Skip to content

US Cyber Trust Mark: still closed to applications

News · Regulatory evolution

On 11 August 2026 the FCC's Public Safety and Homeland Security Bureau released Public Notice DA 26-834: two further label administrators conditionally approved, and the application filing window reopened. The same document restates, in terms that leave no room for interpretation, that "Conditionally approved CLAs are not authorized by the Commission to approve the use of the FCC IoT Label". Nearly two and a half years after Report and Order FCC 24-26 was adopted on 14 March 2024, the voluntary US Cyber Trust Mark programme still accepts no product authorisation applications.

In short:

  • The programme is voluntary as a matter of rule text: 47 CFR 8.203(k) defines it as "a voluntary program for consumer IoT products".
  • As of 19 August 2026 no administrator has moved from conditional to full approval, the precondition for any product application.
  • The ISO/IEC 17065 accreditation route is not open: the Commission has not yet established accreditation programmes with recognised accrediting bodies.
  • UL Solutions withdrew as Lead Administrator effective 19 December 2025; ioXt Alliance succeeded it on 13 April 2026.
  • The standards and testing procedures have not been adopted: DA 26-834 still refers to a "forthcoming FCC program scope".

A long roll-out that never opened for business

Section titled “A long roll-out that never opened for business”

The legal framework does exist. Adopted on 14 March 2024 in PS Docket No. 23-239, FCC 24-26 inserts into 47 CFR part 8 a new subpart B entitled "Cybersecurity Labeling Program for IoT Products", made up of sections 8.201 through 8.222. The final rule was published in the Federal Register on 30 July 2024 and has been effective since 29 August 2024. What is missing is not the rule, but the conformity assessment infrastructure the rule assumes.

DateInstrumentEffect
14 March 2024FCC 24-26 adoptedCreates the programme, subpart B of 47 CFR part 8
30 July 2024Federal Register, doc. 2024-14148Rule effective 29 August 2024
10 September 2024DA 24-900First CLA and Lead Administrator filing window
4 December 2024DA 24-1214UL LLC selected as Lead Administrator and CLA
11 December 2024DA 24-1241Eleven administrators conditionally approved
15 August 2025CTIA Certification LLC withdrawalOne fewer CLA among the eleven (DA 26-75)
19 December 2025UL Solutions withdrawalLead Administrator post left vacant
6 January 2026DA 26-18Lead Administrator window, 7 to 28 January 2026
26 January 2026DA 26-75CLA window, 27 January to 24 February 2026
13 April 2026DA 26-354ioXt Alliance selected as new Lead Administrator
11 August 2026DA 26-834Two more CLAs, window reopened with no closing date

DA 24-1241 named eleven administrators, among them CTIA Certification LLC, ioXt Alliance and UL LLC; DA 26-75 records that CTIA Certification LLC withdrew with effect from 15 August 2025; DA 26-834 adds two more, IIA Lab Services and Element Materials Technology Portland - Evergreen, leaving twelve conditionally approved administrators, though the FCC publishes no consolidated total.

The bottleneck: accreditation and test procedures

Section titled “The bottleneck: accreditation and test procedures”

The two roles are distinct in the rules. 47 CFR 8.203(c) defines the Cybersecurity Label Administrator (CLA) as an accredited third-party entity recognised and authorised by the Commission to manage and administer the programme. 8.203(d) defines the CyberLAB as an accredited third-party entity recognised and authorised by a CLA, not by the FCC. CyberLABs must hold ISO/IEC 17025 accreditation from a body recognised by the Bureau on the basis of ISO/IEC 17011, with reassessment at intervals not exceeding two years (8.217(a)(2) and 8.217(f)). It is the Lead Administrator, not the Commission, that maintains the public list of recognised CyberLABs, and inclusion "does not constitute Commission endorsement of that facility" (8.217(d)).

On the administrator side, 8.220(c)(6) conditions approval on ISO/IEC 17065 accreditation with the appropriate FCC programme scope, obtained within six months of the effective date of the Commission's adoption of the labelling standards and testing procedures. Since those standards have not been adopted, that clock has never started. DA 26-834 puts it plainly: CLAs "may apply for accreditation after the Commission has established accreditation program(s) with FCC-recognized accrediting bodies".

The technical content is missing too. 8.221(a)(4) requires the Lead Administrator, within 90 days of election, to recommend to the Bureau the technical standards and testing procedures for at least one class of IoT products, how often authorisations must be renewed, post-market surveillance procedures, registry updates, and the design of the label. DA 26-354 records that the previous Lead Administrator had filed an initial set of recommendations, under review and to be put out for public comment. No public notice moving a CLA to full approval has appeared in PS Docket No. 23-239 as of 19 August 2026.

The NIST IR 8425 baseline and the registry

Section titled “The NIST IR 8425 baseline and the registry”

The technical baseline, by contrast, is settled: at paragraph 99, FCC 24-26 adopts NIST IR 8425 as the basis for the programme. Published in September 2022, this non-normative guidance sets out six IoT product capabilities (asset identification, product configuration, data protection, interface access control, software update, cybersecurity state awareness) and four non-technical supporting capabilities (documentation, information and query reception, information dissemination, product education and awareness). Under 8.221(a)(5) the Lead Administrator has 45 days from a NIST guideline update to recommend the matching changes. The dedicated guide works through the ten capabilities.

