Regulations / United States

Regulations by jurisdiction

United States: what binds a connected product

The US has no horizontal IoT security law. What exists is sector-specific (FDA for medical devices), voluntary (the Cyber Trust Mark), or enforcement after the fact by the FTC under consumer-protection law.

FrameworkApplies whenWho demands itIn forcePenalties
US Cyber Trust MarkConsumer wireless IoT sold in the US, by choiceRetail shelf positioning; no legal dutyProgramme launched Jan 2025None; misuse of the mark is an FCC matter
FDA premarket cybersecurityCyber devices submitted for FDA clearance or approval in the USRegulatory approvalStatutory since 29 Mar 2023Refusal to accept the submission

US Cyber Trust Mark

FCC labelling programme modelled on Energy Star; testing against NIST IR 8425 criteria by accredited labs.

FDA premarket cybersecurity

Section 524B of the FD&C Act: a cybersecurity plan, SBOM, and post-market vulnerability process in every submission; 2023 and 2025 guidance.

Check your own product

The IoT security scorecard and the requirements generator resolve these frameworks for your product archetype and markets. Educational reference, not legal advice.

← All jurisdictions

© 2026 Yoel Frischoff / TheRoad. All rights reserved. · About the Book · Press · Teaching · Glossary · References · Privacy · Terms · Accessibility