as the new Lead Administrator on 13 April 2026.

What standard does certification test against?

NIST IR 8425, the Profile of the IoT Core Baseline for Consumer IoT Products, published September 2022. It sets out ten capability areas products must demonstrate: asset identification, product configuration, data protection, interface access control, software update, cybersecurity state awareness, documentation, information/query reception, information dissemination, and product education and awareness.

Which products are in scope, and which are excluded?

In scope: internet-connected consumer IoT such as smart home security cameras, voice-activated devices, smart appliances, fitness trackers, garage door openers and baby monitors. Explicitly excluded: FDA-regulated medical devices, NHTSA-regulated motor vehicles, personal computers, smartphones and routers.

When can device makers apply for certification?

The program has said it expects to begin accepting certification applications from IoT device makers in 2026, though the Lead Administrator transition and the scrutiny that triggered UL's withdrawal could still affect that timeline. There is no confirmed fixed application-open date as of this writing.

Where we fit

Mapping a product against NIST IR 8425's ten capability areas, working out what firmware, documentation and configuration gaps exist, and coordinating with a CLA once applications open is exactly the kind of multi-step compliance programme that stalls without a single owner. We scope the gap against your product line now, so you're ready to file the moment ioXt opens applications — not scrambling afterward.

Book a scoping call