The label is defined at 8.203(f): a binary label bearing the Cyber Trust Mark plus a scannable QR code pointing to a registry. 8.222(a) requires that registry to be dynamic, decentralised, publicly accessible and exposed through a common API that is secure by design. 8.222(b) lists eleven data elements to publish, among them the authorisation date and status, the authorising CLA, the testing laboratory, how to change the default password, the end date of the minimum support period, and disclosure of whether a hardware or software bill of materials (SBOM) is maintained. With no product authorisations issued, that registry has nothing to publish. One labelling constraint is worth flagging to hardware teams: FCC 24-26 expressly disapplies 47 CFR 2.935 to the Cyber Trust Mark, so the mark cannot be shown as an e-label.

TopicRule
NatureVoluntary (8.203(k))
Products in scopeIoT products intended primarily for consumer rather than enterprise or industrial use (8.203(b))
Sector exclusionsMedical devices regulated by the FDA, motor vehicles and vehicle equipment regulated by NHTSA (8.203(b))
Wired productsExcluded at launch; the Commission wanted the scope kept "clear and manageable"
Source-based barsCovered List under 47 CFR 1.50002, Department of Commerce Entity List, Department of Defense List of Chinese Military Companies, entities suspended or debarred from federal procurement (8.204)
US Cyber Trust MarkEuropean Union
NatureVoluntaryMandatory
Technical baselineNIST IR 8425EN 18031-1, -2 and -3, cited with restrictions by Implementing Decision (EU) 2025/138
TriggerManufacturer's choiceRED 3.3(d), (e) and (f), applicable since 1 August 2025
Status at 19 August 2026No product application can be filedRegime fully applicable
OutlookStandards and testing procedures still to be adopted, no date announcedDelegated Regulation (EU) 2022/30 repealed with effect from 11 December 2027, CRA applies in full

Delegated Regulation (EU) 2026/339 of 16 February 2026 repeals Delegated Regulation (EU) 2022/30 with effect from 11 December 2027, so that the same radio equipment is not caught simultaneously by RED 3.3 and by Regulation (EU) 2024/2847. The detailed timeline sits in the article on the repeal of the RED 3.3 regime.

On mutual recognition, it pays to read the text strictly. FCC 24-26 delegates to the Bureau and the FCC Office of International Affairs the task of developing international recognition of the label and mutual recognition of foreign labels, and mentions an agreement for a joint roadmap with comparable EU consumer labelling programmes. At paragraph 61 the same text records that no international agreements are yet in place, and nothing more recent has been published. Compliance with EN 18031 is therefore not authorisation to affix the Cyber Trust Mark, and the reverse does not hold either.

  1. Keep the label out of product milestones. No date for accepting applications has been announced.
  2. Treat NIST IR 8425 as a design reference. The six technical capabilities largely cover what RED 3.3 already requires and what the CRA will require.
  3. Assemble the registry data. The eleven elements in 8.222(b) are mostly product and documentation facts, built during development rather than afterwards.
  4. Check eligibility under 8.204. A component sourced from a listed entity closes off the label regardless of how secure the product is.

Sources & references

  1. FCC 24-26, Cybersecurity Labeling for Internet of Things, Report and Order and Further Notice of Proposed Rulemaking, PS Docket No. 23-239 , Federal Communications Commission docs.fcc.gov/public/attachments/FCC-24-26A1.pdf
  2. Cybersecurity Labeling for Internet of Things, final rule (document 2024-14148) , Federal Register www.federalregister.gov/documents/2024/07/30/2024-14148/cybersecurity-labeling-for-internet-of-things
  3. Public Notice DA 24-900 of 10 September 2024, first CLA and Lead Administrator filing window , Federal Communications Commission docs.fcc.gov/public/attachments/DA-24-900A1.txt
  4. Public Notice DA 24-1214 of 4 December 2024, selection of UL LLC as Lead Administrator , Federal Communications Commission docs.fcc.gov/public/attachments/DA-24-1214A1.txt
  5. Public Notice DA 24-1241 of 11 December 2024, conditionally approved Cybersecurity Label Administrators , Federal Communications Commission docs.fcc.gov/public/attachments/DA-24-1241A1.txt
  6. Public Notice DA 26-18 of 6 January 2026, filing window for Lead Administrator applications , Federal Communications Commission docs.fcc.gov/public/attachments/DA-26-18A1.txt
  7. Public Notice DA 26-75 of 26 January 2026, CLA filing window and restatement of programme obligations , Federal Communications Commission docs.fcc.gov/public/attachments/DA-26-75A1.txt
  8. Public Notice DA 26-354 of 13 April 2026, selection of ioXt Alliance as new Lead Administrator , Federal Communications Commission docs.fcc.gov/public/attachments/DA-26-354A1.txt
  9. Public Notice DA 26-834 of 11 August 2026, conditionally approved administrators and reopened filing window , Federal Communications Commission docs.fcc.gov/public/attachments/DA-26-834A1.txt
  10. NIST IR 8425, Profile of the IoT Core Baseline for Consumer IoT Products , National Institute of Standards and Technology nvlpubs.nist.gov/nistpubs/ir/2022/NIST.IR.8425.pdf
  11. Implementing Decision (EU) 2025/138, citation of the EN 18031 standards , EUR-Lex eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L_202500138
  12. Delegated Regulation (EU) 2026/339 of 16 February 2026 , EUR-Lex eur-lex.europa.eu/eli/reg_del/2026/339/oj
  13. Delegated Regulation (EU) 2022/30 , EUR-Lex eur-lex.europa.eu/eli/reg_del/2022/30/oj